Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] '{3373CD28-8C35-4A36-8569-672D8CA197F5}' = ''
- %WINDIR%\Tasks\4H5HJTHFZkxrCpehBpx4TmR.inf
- %WINDIR%\Tasks\ZsJWEjDqyh2vTuUZF.ico
- <SYSTEM32>\net1.exe stop sharedaccess
- <SYSTEM32>\net.exe stop sharedaccess
- AVP.EXE
- %TEMP%\m.exe
- %TEMP%\m.exe
- ClassName: 'Shell_TrayWnd' WindowName: ''