Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\open.vbe
- '%WINDIR%\hot.exe'
- '<SYSTEM32>\wscript.exe' "%WINDIR%\updateLnk.vbe" 0
- '%WINDIR%\regedit.exe' /s <SYSTEM32>\reg.reg
- '%WINDIR%\regedit.exe' /s %WINDIR%\StrongIndex.reg
- <SYSTEM32>\drwtsn32.exe
- <SYSTEM32>\qq.exe
- %WINDIR%\updateLnk.vbe
- %PROGRAM_FILES%\Internet Explorer\iexlore.exe
- <SYSTEM32>\reg.reg
- %WINDIR%\StrongIndex.reg
- %WINDIR%\hot.exe
- %TEMP%\c3cc_appcompat.txt
- %TEMP%\~DF862.tmp
- ClassName: 'RegEdit_RegEdit' WindowName: ''