Техническая информация
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe tobi0a0c.exe %WINDIR%\winbase_base_procid_none\secureloc0x65\tobi0a0c.exe'
- %WINDIR%\winbase_base_procid_none\0x000f.wav
- %WINDIR%\winbase_base_procid_none\bgtheme.jpg
- %WINDIR%\winbase_base_procid_none\bsector3.exe
- %WINDIR%\winbase_base_procid_none\filesmove.exe
- %WINDIR%\winbase_base_procid_none\mainbgtheme.wav
- %WINDIR%\winbase_base_procid_none\rcur.cur
- %WINDIR%\winbase_base_procid_none\readme(mrsmajor3.0).txt
- %WINDIR%\winbase_base_procid_none\tobi0a0c.exe
- %WINDIR%\winbase_base_procid_none\ui65.exe
- %WINDIR%\winbase_base_procid_none\ui66.exe
- %WINDIR%\winbase_base_procid_none\winrapisti386.vbs
- %WINDIR%\winbase_base_procid_none\winsxs.ico
- %WINDIR%\winbase_base_procid_none\lau.bat
- nul
- ClassName: 'Edit' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\winbase_base_procid_none\lau.bat" "
- '<SYSTEM32>\cacls.exe' "<SYSTEM32>\config\system"
- '<SYSTEM32>\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /f /v "Shell" /t REG_SZ /d "explorer.exe tobi0a0c.exe "%WINDIR%\winbase_base_procid_none\secureloc0x65\tobi0a0c.ex...