Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\smartclock.lnk
- <SYSTEM32>\tasks\smart clock
- %TEMP%\nsh9924.tmp\uac.dll
- %ProgramFiles(x86)%\foler\olader\acppage.dll
- %ProgramFiles(x86)%\foler\olader\adprovider.dll
- %ProgramFiles(x86)%\foler\olader\acledit.dll
- %TEMP%\arose\fine.exe
- %TEMP%\arose\vin.exe
- %TEMP%\ixp000.tmp\cio.xls
- %TEMP%\ixp000.tmp\chiude.xls
- %TEMP%\ixp000.tmp\notti.xls
- %TEMP%\ixp000.tmp\ricomincia.xls
- %APPDATA%\smart clock\smartclock.exe
- %TEMP%\ixp000.tmp\torno.exe.com
- %TEMP%\ixp000.tmp\p
- %TEMP%\nsh9924.tmp\uac.dll
- %TEMP%\ixp000.tmp\p
- %TEMP%\ixp000.tmp\notti.xls
- %TEMP%\ixp000.tmp\ricomincia.xls
- %TEMP%\ixp000.tmp\chiude.xls
- %TEMP%\ixp000.tmp\cio.xls
- %TEMP%\ixp000.tmp\torno.exe.com
- DNS ASK NJ#############JRPvlKPyOPF.NJIEjqRTbnIYnAiJRPvlKPyOPF
- '%TEMP%\arose\fine.exe'
- '%TEMP%\arose\vin.exe'
- '%TEMP%\ixp000.tmp\torno.exe.com' p
- '%APPDATA%\smart clock\smartclock.exe'
- '%WINDIR%\syswow64\dllhost.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c cmd < Ricomincia.xls' (со скрытым окном)
- '%WINDIR%\syswow64\dllhost.exe'
- '%WINDIR%\syswow64\cmd.exe' /c cmd < Ricomincia.xls
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\findstr.exe' /V /R "^jZvjHjHxviPgppBDTSaswkcVepFqvVJTGccDaWvLwkekqowEJeUGTSUqEBpnHGXBbWINNYkWcGfPopUUiqsxqrqOAcYRNYtcgBOtmgRKQYljCyScGgdGfCAzVUhaZxobCUBGxPcToGEwTOkc$" Cio.xls
- '%WINDIR%\syswow64\ping.exe' wzmuna -n 30