Техническая информация
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\Diacostics.lnk
- C:\Default\ComSystem.exe
- C:\Default\Surrogate.exe
- %TEMP%\~SB9.tmp
- %TEMP%\~SBA.tmp
- %TEMP%\Surrogate.0001
- %TEMP%\Surrogate.0002
- C:\Default\Surrogate.vbe
- %TEMP%\ComSystem.0001
- %TEMP%\LSB3.tmp
- %TEMP%\~SB4.tmp
- %TEMP%\LSB1.tmp
- %TEMP%\LSB2.tmp
- %TEMP%\~SB7.tmp
- %TEMP%\~SB8.tmp
- %TEMP%\~SB5.tmp
- %TEMP%\~SB6.tmp
- %TEMP%\b8ab16a0-8791-11e4-4823-00025be10029\x64.exe
- %TEMP%\~SB4.tmp
- %TEMP%\~SB8.tmp
- %TEMP%\LSB3.tmp
- %TEMP%\LSB2.tmp
- %TEMP%\~SB9.tmp
- %TEMP%\LSB1.tmp
- %TEMP%\~SBA.tmp
- %TEMP%\~SB6.tmp
- %TEMP%\~SB5.tmp
- %TEMP%\~SB7.tmp в %TEMP%\b8ab16a0-8791-11e4-4823-00025be10029\x64.exe
- ClassName: 'Shell_TrayWnd' WindowName: ''