Техническая информация
- [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,<SYSTEM32>\wscript.exe <SYSTEM32>\Folder.vbs'
- <SYSTEM32>\folder.vbs
- C:\$recycle.bin\$recycle.bin.vbs
- C:\documents and settings\documents and settings.vbs
- <Текущая директория>\dttfghrf.vbs
- C:\kms\kms.vbs
- C:\msocache\msocache.vbs
- C:\perflogs\perflogs.vbs
- %ProgramFiles%\program files.vbs
- %ProgramFiles(x86)%\program files (x86).vbs
- %ALLUSERSPROFILE%\programdata.vbs
- C:\recovery\recovery.vbs
- <SYSTEM32>\folder.vbs
- '<SYSTEM32>\logoff.exe'