Техническая информация
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\svchost.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\svchost.exe
- <SYSTEM32>\attrib.exe +h "%ALLUSERSPROFILE%\Start Menu\Programs\Startup"
- %WINDIR%\confirm85.txt
- %TEMP%\~DFC4BF.tmp
- 'r3###1gn.ath.cx':8965
- DNS ASK r3###1gn.ath.cx
- ClassName: 'Shell_TrayWnd' WindowName: ''