Техническая информация
- <SYSTEM32>\wscript.exe "%PROGRAM_FILES%\out of the address\An enterprise\bb\8fb32ee31ccdae8907713c9922c0f344.vbs"
- <SYSTEM32>\wscript.exe "%PROGRAM_FILES%\out of the address\An enterprise\bb\036a9c5c8c3c476cd499c12be352ba5c.vbs"
- <SYSTEM32>\cmd.exe /c ""%PROGRAM_FILES%\out of the address\An enterprise\036a9c5c8c3c476cd499c12be352ba5c.bat" "
- %HOMEPATH%\Recent\036a9c5c8c3c476cd499c12be352ba5c.lnk
- %PROGRAM_FILES%\out of the address\An enterprise\bb\8fb32ee31ccdae8907713c9922c0f344.vbs
- %HOMEPATH%\Recent\8fb32ee31ccdae8907713c9922c0f344.lnk
- %HOMEPATH%\Recent\bb.lnk
- %PROGRAM_FILES%\out of the address\An enterprise\bb\036a9c5c8c3c476cd499c12be352ba5c.vbs
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- %PROGRAM_FILES%\out of the address\An enterprise\036a9c5c8c3c476cd499c12be352ba5c.bat
- %PROGRAM_FILES%\out of the address\An enterprise\bb\pipi.ska
- %HOMEPATH%\Recent\bb.lnk
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- '19#.#41.191.138':1999
- 'localhost':1037
- ClassName: 'Shell_TrayWnd' WindowName: ''