Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\9waQe17J.lnk
- %HOMEPATH%\Favorites\Links\!T0_Rest0re_Y0ur_FilEs_ReadMe!.rtf
- %HOMEPATH%\Favorites\!T0_Rest0re_Y0ur_FilEs_ReadMe!.rtf
- %TEMP%\UPOWNahJ.exe
- %HOMEPATH%\Templates\!T0_Rest0re_Y0ur_FilEs_ReadMe!.rtf
- %HOMEPATH%\Start Menu\Programs\Startup\9waQe17J.lnk
- '<SYSTEM32>\cacls.exe' "%HOMEPATH%\NTUSER.DAT" /E /G %USERNAME%:F /C
- '<SYSTEM32>\attrib.exe' -R -A -H "%HOMEPATH%\NTUSER.DAT"
- '<SYSTEM32>\cmd.exe' /C CACLS "%HOMEPATH%\NTUSER.DAT" /E /G %USERNAME%:F /C & ATTRIB -R -A -H "%HOMEPATH%\NTUSER.DAT"
- '<SYSTEM32>\cmd.exe' /C attrib +H "%HOMEPATH%\Start Menu\Programs\Startup\9waQe17J.lnk"
- '<SYSTEM32>\attrib.exe' +H "%HOMEPATH%\Start Menu\Programs\Startup\9waQe17J.lnk"