Техническая информация
- %HOMEPATH%\desktop\1189.jpeg
- %HOMEPATH%\desktop\thlps_keeper_mayer_1965.docx
- %HOMEPATH%\desktop\testcertificate.cer
- %HOMEPATH%\desktop\region-north-karelia.jpg
- %HOMEPATH%\desktop\region-north-karelia.jpeg
- %HOMEPATH%\desktop\pushkin.jpg
- %HOMEPATH%\desktop\nwfieldnotes1966.docx
- %HOMEPATH%\desktop\lisp_success.doc
- %HOMEPATH%\desktop\issi2013_template_for_posters.docx
- %HOMEPATH%\desktop\holycrosschurchinstructions.docx
- %HOMEPATH%\desktop\garden.htm
- %HOMEPATH%\desktop\file_p_00000000_1371597592.docx
- %HOMEPATH%\desktop\dial.bmp
- %HOMEPATH%\desktop\tree_view.htm
- %HOMEPATH%\desktop\delete.avi
- %HOMEPATH%\desktop\dashborder_120.bmp
- %HOMEPATH%\desktop\cveuropeo.doc
- %HOMEPATH%\desktop\contosoroot_1.cer
- %HOMEPATH%\desktop\archer.avi
- %HOMEPATH%\desktop\api-hashmap.html
- %HOMEPATH%\desktop\alert.html
- %HOMEPATH%\desktop\adadsi.html
- %HOMEPATH%\desktop\about.html
- %HOMEPATH%\desktop\64bit_notes.htm
- %HOMEPATH%\desktop\4f0bf7ff71f28.jpeg
- %HOMEPATH%\desktop\3.jpg
- %HOMEPATH%\desktop\168.jpg
- %HOMEPATH%\desktop\dashborder_144.bmp
- %HOMEPATH%\desktop\weeklysheet1215.doc
- %HOMEPATH%\dosomething.ps1
- %HOMEPATH%\desktop\utorrent.exe.montelli
- %HOMEPATH%\favorites\msn websites\msn money.url.montelli
- %HOMEPATH%\favorites\msn websites\msn entertainment.url.montelli
- %HOMEPATH%\favorites\msn websites\msn autos.url.montelli
- %HOMEPATH%\favorites\microsoft websites\microsoft store.url.montelli
- %HOMEPATH%\desktop\telegram.lnk.montelli
- %HOMEPATH%\desktop\winmine.exe.montelli
- %HOMEPATH%\favorites\msn websites\msn sports.url.montelli
- %HOMEPATH%\favorites\microsoft websites\microsoft at home.url.montelli
- %TEMP%\s1ubtyy6.dll
- %HOMEPATH%\searches\indexed locations.search-ms.montelli
- %TEMP%\res3034.tmp
- %HOMEPATH%\links\recentplaces.lnk.montelli
- %HOMEPATH%\favorites\microsoft websites\ie site on microsoft.com.url.montelli
- %HOMEPATH%\favorites\microsoft websites\microsoft at work.url.montelli
- %HOMEPATH%\music\desktop.ini.montelli
- %HOMEPATH%\favorites\msn websites\msn.url.montelli
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\delegate_execute.exe.montelli
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\default_apps\youtube.crx.montelli
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\default_apps\search.crx.montelli
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\default_apps\gmail.crx.montelli
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\default_apps\external_extensions.json.montelli
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\default_apps\drive.crx.montelli
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\default_apps\docs.crx.montelli
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\d3dcompiler_47.dll.montelli
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\chrome_watcher.dll.montelli
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\chrome_elf.dll.montelli
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\chrome_child.dll.montelli
- %HOMEPATH%\favorites\windows live\windows live spaces.url.montelli
- %HOMEPATH%\favorites\windows live\windows live mail.url.montelli
- %HOMEPATH%\favorites\windows live\windows live gallery.url.montelli
- %HOMEPATH%\favorites\windows live\get windows live.url.montelli
- %TEMP%\csc3024.tmp
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\chrome_200_percent.pak.montelli
- %HOMEPATH%\favorites\microsoft websites\ie add-on site.url.montelli
- %TEMP%\s1ubtyy6.out
- %TEMP%\s1ubtyy6.cmdline
- %HOMEPATH%\desktop\64bit_notes.htm.montelli
- %HOMEPATH%\downloads\desktop.ini.montelli
- %HOMEPATH%\documents\desktop.ini.montelli
- %HOMEPATH%\desktop\api-hashmap.html.montelli
- %HOMEPATH%\desktop\alert.html.montelli
- %HOMEPATH%\desktop\adadsi.html.montelli
- %HOMEPATH%\desktop\about.html.montelli
- %HOMEPATH%\desktop\4f0bf7ff71f28.jpeg.montelli
- %HOMEPATH%\links\desktop.ini.montelli
- %HOMEPATH%\desktop\3.jpg.montelli
- %HOMEPATH%\desktop\168.jpg.montelli
- %HOMEPATH%\desktop\1189.jpeg.montelli
- %HOMEPATH%\contacts\user.contact.montelli
- %HOMEPATH%\contacts\desktop.ini.montelli
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\42.0.2311.135.manifest.montelli
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\extensions\external_extensions.json.montelli
- %HOMEPATH%\favorites\msn websites\msnbc news.url.montelli
- %HOMEPATH%\favorites\links\desktop.ini.montelli
- %HOMEPATH%\saved games\desktop.ini.montelli
- %HOMEPATH%\favorites\desktop.ini.montelli
- %TEMP%\s1ubtyy6.0.cs
- %HOMEPATH%\favorites\links for united states\usa.gov.url.montelli
- %HOMEPATH%\favorites\links for united states\gobiernousa.gov.url.montelli
- %HOMEPATH%\searches\everywhere.search-ms.montelli
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\chrome_100_percent.pak.montelli
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\chrome.dll.montelli
- %HOMEPATH%\desktop\google chrome.lnk.montelli
- %HOMEPATH%\favorites\links for united states\desktop.ini.montelli
- %HOMEPATH%\links\downloads.lnk.montelli
- %HOMEPATH%\desktop\desktop.ini.montelli
- %HOMEPATH%\searches\desktop.ini.montelli
- %HOMEPATH%\favorites\links\web slice gallery.url.montelli
- %HOMEPATH%\links\desktop.lnk.montelli
- %HOMEPATH%\videos\desktop.ini.montelli
- %HOMEPATH%\pictures\desktop.ini.montelli
- %LOCALAPPDATA%\google\chrome\application\42.0.2311.135\ffmpegsumo.dll.montelli
- %TEMP%\res3034.tmp
- %TEMP%\csc3024.tmp
- %TEMP%\s1ubtyy6.out
- %TEMP%\s1ubtyy6.cmdline
- %TEMP%\s1ubtyy6.0.cs
- %TEMP%\s1ubtyy6.dll
- %TEMP%\s1ubtyy6.pdb
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -ExecutionPolicy Bypass -File "%HOMEPATH%\dosomething.ps1"
- '<SYSTEM32>\cmd.exe' /c powershell -WindowStyle Hidden -ExecutionPolicy Bypass -File "%HOMEPATH%\dosomething.ps1"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\s1ubtyy6.cmdline" (со скрытым окном)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES3034.tmp" "%TEMP%\CSC3024.tmp" (со скрытым окном)