Техническая информация
- '%WINDIR%\Temp\fimdweb.exe'
- '<SYSTEM32>\wscript.exe' "%TEMP%\RarSFX0\fimdweb.vbs"
- '%WINDIR%\regedit.exe' /s <SYSTEM32>\smsie.reg
- %HOMEPATH%\Favorites\OVИнјюХѕМṩЧоРВГв·СИнјюЎў№ІПнИнјюПВФШ!.url
- %HOMEPATH%\Favorites\МФ±¦»К№ЪµкЖМѕ«СЎ.url
- %HOMEPATH%\Favorites\°Щ¶ИТ»ПВЈ¬ДгѕНЦЄµА.url
- %HOMEPATH%\Favorites\°Щ¶ИЛСЛч_QQ.url
- %HOMEPATH%\Favorites\°Щ¶ИЛСЛч_НшЧ¬.url
- %TEMP%\RarSFX0\fimdweb.vbs
- %WINDIR%\Temp\fimdweb.exe
- <SYSTEM32>\smsie.reg
- %HOMEPATH%\Favorites\МФ±¦Нш - МФЈЎОТПІ»¶.url
- %HOMEPATH%\Favorites\OV98НшЦ·µјєЅЈЧоєГµДЦРОДНшЦ·Хѕ.url
- %TEMP%\RarSFX0\fimdweb.vbs
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'