Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\name.vbs
- %WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe
- %TEMP%\aute935.tmp
- %TEMP%\nonplacental
- %TEMP%\aute994.tmp
- %TEMP%\citlaltpetl
- %LOCALAPPDATA%\directory\name.exe
- %TEMP%\autf40e.tmp
- %TEMP%\autf48c.tmp
- %TEMP%\aute935.tmp
- %TEMP%\aute994.tmp
- %TEMP%\autf40e.tmp
- %TEMP%\autf48c.tmp
- '%LOCALAPPDATA%\directory\name.exe'
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe'