Техническая информация
- [HKCU\Environment] 'UserInitMprLogonScript' = '%WINDIR%\SysWOW64\AdapterTroubleshooter.exe'
- %WINDIR%\syswow64\pupipirecu.exe
- %LOCALAPPDATA%\ics\aeiou.ini
- ClassName: 'Button' WindowName: ''
- ClassName: 'customround' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c REG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V"user" /t REG_SZ /F /D "%WINDIR%\SysWOW64\pupipirecu.exe %WINDIR%\SysWOW64\ %WINDIR%\SysWOW64\zipfldr.dll" (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V"user" /t REG_SZ /F /D "%WINDIR%\SysWOW64\pupipirecu.exe %WINDIR%\SysWOW64\ %WINDIR%\SysWOW64\zipfldr.dll"