Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] '' = '%HOMEPATH%\Local Settings\Microsoft\dllhost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] '' = '"%HOMEPATH%\Local Settings\Microsoft\Windows Live\Explorer.exe" /RunOnce'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '' = '%HOMEPATH%\Local Settings\Hewlett-Packard\SynTPE.exe'
- <SYSTEM32>\schtasks.exe /delete /f /tn "WindowsExplore"
- <SYSTEM32>\schtasks.exe /create /tn "WindowsExplore" /tr "'%HOMEPATH%\Local Settings\Microsoft\Windows\Explorer\iexplore.exe'" /sc ONLOGON /ru "CRNJEUFU\%USERNAME%"
- <SYSTEM32>\schtasks.exe /delete /f /tn "WinManager"
- <SYSTEM32>\schtasks.exe /create /tn "WinManager" /tr "'%HOMEPATH%\Local Settings\Microsoft\Windows\Manager.exe'" /sc ONLOGON /ru "CRNJEUFU\%USERNAME%"
- %TEMP%\winlogon.exe
- ClassName: 'Shell_TrayWnd' WindowName: ''