Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awttrPJB] 'Logon' = 'o'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awttrPJB] 'DllName' = 'awttrPJB.dll'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] '{1F9B4E9A-2117-4954-BB33-A09A3185D67C}' = ''
- <SYSTEM32>\cmd.exe /c %TEMP%\removalfile.bat "<Полный путь к вирусу>"
- <SYSTEM32>\rundll32.exe ,a
- <SYSTEM32>\winlogon.exe
- %TEMP%\removalfile.bat
- <SYSTEM32>\awttrPJB.dll
- ClassName: 'Shell_TrayWnd' WindowName: ''