Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\virtuoso.url
- %TEMP%\components
- %LOCALAPPDATA%\immersive creations co\d
- %TEMP%\316094\u
- %TEMP%\316094\intranet.pif
- %TEMP%\cricket.bat
- %TEMP%\faculty
- %TEMP%\ima
- %TEMP%\responsible
- %LOCALAPPDATA%\immersive creations co\virtuoso.scr
- %TEMP%\indiana
- %TEMP%\cricket
- %TEMP%\scientists
- %TEMP%\prep
- %TEMP%\medium
- %TEMP%\stranger
- %TEMP%\my
- %TEMP%\metres
- %TEMP%\recreation
- %LOCALAPPDATA%\immersive creations co\virtuoso.js
- %TEMP%\316094\u
- DNS ASK qv########swxcUi.qvlUfqsrAwswxcUi
- '%TEMP%\316094\intranet.pif' u
- '%WINDIR%\syswow64\cmd.exe' /c copy Cricket Cricket.bat & Cricket.bat (со скрытым окном)
- '%WINDIR%\syswow64\tasklist.exe'
- '%WINDIR%\syswow64\findstr.exe' /I "wrsa opssvc"
- '%WINDIR%\syswow64\findstr.exe' -I "avastui avgui bdservicehost nswscsvc sophoshealth"
- '%WINDIR%\syswow64\cmd.exe' /c md 316094
- '%WINDIR%\syswow64\findstr.exe' /V "SequenceOctoberContributionRef" Recreation
- '%WINDIR%\syswow64\cmd.exe' /c copy /b ..\Metres + ..\Scientists + ..\Prep + ..\Responsible + ..\Stranger + ..\Components + ..\Medium + ..\Ima + ..\My + ..\Indiana u
- '%WINDIR%\syswow64\choice.exe' /d y /t 5
- '%WINDIR%\syswow64\cmd.exe' /k echo [InternetShortcut] > "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\Virtuoso.url" & echo URL="%LOCALAPPDATA%\Immersive Creations Co\Virtuoso.js" >> "%APPDATA%\Microsoft\Window...