Техническая информация
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\WinInetDriver.url
- %ProgramFiles%\Games\news.bat
- %ProgramFiles%\Games\Video.sfx.exe
- %ProgramFiles%\Games\MoranaBattory.mp4
- C:\program\Video.exe
- %TEMP%\NetEvtFwdr.exe
- %TEMP%\MicrosoftCommon.exe
- %TEMP%\errorEredel.log
- %TEMP%\tmp1.tmp
- %TEMP%\tmp2.tmp
- %ALLUSERSPROFILE%\Application Data\{942846-0a5405-5463-00c6a175bebc}\hostdl.exe
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp3.tmp
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- C:\program\TempWmicBatchFile.bat
- %ALLUSERSPROFILE%\Application Data\{942846-0a5405-5463-00c6a175bebc}\hostdl.exe
- %TEMP%\tmp1.tmp
- %TEMP%\tmp2.tmp
- %TEMP%\tmp3.tmp
- ClassName: 'EDIT' WindowName: ''
- '%ProgramFiles%\Games\Video.sfx.exe' -p123 -d%ProgramFiles%\games
- 'C:\program\Video.exe'
- '%TEMP%\NetEvtFwdr.exe'
- '%TEMP%\MicrosoftCommon.exe'
- '<SYSTEM32>\cmd.exe' /c ""%ProgramFiles%\Games\news.bat" "
- '<SYSTEM32>\schtasks.exe' /create /tn WinInetDriver /tr %ALLUSERSPROFILE%\Application Data\{942846-0a5405-5463-00c6a175bebc}\hostdl.exe /sc minute /F