Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\SysDir.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\SysDir.lnk
- '<SYSTEM32>\ipconfig.exe' /all
- '<SYSTEM32>\xcopy.exe' "%TEMP%\SysDir.lnk" "%HOMEPATH%\Start Menu\Programs\Startup" /Y
- '<SYSTEM32>\xcopy.exe' "%TEMP%\SysDir.lnk" "%ALLUSERSPROFILE%\Start Menu\Programs\Startup" /Y
- <LS_APPDATA>\MZミ
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\rt[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\rt[1].php
- %TEMP%\SysDir.lnk
- %TEMP%\iconfall.log
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\rt[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\rt[1].php
- 'si###erwork.net':80
- si###erwork.net/joy/CRNJEUFU@URNXYMAV/MZ???
- si###erwork.net/joy/rt.php?cn###############################
- DNS ASK si###erwork.net
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'