Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'RMPx85' = '<SYSTEM32>\Info.exe'
- '<SYSTEM32>\attrib.exe' +S +H +R +A "\Info.exe"
- '<SYSTEM32>\attrib.exe' +S +H +R +A "<SYSTEM32>\Info.exe"
- '<SYSTEM32>\find.exe' /i "extra"
- '<SYSTEM32>\wbem\wmic.exe' logicaldisk get caption, description
- '<SYSTEM32>\reg.exe' DELETE HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v RMPx85 /f
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\BuscaArchivos2485.bat" "
- '<SYSTEM32>\attrib.exe' -S -H +R +A "\Info.exe"
- '<SYSTEM32>\reg.exe' ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v RMPx85 /t REG_SZ /d <SYSTEM32>\Info.exe
- %TEMP%\tmp2.tmp
- %TEMP%\tmp3.tmp
- %TEMP%\1.tmp\BuscaArchivos2485.bat
- <Текущая директория>\viva bolivia.jpg
- %TEMP%\tmp2.tmp
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''