Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'antivirus' = '<SYSTEM32>\wscript.exe %APPDATA%\reports.wsf'
- %HOMEPATH%\Start Menu\Programs\Startup\windowsupdate.Lnk
- '<SYSTEM32>\cscript.exe' %APPDATA%\reports.wsf
- '%ProgramFiles%\Windows NT\Accessories\wordpad.exe' "%APPDATA%\reportnew.doc"
- %APPDATA%\reports.wsf
- %APPDATA%\reportnew.doc
- %APPDATA%\reports.wsf
- %APPDATA%\reportnew.doc
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'WordPadClass' WindowName: ''