Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows live Messeger' = '<SYSTEM32>\arquivo.exe'
- '<SYSTEM32>\arquivo.exe'
- '%WINDIR%\extrator.exe'
- <SYSTEM32>\arquivo.exe
- <SYSTEM32>\ssleay32.dll
- <SYSTEM32>\arquivocompactado.exe
- %WINDIR%\extrator.exe
- <SYSTEM32>\arquivocompactado2.exe
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'