Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Taskmgr' = '%WINDIR%\system\reload.bat'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'update' = '%WINDIR%\system\update.scr'
- '<SYSTEM32>\reg.exe' add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v Taskmgr /t reg_sz /d %WINDIR%\system\reload.bat /f
- '<SYSTEM32>\reg.exe' add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v update /t reg_sz /d %WINDIR%\system\update.scr /f
- %WINDIR%\system\reload.bat
- %WINDIR%\system\update
- %WINDIR%\system\update в %WINDIR%\system\update.scr
- 'dr####a1.no-ip.biz':1234
- DNS ASK dr####a1.no-ip.biz
- ClassName: 'Tapplication' WindowName: 'ULTIMOS DIAS'