Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'MySiren' = '"%PROGRAM_FILES%\MySiren\MySiren.exe" -h -boot'
- %PROGRAM_FILES%\MySiren\MySirenUI.exe -whitgame -install
- <SYSTEM32>\cmd.exe /c \DelUS.bat
- %ALLUSERSPROFILE%\Application Data\MySiren\Data\mysmwt.mys
- %PROGRAM_FILES%\MySiren\Uninstall.exe
- %ALLUSERSPROFILE%\Application Data\MySiren\Data\myscls.mys
- %ALLUSERSPROFILE%\Application Data\MySiren\Data\mysidc.mys
- %HOMEPATH%\Start Menu\Programs\ё¶АМ»зАМ·»\»з»эИ°Б¤єё БцЕґАМ ЅЗЗа.lnk
- %TEMP%\nsq2.tmp\DelSelf.dll
- C:\DelUS.bat
- %HOMEPATH%\Start Menu\Programs\ё¶АМ»зАМ·»\»з»эИ°Б¤єё БцЕґАМ ѕИі».url
- %HOMEPATH%\Desktop\»з»эИ°Б¤єё БцЕґАМ.lnk
- %PROGRAM_FILES%\MySiren\MySirenMT.exe
- %PROGRAM_FILES%\MySiren\MySirenUI.exe
- %TEMP%\nsq2.tmp\System.dll
- %PROGRAM_FILES%\MySiren\MySiren.exe
- %PROGRAM_FILES%\MySiren\MySirenUpdater.exe
- %PROGRAM_FILES%\MySiren\lang\MySiren.lng
- %ALLUSERSPROFILE%\Application Data\MySiren\Data\myshis.mys
- %PROGRAM_FILES%\MySiren\myshis.dll
- %PROGRAM_FILES%\MySiren\mysidc.dll
- %TEMP%\nsq2.tmp\System.dll
- %TEMP%\nsq2.tmp\DelSelf.dll
- 'lo#.##siren.co.kr':80
- lo#.##siren.co.kr/app/count_post.asp
- DNS ASK lo#.##siren.co.kr