Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\smartclock.lnk
- <SYSTEM32>\tasks\smart clock
- %TEMP%\nss2933.tmp\uac.dll
- %ProgramFiles(x86)%\foler\olader\acppage.dll
- %ProgramFiles(x86)%\foler\olader\adprovider.dll
- %ProgramFiles(x86)%\foler\olader\acledit.dll
- %TEMP%\new feature\vpn.exe
- %TEMP%\new feature\4.exe
- %TEMP%\7zipsfx.000\quando.mui
- %TEMP%\7zipsfx.000\questa.mui
- %TEMP%\7zipsfx.000\ricordarmi.mui
- %TEMP%\7zipsfx.000\tocchi.mui
- %APPDATA%\smart clock\smartclock.exe
- %TEMP%\7zipsfx.000\ritornata.exe.com
- %TEMP%\7zipsfx.000\h
- %TEMP%\nss2933.tmp\uac.dll
- %TEMP%\7zipsfx.000\h
- %TEMP%\7zipsfx.000\quando.mui
- '%TEMP%\new feature\vpn.exe'
- '%TEMP%\new feature\4.exe'
- '%TEMP%\7zipsfx.000\ritornata.exe.com' h
- '%APPDATA%\smart clock\smartclock.exe'
- '%WINDIR%\syswow64\dllhost.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c cmd < Questa.mui' (со скрытым окном)
- '%WINDIR%\syswow64\dllhost.exe'
- '%WINDIR%\syswow64\cmd.exe' /c cmd < Questa.mui
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\findstr.exe' /V /R "^bkKukanvvIaviummCuKudmQWXJRADyBlRAsoRwEThgwuiCesPIojDwzYxNpBAXTdiiEGPdHACRTwbKPxGALUXfHPizOtSezfcKZZYcCnqHJMosAJYPUqkYzRAOnvCDI$" Tocchi.mui
- '%WINDIR%\syswow64\ping.exe' 127.0.0.1 -n 30