Техническая информация
- %TEMP%\is-j8jki.tmp\is-d4adn.tmp
- %TEMP%\is-ocnm1.tmp\_isetup\_setup64.tmp
- %TEMP%\is-ocnm1.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-ocnm1.tmp\_isdecmp.dll
- %TEMP%\is-ocnm1.tmp\_iscrypt.dll
- %LOCALAPPDATA%\ado video tools 2019.03\is-8lqm9.tmp
- %LOCALAPPDATA%\ado video tools 2019.03\is-6c70p.tmp
- %LOCALAPPDATA%\ado video tools 2019.03\is-ipv3i.tmp
- %LOCALAPPDATA%\ado video tools 2019.03\unins000.dat
- %LOCALAPPDATA%\ado video tools 2019.03\adovideotools1117.exe
- %LOCALAPPDATA%\ado video tools 2019.03\is-8lqm9.tmp в %LOCALAPPDATA%\ado video tools 2019.03\unins000.exe
- %LOCALAPPDATA%\ado video tools 2019.03\is-6c70p.tmp в %LOCALAPPDATA%\ado video tools 2019.03\sqlite3.dll
- %LOCALAPPDATA%\ado video tools 2019.03\is-ipv3i.tmp в %LOCALAPPDATA%\ado video tools 2019.03\adovideotools1117.exe
- 'st###7345724.ru':80
- http://st###7345724.ru/new/net_api
- DNS ASK st###7345724.ru
- ClassName: 'D%x_adovt_11173ca7e9d' WindowName: ''
- '%TEMP%\is-j8jki.tmp\is-d4adn.tmp' /SL4 $5024A "<Полный путь к файлу>" 5086541 52224
- '%LOCALAPPDATA%\ado video tools 2019.03\adovideotools1117.exe' 40e351f040625c6d41c6d2a62c869355
- '%WINDIR%\syswow64\schtasks.exe' /Delete /F /TN "ado_video_tools_11173"