Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'EXPLORER' = 'EXPL0RER.EXE'
- <SYSTEM32>\EXPL0RER.EXE "%WINDIR%\TEMP#01.EXE"
- %WINDIR%\TEMP#01.EXE
- %WINDIR%\TEMP$01.EXE
- ClassName: 'RegMonClass' WindowName: ''
- ClassName: 'FileMonClass' WindowName: ''
- <SYSTEM32>\win32log.dat
- <SYSTEM32>\EXPL0RER.EXE
- <SYSTEM32>\Пн_Вер_24_2012.txt
- %WINDIR%\TEMP$01.EXE
- %WINDIR%\TEMP#01.EXE
- <SYSTEM32>\EXPL0RER.EXE
- 'any':25
- ClassName: 'Shell_TrayWnd' WindowName: ''