Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\Google Chrome.lnk
- %HOMEPATH%\Start Menu\Programs\Startup\Google Chrome.URL
- %HOMEPATH%\Start Menu\Programs\Startup\Google Chrome.js
- %HOMEPATH%\Start Menu\Programs\Startup\Client.exe
- %HOMEPATH%\Start Menu\Programs\Startup\Google Chrome.vbs
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
- %TEMP%\obpvj4er.0.vb
- %TEMP%\obpvj4er.cmdline
- %APPDATA%\ScriptHub.exe
- C:\AUTOEXEC.BAT.exe
- %TEMP%\vbc5.tmp
- %TEMP%\RES6.tmp
- %TEMP%\obpvj4er.out
- %TEMP%\vbc4.tmp
- %TEMP%\RES3.tmp
- C:\ProgramData\GoogleChrome\AUTOEXEC.ico
- %TEMP%\s1unwksx.0.vb
- %TEMP%\POciqXU.txt
- C:\GoogleChrome\Client.exe
- %TEMP%\vbc1.tmp
- %TEMP%\vbc2.tmp
- %TEMP%\s1unwksx.cmdline
- %TEMP%\s1unwksx.out
- C:\GoogleChrome\Client.exe
- %TEMP%\vbc2.tmp
- %TEMP%\RES3.tmp
- %TEMP%\s1unwksx.cmdline
- '<LOCALNET>.1.3':333
- '<LOCALNET>.1.1':333
- '%APPDATA%\ScriptHub.exe'
- '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\vbc.exe' /noconfig @"%TEMP%\obpvj4er.cmdline"
- '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES6.tmp" "%TEMP%\vbc5.tmp"
- '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES3.tmp" "%TEMP%\vbc2.tmp"
- '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe'
- '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\vbc.exe' /noconfig @"%TEMP%\s1unwksx.cmdline"