Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RavTroy' = '"%WINDIR%\debug\debug.exe" /start'
- '%WINDIR%\Debug\debug.exe'
- '<SYSTEM32>\ping.exe' /n 2 /w 400 1.1
- '%WINDIR%\regedit.exe' /s 1.reg
- '<SYSTEM32>\wscript.exe' "%WINDIR%\debug\run.vbe"
- %WINDIR%\Debug\run.vbe
- %WINDIR%\Debug\debug.exe
- %WINDIR%\Debug\run.bat
- %WINDIR%\Debug\1.reg
- %WINDIR%\Debug\inin.ini
- %WINDIR%\Debug\1.reg
- %WINDIR%\Debug\run.vbe
- DNS ASK si####lp.zjfm.com
- 'si####lp.zjfm.com':8000
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''