Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\Security.lnk
- '%TEMP%\123\JoinM.exe'
- '%TEMP%\vk\vk.sfx.exe' -p322 -d%TEMP%\vk2
- '<SYSTEM32>\cmd.exe' /c start C:\ProgramData\System32\Security.exe
- 'C:\ProgramData\System32\Security.exe'
- '%TEMP%\vk2\LastBuild.exe'
- '%TEMP%\vk\JoinU.sfx.exe' -p322 -d%TEMP%\123
- '%TEMP%\vk\JoinUs.exe'
- '%TEMP%\changess\333.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\2896JUTM.bat" "%TEMP%\vk\JoinUs.exe" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\2912A6OT.bat" "%TEMP%\vk\vks.exe" "
- '%TEMP%\vk\vks.exe'
- C:\ProgramData\System32\system.exe
- C:\ProgramData\System32\1.bat
- %TEMP%\vk2\php5ts.dll
- %TEMP%\PSE20\d054c3591e5a105c53729f121c48a425\php.ini
- %TEMP%\vk2\LastBuild.exe
- C:\ProgramData\System32\Security.exe
- %TEMP%\vk\JoinU.sfx.exe
- %TEMP%\vk\JoinUs.exe
- %TEMP%\changess\333.exe
- %TEMP%\123\JoinM.exe
- %TEMP%\vk\vk.sfx.exe
- %TEMP%\vk\vks.exe
- %TEMP%\2912A6OT.bat
- %TEMP%\2896JUTM.bat
- %TEMP%\aut3.tmp
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''