Техническая информация
- %WINDIR%\Tasks\At1.job
- '%TEMP%\PortraitProfessional.exe'
- '%TEMP%\nsz3.tmp\ns4.tmp' <SYSTEM32>\cmd.exe /C at 16:00 /every:M,T,W,Th,F,Sa,Su ""%TEMP%\Authnb.exe""
- '<SYSTEM32>\at.exe' 16:00 /every:M,T,W,Th,F,Sa,Su ""%TEMP%\Authnb.exe""
- %TEMP%\nsz3.tmp\nsExec.dll
- %TEMP%\nsz3.tmp\ns4.tmp
- %TEMP%\PortraitProfessional.exe
- %TEMP%\nsx2.tmp
- %TEMP%\Authnb.exe
- %TEMP%\PortraitProfessional.exe
- %TEMP%\Authnb.exe
- %TEMP%\nsz3.tmp\nsExec.dll
- %TEMP%\nsz3.tmp\ns4.tmp