Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\sdfkbLO] 'Start' = '00000002'
- <SYSTEM32>\gornpK.exe
- %PROGRAM_FILES%\invspt.exe
- <SYSTEM32>\ping.exe -n 10 127.0.0.1
- <SYSTEM32>\reg.exe add "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main" /v "Start Page" /t reg_sz /d "http://www.32##11.cn/hao123.com.html" /f
- <SYSTEM32>\cmd.exe /c ""%PROGRAM_FILES%\pasvmp.bat" "
- C:\МФ±¦99РЕУюµкЖМ№єОпНЖјц.url
- %HOMEPATH%\Favorites\МФ±¦99РЕУюµкЖМ№єОпНЖјц.url
- %HOMEPATH%\Start Menu\МФ±¦99РЕУюµкЖМ№єОпНЖјц.url
- <SYSTEM32>\gornpK.exe
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\МФ±¦99РЕУюµкЖМ№єОпНЖјц.url
- %HOMEPATH%\My Documents\МФ±¦99РЕУюµкЖМ№єОпНЖјц.url
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\7.tmp
- %TEMP%\$inst\2.tmp
- %HOMEPATH%\Desktop\МФ±¦99РЕУюµкЖМ№єОпНЖјц.url
- %PROGRAM_FILES%\invspt.exe
- %PROGRAM_FILES%\pasvmp.bat
- <SYSTEM32>\gornpK.exe
- %TEMP%\$inst\7.tmp
- %PROGRAM_FILES%\invspt.exe
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- ClassName: 'Shell_TrayWnd' WindowName: ''