Техническая информация
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\WinInetDriver.url
- %ProgramFiles% (x86)\extract.bat
- %ProgramFiles% (x86)\MSCaic.exe
- C:\Program\raserver.exe
- %ALLUSERSPROFILE%\Application Data\{6a4dba-504830-d04a-3683699e0606}\hostdl.exe
- %ALLUSERSPROFILE%\Application Data\{6a4dba-504830-d04a-3683699e0606}\hostdl.exe
- ClassName: 'EDIT' WindowName: ''
- '%ProgramFiles% (x86)\MSCaic.exe' -pSoeVBTPbRz -d%ProgramFiles% (x86)
- 'C:\Program\raserver.exe'
- '<SYSTEM32>\cmd.exe' /c ""%ProgramFiles% (x86)\extract.bat" "
- '<SYSTEM32>\schtasks.exe' /create /tn WinInetDriver /tr %ALLUSERSPROFILE%\Application Data\{6a4dba-504830-d04a-3683699e0606}\hostdl.exe /sc minute /F