Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'systrice' = '%ProgramFiles%\Windows Media Player\systrice.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'msserver' = '%ProgramFiles%\Internet Explorer\msserver.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%WINDIR%\netfile.exe'
- %ProgramFiles%\Internet Explorer\msserver.exe
- %ProgramFiles%\Windows Media Player\systrice.exe
- %TEMP%\~DF5AD0.tmp
- %WINDIR%\netfile.exe