Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\Sound Balance Control.lnk
- %HOMEPATH%\Start Menu\Programs\Startup\HDDrive.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\HDDrive.lnk
- '%HOMEPATH%\programs\winhost.exe'
- '%HOMEPATH%\programs\wincedit.exe'
- '<SYSTEM32>\ipconfig.exe' /all
- '<SYSTEM32>\systeminfo.exe'
- '<SYSTEM32>\xcopy.exe' "%TEMP%\HDDrive.lnk" "%HOMEPATH%\Start Menu\Programs\Startup" /Y
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shell32.dll,OpenAs_RunDLL %HOMEPATH%\programs\Pending_Parcel_Details.docx
- '<SYSTEM32>\xcopy.exe' "%TEMP%\HDDrive.lnk" "%ALLUSERSPROFILE%\Start Menu\Programs\Startup" /Y
- %TEMP%\iconfall.log
- %TEMP%\HDDrive.lnk
- %TEMP%\syinf.log
- %TEMP%\store.log
- %TEMP%\Sound Balance Control.lnk
- %HOMEPATH%\programs\Pending_Parcel_Details.docx
- %HOMEPATH%\programs\winhost.exe
- %HOMEPATH%\programs\wincedit.exe
- %HOMEPATH%\programs\cdata.txt
- 'cl###ham.com':80
- cl###ham.com/vwrk.php
- DNS ASK cl###ham.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'