Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\Microsoft Update.lnk
- '%TEMP%\{EB36B906-2994-4EE8-8DA6-FB7148BD8C14}\.cr\NCOXKA.exe' -burn.clean.room="%TEMP%\NCOXKA.exe"
- '%TEMP%\NCOXKA.exe'
- %TEMP%\NCOXKA.exe
- %TEMP%\Avira_Connect_20170703105906.log
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- %TEMP%\cvkkxrj
- %TEMP%\aut2.tmp
- %TEMP%\cvkkxrj
- %TEMP%\aut1.tmp
- 'so####lrat.ddns.net':1177
- DNS ASK so####lrat.ddns.net
- ClassName: 'Shell_TrayWnd' WindowName: ''