Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\baijrq] 'Start' = '00000002'
- 'C:\1.scr' /S
- '<SYSTEM32>\svchost.exe' -k netsvcs
- %WINDIR%\FuckYou.reg
- %TEMP%\wi180500nd.temp
- %PROGRAM_FILES%\temp0\QQ.exe
- %WINDIR%\MyInformations.ini
- C:\1.scr
- %WINDIR%\Ball.txt
- C:\1.scr
- %WINDIR%\MyInformations.ini
- %WINDIR%\Ball.txt
- %WINDIR%\FuckYou.reg
- %TEMP%\wi180500nd.temp в C:\Documents and Settings\bai.dll
- ClassName: 'Shell_TrayWnd' WindowName: ''