Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Explorer' = '<SYSTEM32>\wscript "%APPDATA%\Windows\%USERNAME%.vbs"'
- [<HKLM>\SYSTEM\ControlSet001\Services\Dhcp] 'Start' = '00000002'
- '<SYSTEM32>\cscript.exe' "%APPDATA%\%USERNAME%.vbs"
- %APPDATA%\Windows\x64\explorer.exe
- %APPDATA%\Windows\%USERNAME%.vbs
- %APPDATA%\Windows\x86\zlib1.dll
- %APPDATA%\Windows\x64\zlib1.dll
- %APPDATA%\Windows\x64\pthreadGC2.dll
- %APPDATA%\Windows\x64\libcurl.dll
- %APPDATA%\%USERNAME%.vbs
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- %APPDATA%\Windows\x86\pthreadGC2.dll
- %APPDATA%\Windows\x86\libcurl-4.dll
- %APPDATA%\Windows\x86\explorer.exe
- %TEMP%\$inst\2.tmp
- %APPDATA%\%USERNAME%.vbs
- %TEMP%\$inst\temp_0.tmp
- ClassName: 'Indicator' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'