Техническая информация
- <SYSTEM32>\at.exe 19:40 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\hti.exe""
- <SYSTEM32>\at.exe 19:45 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\xtr.exe""
- <SYSTEM32>\at.exe 19:35 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\bch.exe""
- <SYSTEM32>\at.exe 19:25 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\cdi.exe""
- <SYSTEM32>\at.exe 19:30 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\dss.exe""
- %TEMP%\nsj3.tmp\ns7.tmp
- %TEMP%\nsj3.tmp\ns6.tmp
- %TEMP%\nsj3.tmp\ns5.tmp
- %TEMP%\nsj3.tmp\ns8.tmp
- C:\ndf
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\counter[1].php
- %TEMP%\nsj3.tmp\inetc.dll
- %TEMP%\nsj3.tmp\ns4.tmp
- %WINDIR%\dss.exe
- %WINDIR%\cdi.exe
- %TEMP%\nsd2.tmp
- %WINDIR%\bch.exe
- %TEMP%\nsj3.tmp\nsExec.dll
- %WINDIR%\xtr.exe
- %WINDIR%\hti.exe
- %WINDIR%\hti.exe
- %WINDIR%\xtr.exe
- C:\ndf
- %WINDIR%\cdi.exe
- %WINDIR%\dss.exe
- %WINDIR%\bch.exe
- %TEMP%\nsj3.tmp\ns8.tmp
- %TEMP%\nsj3.tmp\inetc.dll
- %TEMP%\nsj3.tmp\nsExec.dll
- %TEMP%\nsj3.tmp\ns7.tmp
- %TEMP%\nsj3.tmp\ns4.tmp
- %TEMP%\nsj3.tmp\ns5.tmp
- %TEMP%\nsj3.tmp\ns6.tmp
- '12#.#17.235.76':80
- 12#.#17.235.76/games/counter.php
- ClassName: 'Shell_TrayWnd' WindowName: ''