Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Windows DNS' = '"%WINDIR%\wni\winacs.exe" %WINDIR%\wni'
- <SYSTEM32>\attrib.exe "%WINDIR%/wni/index.html"
- <SYSTEM32>\attrib.exe "%WINDIR%/wni" +s +h +r /S /D
- <SYSTEM32>\cmd.exe /c ""%TEMP%\dir.bat" "
- <SYSTEM32>\attrib.exe "%WINDIR%/wni/winacs.exe" +s +h +r /S /D
- %TEMP%\dir.bat
- %WINDIR%\wni\index.html
- %WINDIR%\wni\winacs.exe
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\12345
- %WINDIR%\wni\winacs.exe
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- ClassName: 'Shell_TrayWnd' WindowName: ''