Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'antivirus' = '%APPDATA%\auto.exe %APPDATA%\run.ahk'
- %HOMEPATH%\Start Menu\Programs\Startup\windowsupdate.Lnk
- '<SYSTEM32>\cscript.exe' %APPDATA%\Deman.wsf
- '%ProgramFiles%\Windows NT\Accessories\wordpad.exe' "%APPDATA%\abubaker.doc"
- %TEMP%\ms809.tmp
- %APPDATA%\AutoIt3.exe
- %APPDATA%\stub.au3
- %APPDATA%\abubaker.doc
- %APPDATA%\run.ahk
- %APPDATA%\Deman.wsf
- %APPDATA%\AutoIt3.exe
- %APPDATA%\stub.au3
- %APPDATA%\abubaker.doc
- %APPDATA%\Deman.wsf
- 'ti##url.com':80
- http://ti##url.com/nn4b22x
- http://ti##url.com/orolftl
- DNS ASK ti##url.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'WordPadClass' WindowName: ''