Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\SysDir.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\SysDir.lnk
- '%HOMEPATH%\spool.exe'
- '<SYSTEM32>\ipconfig.exe' /all
- '<SYSTEM32>\xcopy.exe' "%TEMP%\SysDir.lnk" "%HOMEPATH%\Start Menu\Programs\Startup" /Y
- '<SYSTEM32>\xcopy.exe' "%TEMP%\SysDir.lnk" "%ALLUSERSPROFILE%\Start Menu\Programs\Startup" /Y
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\rt[1].php
- %TEMP%\iconfall.log
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\rt[1].php
- <LS_APPDATA>\MZミ
- %HOMEPATH%\spool.exe
- %HOMEPATH%\Chat.doc
- %TEMP%\ms1133.tmp
- %TEMP%\SysDir.lnk
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\rt[1].php
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\rt[1].php
- 'si###erwork.net':80
- si###erwork.net/examresult/CRNJEUFU@URNXYMAV/MZ???
- si###erwork.net/examresult/rt.php?cn###############################
- DNS ASK si###erwork.net
- ClassName: 'WordPadClass' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'