Техническая информация
- [<HKLM>\SOFTWARE\Classes\.scr] '' = 'scrfile'
- [<HKLM>\SOFTWARE\Classes\scrfile\shell\open\command] '' = ''
- [<HKLM>\SOFTWARE\Classes\.exe] '' = 'exefile'
- [<HKLM>\SOFTWARE\Classes\exefile\shell\open\command] '' = ''
- <SYSTEM32>\reg.exe delete HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /f /v "StartUp"
- <SYSTEM32>\reg.exe delete HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /f /v "StartUpCheck"
- %WINDIR%\Explorer.EXE
- %WINDIR%\rules.dat
- %WINDIR%\wndsk.dll
- из <Полный путь к вирусу> в %WINDIR%\trashicon.exe