Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\smartclock.lnk
- <SYSTEM32>\tasks\smart clock
- %TEMP%\nsx6816.tmp\uac.dll
- %ProgramFiles(x86)%\foler\olader\acppage.dll
- %ProgramFiles(x86)%\foler\olader\adprovider.dll
- %ProgramFiles(x86)%\foler\olader\acledit.dll
- %TEMP%\new feature\vpn.exe
- %TEMP%\new feature\4.exe
- %TEMP%\7zipsfx.000\dal.aiff
- %TEMP%\7zipsfx.000\diritto.aiff
- %TEMP%\7zipsfx.000\dov.aiff
- %TEMP%\7zipsfx.000\gote.aiff
- %APPDATA%\smart clock\smartclock.exe
- %TEMP%\7zipsfx.000\gabbie.exe.com
- %TEMP%\7zipsfx.000\c
- %TEMP%\nsx6816.tmp\uac.dll
- '%TEMP%\new feature\vpn.exe'
- '%TEMP%\new feature\4.exe'
- '%TEMP%\7zipsfx.000\gabbie.exe.com' c
- '%APPDATA%\smart clock\smartclock.exe'
- '%WINDIR%\syswow64\cmd.exe' /c cmd < Gote.aiff' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c cmd < Gote.aiff
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\findstr.exe' /V /R "^LjaIWKsNCnNrcrIGrRSgkvhmTVtiUhayrefgTaEfPZCszvASPFwjlwZgZTOwGpSgyIZzOzMKjDnkUVybxkagkuUerqfqE$" Diritto.aiff
- '%WINDIR%\syswow64\ping.exe' 127.0.0.1 -n 30