Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\SysDirv.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\SysDirv.lnk
- '%HOMEPATH%\down.exe'
- '<SYSTEM32>\ipconfig.exe' /all
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\xcopy.exe' "%TEMP%\SysDirv.lnk" "%HOMEPATH%\Start Menu\Programs\Startup" /Y
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shell32.dll,OpenAs_RunDLL %HOMEPATH%\Confidential.pdf
- '<SYSTEM32>\xcopy.exe' "%TEMP%\SysDirv.lnk" "%ALLUSERSPROFILE%\Start Menu\Programs\Startup" /Y
- %TEMP%\SysDirv.lnk
- %TEMP%\iconfall.log
- <LS_APPDATA>\MZミ
- %HOMEPATH%\Confidential.pdf
- %HOMEPATH%\down.exe
- %HOMEPATH%\fol.ico
- %HOMEPATH%\fol.ico
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- <SYSTEM32>\PerfStringBackup.TMP
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\root[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\root[1].php
- 'go##obs.net':80
- go##obs.net/holi/CRNJEUFU@URNXYMAV/MZ???
- go##obs.net/holi/root.php?cn##################################
- DNS ASK go##obs.net
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''