Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,%WINDIR%\system\csrss.exe,'
- '%WINDIR%\system\csrss.exe'
- '<SYSTEM32>\cmd.exe' /c %WINDIR%\\system\del.bat
- '<SYSTEM32>\attrib.exe' <DRIVERS>\etc\hosts -r -s -h
- '<SYSTEM32>\attrib.exe' <DRIVERS>\etc\hosts.ics -r -s -h
- iexplore.exe
- %WINDIR%\system\del.bat
- %WINDIR%\system\csrss.exe
- %WINDIR%\regini.ini
- <DRIVERS>\etc\hosts
- ClassName: 'IEFrame' WindowName: '(null)'
- ClassName: 'DBL' WindowName: 'DBL'