Техническая информация
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\WinInetDriver.url
- %TEMP%\nsz2.tmp
- %APPDATA%\1337\PTS.exe
- %APPDATA%\1337\jRlt.exe
- %TEMP%\nso5.tmp
- %TEMP%\nsz6.tmp\System.dll
- %APPDATA%\1337\netiougc.exe
- %APPDATA%\1337\ptc.exe
- %ALLUSERSPROFILE%\Application Data\{e75736-19277a-8738-bf1c0bd1867f}\hostdl.exe
- %ALLUSERSPROFILE%\Application Data\{e75736-19277a-8738-bf1c0bd1867f}\hostdl.exe
- %TEMP%\nsu3.tmp\System.dll
- %TEMP%\nsz6.tmp\System.dll
- '%APPDATA%\1337\jRlt.exe'
- '%APPDATA%\1337\netiougc.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn WinInetDriver /tr %ALLUSERSPROFILE%\Application Data\{e75736-19277a-8738-bf1c0bd1867f}\hostdl.exe /sc minute /F