Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Explorer.exe' = '%APPDATA%\Roaming\sample.exe'
- '%APPDATA%\Roaming\sample.exe' /AutoIt3ExecuteScript "%TEMP%\431878" "%APPDATA%\Roaming\sample.exe"
- '%APPDATA%\Roaming\sample.exe'
- '<SYSTEM32>\PING.EXE' -n 0127.0.0.1
- %TEMP%\aut14C7.tmp
- %TEMP%\54.bat
- %APPDATA%\Roaming\sample.exe
- %TEMP%\1685
- %TEMP%\431878
- %TEMP%\aut14E8.tmp
- %TEMP%\aut14D8.tmp
- %TEMP%\autBC.tmp
- %TEMP%\232331
- %TEMP%\aut9C.tmp
- %TEMP%\incl1
- %TEMP%\471868
- %TEMP%\incl2
- %TEMP%\autCC.tmp
- %APPDATA%\Roaming\sample.exe
- %TEMP%\aut14C7.tmp
- %TEMP%\aut14D8.tmp
- %TEMP%\aut14E8.tmp
- %TEMP%\471868
- %TEMP%\aut9C.tmp
- %TEMP%\autBC.tmp
- %TEMP%\autCC.tmp
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''