Техническая информация
- '<SYSTEM32>\schtasks.exe' /create /sc onlogon /tn "AntivirusFolder" /rl highest /tr "'%ProgramFiles%\Client\WindowsUpdate.exe' /startup" /f
- <SYSTEM32>\svchost.exe
- %TEMP%\NOTE-datetime-970915
- %TEMP%\collapse.min.js
- %TEMP%\74fgkCnB0edxkJQ3u185tmTz1GKvcbfx.P
- %ProgramFiles%\Client\WindowsUpdate.exe
- %TEMP%\nsk3.tmp\System.dll
- %TEMP%\home
- %TEMP%\fr
- %TEMP%\nsm2.tmp
- %TEMP%\public
- %TEMP%\favicon.ico893736346vnd.microsoft.icon
- %TEMP%\feedback
- 'localhost':1110
- '21#.#.192.248':1110