Техническая информация
- <SYSTEM32>\nwwscript.exe "<SYSTEM32>\c_12255.nls"
- <SYSTEM32>\at.exe 19:42 /every:Th "<SYSTEM32>\nwwscript.exe"
- <SYSTEM32>\regsvr32.exe /s "<SYSTEM32>\xollehlp.dll"
- <SYSTEM32>\xollehlp.dll
- %TEMP%\3070117190.bin
- <SYSTEM32>\3063\inf3063.dat
- <SYSTEM32>\c_12255.nls
- %TEMP%\2734828588.bin
- %TEMP%\270519167.tmp
- <SYSTEM32>\nwwscript.exe
- %TEMP%\2734828588.bin
- %TEMP%\270519167.tmp
- ClassName: 'Shell_TrayWnd' WindowName: ''