Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\bite56e.tmp
- ultrage.exe
- xpfix.exe
- %TEMP%\rarsfx0\hengine.exe
- %TEMP%\ultrage.exe
- %TEMP%\c0627ad.tmp
- %TEMP%\c001c94.tmp
- %APPDATA%\zstsvc_5\xpfix.exe
- %ALLUSERSPROFILE%\zstsvc_5\pleabclirtkrour.inpk
- %ALLUSERSPROFILE%\zstsvc_5\vcruntime140.dll
- %ALLUSERSPROFILE%\zstsvc_5\shourlaeng.iwp
- %ALLUSERSPROFILE%\zstsvc_5\qt5xml.dll
- %ALLUSERSPROFILE%\zstsvc_5\qt5widgets.dll
- %ALLUSERSPROFILE%\zstsvc_5\qt5network.dll
- %ALLUSERSPROFILE%\zstsvc_5\qt5gui.dll
- %ALLUSERSPROFILE%\zstsvc_5\qt5core.dll
- %ALLUSERSPROFILE%\zstsvc_5\msvcp140.dll
- %ALLUSERSPROFILE%\zstsvc_5\hengine.exe
- %TEMP%\rarsfx0\vcruntime140.dll
- %TEMP%\rarsfx0\shourlaeng.iwp
- %TEMP%\rarsfx0\qt5xml.dll
- %TEMP%\rarsfx0\qt5widgets.dll
- %TEMP%\rarsfx0\qt5network.dll
- %TEMP%\rarsfx0\qt5gui.dll
- %TEMP%\rarsfx0\qt5core.dll
- %TEMP%\rarsfx0\pleabclirtkrour.inpk
- %TEMP%\rarsfx0\msvcp140.dll
- %TEMP%\c113aef.tmp
- %TEMP%\c6ee031.tmp
- %APPDATA%\microsoft\windows\start menu\programs\startup\bite56e.tmp
- %TEMP%\c001c94.tmp
- %TEMP%\c001c94.tmp
- ClassName: 'Edit' WindowName: ''
- '%TEMP%\rarsfx0\hengine.exe'
- '%ALLUSERSPROFILE%\zstsvc_5\hengine.exe'
- '%TEMP%\ultrage.exe'
- '%APPDATA%\zstsvc_5\xpfix.exe' "%APPDATA%\Zstsvc_5\XPFix.exe" /u