Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'IE.vbs' = 'c:\ghost\IE.vbs'
- %WINDIR%\syswow64\windows32.vbs
- %WINDIR%\syswow64\3.bat
- %WINDIR%\syswow64\3.vbs
- %WINDIR%\syswow64\9ptv.ico
- %WINDIR%\syswow64\77zb.ico
- %WINDIR%\syswow64\game.ico
- %WINDIR%\syswow64\kusila.ico
- %WINDIR%\syswow64\qq.ico
- %WINDIR%\syswow64\taobao.ico
- %WINDIR%\syswow64\1.vbs
- %WINDIR%\syswow64\腾讯qq.lnk
- %WINDIR%\syswow64\ie.reg
- %HOMEPATH%\application data\microsoft\internet explorer\quick launch\internet exp1orer.url
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: '%HOMEPATH%\Desktop'
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c ""<SYSTEM32>\3.bat" "' (со скрытым окном)
- '%WINDIR%\syswow64\wscript.exe' "<SYSTEM32>\windows32.vbs"
- '%WINDIR%\syswow64\cmd.exe' /c ""<SYSTEM32>\3.bat" "
- '%WINDIR%\syswow64\reg.exe' del "HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command" /v
- '%WINDIR%\syswow64\reg.exe' add "HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command" /v "" /d "%ProgramFiles(x86)%\Internet Explorer\iexplore.exe http://www.v2##3.com/?10### /f
- '%WINDIR%\syswow64\regedit.exe' /s ie.reg