Техническая информация
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Bad' = '%HOMEPATH%\Documents\bad.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Bad' = '%HOMEPATH%\Documents\bad.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\bad.exe
- %WINDIR%\explorer.exe
- %HOMEPATH%\documents\bad.exe
- %HOMEPATH%\documents\123.jpg
- ClassName: 'SystemTray_Main' WindowName: ''
- '%WINDIR%\explorer.exe'