Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Ias] 'Start' = '00000002'
- <SYSTEM32>\cmd.exe /c """%TEMP%\win.bat"" "
- <SYSTEM32>\services.exe
- <SYSTEM32>\Iasid.dll.move.tlb
- <SYSTEM32>\Iasid.dll.temp.tlb
- <SYSTEM32>\Iasid.dll.right.tlb
- %TEMP%\win
- %ALLUSERSPROFILE%\Application Data\Iasid.dll
- <SYSTEM32>\cc.exetem.tem
- %TEMP%\108468na.dll
- C:\RECYCLER\recyl.exe
- <SYSTEM32>\cc.execyl.txt
- %WINDIR%\Temp\108906cnna.txt
- ClassName: 'Shell_TrayWnd' WindowName: ''