Техническая информация
- <SYSTEM32>\wscript.exe "%PROGRAM_FILES%\ringoo ho kjsaq\nada rano vsavat\ee\87dba6b5e5e739d7a8506bbceb19e4be.vbs"
- <SYSTEM32>\wscript.exe "%PROGRAM_FILES%\ringoo ho kjsaq\nada rano vsavat\ee\63c4da4fde984fa5c719cdcf2147ab7f.vbs"
- <SYSTEM32>\cmd.exe /c ""%PROGRAM_FILES%\ringoo ho kjsaq\nada rano vsavat\1ca0a320b7bd66069c01d79c71e2349.bat" "
- %HOMEPATH%\Recent\63c4da4fde984fa5c719cdcf2147ab7f.lnk
- %PROGRAM_FILES%\ringoo ho kjsaq\nada rano vsavat\ee\87dba6b5e5e739d7a8506bbceb19e4be.vbs
- %HOMEPATH%\Recent\87dba6b5e5e739d7a8506bbceb19e4be.lnk
- %HOMEPATH%\Recent\ee.lnk
- %PROGRAM_FILES%\ringoo ho kjsaq\nada rano vsavat\ee\63c4da4fde984fa5c719cdcf2147ab7f.vbs
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- %PROGRAM_FILES%\ringoo ho kjsaq\nada rano vsavat\1ca0a320b7bd66069c01d79c71e2349.bat
- %PROGRAM_FILES%\ringoo ho kjsaq\nada rano vsavat\ee\aaaaaaaaaaaaaaa.aa.aa
- %HOMEPATH%\Recent\ee.lnk
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- '19#.#41.191.138':1999
- 'localhost':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''