Техническая информация
- [HKLM\System\CurrentControlSet\Services\soundman] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\soundman] 'ImagePath' = '%WINDIR%\mozila\ixpers.exe'
- 'soundman' %WINDIR%\mozila\ixpers.exe
- %WINDIR%\mozila\config.ini
- %WINDIR%\mozila\fs.bat
- %WINDIR%\mozila\ixpers.exe
- %WINDIR%\mozila\txt.vbs
- %WINDIR%\mozila\butterfly that never flew.ppt
- %WINDIR%\mozila\directx.log
- %WINDIR%\mozila\enc_config.ini
- %WINDIR%\mozila\enc_config.ini в %WINDIR%\mozila\config.ini
- %WINDIR%\mozila\enc_config.ini
- DNS ASK ft#.#ecuina.net
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "%WINDIR%\mozila\txt.vbs"
- '%WINDIR%\mozila\ixpers.exe' -R
- '%WINDIR%\mozila\ixpers.exe' -I
- '%WINDIR%\mozila\ixpers.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%WINDIR%\mozila\fs.bat" " (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\powerpnt.exe' "%WINDIR%\mozila\Butterfly That Never Flew.ppt"
- '%WINDIR%\syswow64\attrib.exe' +s +h %WINDIR%\mozila