Техническая информация
- <SYSTEM32>\at.exe 14:00 /every:M,T,W,Th,F,Sa,Su """%TEMP%\conhostb.exe"""
- %TEMP%\nse3.tmp\nsExec.dll
- %TEMP%\nse3.tmp\ns4.tmp
- %TEMP%\setup.exe
- %TEMP%\nsd2.tmp
- %TEMP%\conhostb.exe
- %TEMP%\setup.exe
- %TEMP%\conhostb.exe
- %TEMP%\nse3.tmp\nsExec.dll
- %TEMP%\nse3.tmp\ns4.tmp