Техническая информация
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\SHQ.DLL
- <SYSTEM32>\REGKEY.hiv
- %TEMP%\SHQ.DLL
- C:\Privilege.dat
- %TEMP%\SHQMANGR.DLL
- <SYSTEM32>\SHQMANGR.DLL
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- <SYSTEM32>\REGKEY.hiv
- C:\Privilege.dat в <SYSTEM32>\LYLOADMR.EXE