Техническая информация
- %WINDIR%\regedit.exe /s ie.reg
- <SYSTEM32>\cmd.exe /c """%TEMP%\1.tmp\Virus.bat"" "
- [<HKCU>\Software\Microsoft\Internet Explorer\Main] 'Window Title' = 'VIRUS-VIRUS-VIRUS-VIRUS-VIRUS-VIRUS-THANKS FOR OPENING MY VIRUS!'
- %TEMP%\1.tmp\Virus.bat
- <Текущая директория>\ie.reg
- %TEMP%\1.tmp\binaries.txt
- %TEMP%\1.tmp\b2e
- %TEMP%\1.tmp\b2e.dll
- <Текущая директория>\ie.reg
- %TEMP%\1.tmp\b2e.dll
- %TEMP%\1.tmp\Virus.bat
- %TEMP%\1.tmp\binaries.txt
- %TEMP%\1.tmp\b2e
- ClassName: 'RegEdit_RegEdit' WindowName: ''