Техническая информация
- <SYSTEM32>\at.exe 22:25 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\pdwa.exe""
- <SYSTEM32>\at.exe 22:29 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\dtmn.exe""
- <SYSTEM32>\at.exe 22:21 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\wtsx.exe""
- <SYSTEM32>\at.exe 22:13 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\uhcd.exe""
- <SYSTEM32>\at.exe 22:17 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\kdhr.exe""
- %TEMP%\nsz3.tmp\ns5.tmp
- %TEMP%\nsz3.tmp\ns4.tmp
- %TEMP%\nsz3.tmp\nsExec.dll
- %TEMP%\nsz3.tmp\ns8.tmp
- %TEMP%\nsz3.tmp\ns7.tmp
- %TEMP%\nsz3.tmp\ns6.tmp
- %WINDIR%\kdhr.exe
- %WINDIR%\uhcd.exe
- %TEMP%\nsj2.tmp
- %WINDIR%\dtmn.exe
- %WINDIR%\pdwa.exe
- %WINDIR%\wtsx.exe
- %WINDIR%\pdwa.exe
- %WINDIR%\dtmn.exe
- %WINDIR%\wtsx.exe
- %WINDIR%\uhcd.exe
- %WINDIR%\kdhr.exe
- %TEMP%\nsz3.tmp\ns7.tmp
- %TEMP%\nsz3.tmp\ns8.tmp
- %TEMP%\nsz3.tmp\nsExec.dll
- %TEMP%\nsz3.tmp\ns4.tmp
- %TEMP%\nsz3.tmp\ns5.tmp
- %TEMP%\nsz3.tmp\ns6.tmp
- ClassName: 'SysListView32' WindowName: ''
- ClassName: '#32770' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''