Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- %ProgramFiles(x86)%\internet explorer\uninstall.exe
- %ProgramFiles(x86)%\internet explorer\qc.inf
- %ProgramFiles(x86)%\internet explorer\qweerz chgtype.exe
- %ProgramFiles(x86)%\internet explorer\ssetup.cfg
- %WINDIR%\inf\seted0c.tmp
- %WINDIR%\setedd8.tmp
- %WINDIR%\inf\seted0c.tmp в %WINDIR%\inf\qc.inf
- %WINDIR%\setedd8.tmp в %WINDIR%\qweerz chgtype.exe
- %LOCALAPPDATA%\microsoft\windows\explorer\explorerstartuplog_runonce.etl
- ClassName: 'EDIT' WindowName: ''
- '%ProgramFiles(x86)%\internet explorer\uninstall.exe'
- '%WINDIR%\syswow64\infdefaultinstall.exe' "%ProgramFiles(x86)%\Internet Explorer\QC.inf"
- '%WINDIR%\syswow64\runonce.exe' -r
- '%WINDIR%\syswow64\grpconv.exe' -o