Техническая информация
- <SYSTEM32>\at.exe 20:00 /every:M,T,W,Th,F,Sa,Su """%TEMP%\mfpmpb.exe"""
- %TEMP%\nsp3.tmp\nsExec.dll
- %TEMP%\nsp3.tmp\ns4.tmp
- %TEMP%\hl2.exe
- %TEMP%\nst2.tmp
- %TEMP%\mfpmpb.exe
- %TEMP%\hl2.exe
- %TEMP%\mfpmpb.exe
- %TEMP%\nsp3.tmp\nsExec.dll
- %TEMP%\nsp3.tmp\ns4.tmp
- ClassName: 'Shell_TrayWnd' WindowName: ''