Техническая информация
- <SYSTEM32>\at.exe 19:37 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\icp3.exe""
- <SYSTEM32>\at.exe 19:42 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\bclm.exe""
- <SYSTEM32>\at.exe 19:27 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\eu2i.exe""
- <SYSTEM32>\at.exe 19:32 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\r2p3.exe""
- %TEMP%\nsf3.tmp\ns7.tmp
- %TEMP%\nsf3.tmp\ns6.tmp
- %TEMP%\nsf3.tmp\ns5.tmp
- C:\ndf
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\counter[1].php
- %TEMP%\nsf3.tmp\inetc.dll
- %TEMP%\nsf3.tmp\ns4.tmp
- %WINDIR%\icp3.exe
- %WINDIR%\eu2i.exe
- %TEMP%\nsu2.tmp
- %TEMP%\nsf3.tmp\nsExec.dll
- %WINDIR%\r2p3.exe
- %WINDIR%\bclm.exe
- %WINDIR%\r2p3.exe
- C:\ndf
- %WINDIR%\bclm.exe
- %WINDIR%\eu2i.exe
- %WINDIR%\icp3.exe
- %TEMP%\nsf3.tmp\ns7.tmp
- %TEMP%\nsf3.tmp\inetc.dll
- %TEMP%\nsf3.tmp\nsExec.dll
- %TEMP%\nsf3.tmp\ns4.tmp
- %TEMP%\nsf3.tmp\ns5.tmp
- %TEMP%\nsf3.tmp\ns6.tmp
- '12#.#17.235.76':80
- 12#.#17.235.76/videos/counter.php
- ClassName: 'Shell_TrayWnd' WindowName: ''