Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'explorer' = '"%TEMP%\iexplorer.exe" [1]'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'explorer' = '"%TEMP%\iexplorer.exe" [1]'
- '%TEMP%\iexplorer.exe' [1]
- '<SYSTEM32>\svchost.exe' [2]
- '<SYSTEM32>\wscript.exe' %TEMP%\iexplorer.exetmp.vbstmp1.vbs
- '<SYSTEM32>\wscript.exe' "%TEMP%\iexplorer.exetmp.vbs" "<Полный путь к вирусу>" "%TEMP%\iexplorer.exe"
- <SYSTEM32>\svchost.exe
- %TEMP%\iexplorer.exe
- %TEMP%\iexplorer.exetmp.vbstmp1.vbs
- %TEMP%\iexplorer.exetmp.vbs
- %TEMP%\iexplorer.exetmp.vbstmp1.vbs
- %TEMP%\iexplorer.exetmp.vbs
- '91.##9.23.29':1992
- ClassName: 'Indicator' WindowName: ''