Техническая информация
- [HKCU\software\microsoft\windows\currentversion\run] 'Tempoo' = 'wscript.exe //B "%TEMP%\Tempoo.vbs"'
- [HKLM\software\microsoft\windows\currentversion\run] 'Tempoo' = 'wscript.exe //B "%TEMP%\Tempoo.vbs"'
- %APPDATA%\microsoft\windows\start menu\programs\startup\tempoo.vbs
- %LOCALAPPDATA%\tempoodefrag18professional64enu.exe
- %TEMP%\oo software\oo setupstub\oostub17430989402404\oostub-2025-03-27_110900.log
- %TEMP%\oo software\oo setupstub\oostub17430989402404\setup.dat
- %LOCALAPPDATA%\tempoo.vbs
- %ALLUSERSPROFILE%\oo software\installations\d88f55ff40b16e7a3ad76e147c06d17a0ab8c905.msi
- %TEMP%\tempoo.vbs
- %TEMP%\oo software\oo setupstub\oostub17430989402404\setup.msi
- %TEMP%\oo software\oo setupstub\oostub17430989402404\setup.dat в %TEMP%\oo software\oo setupstub\oostub17430989402404\setup.msi
- '%LOCALAPPDATA%\tempoodefrag18professional64enu.exe'
- '<SYSTEM32>\wscript.exe' "%LOCALAPPDATA%\Tempoo.vbs"
- '<SYSTEM32>\wscript.exe' //B "%TEMP%\Tempoo.vbs"
- '%WINDIR%\syswow64\msiexec.exe' /i "%ALLUSERSPROFILE%\OO Software\Installations\D88F55FF40B16E7A3AD76E147C06D17A0AB8C905.msi" AFFILIATE_ID=1000 SQUID=1A169C05F988E4A4597872274AB5A6DA MSIFILENAME=D88F55FF40B16E7A3AD76E147C06D...