Техническая информация
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\`.bat" -in"
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\1.bat" "
- %WINDIR%\Temp\tmp\df.008.tmp
- %WINDIR%\Temp\tmp\df.009.tmp
- %WINDIR%\Temp\tmp\df.006.tmp
- %WINDIR%\Temp\tmp\df.007.tmp
- %WINDIR%\Temp\tmp\df.010.tmp
- %WINDIR%\Temp\df.dat
- %WINDIR%\Temp\dfcent
- %WINDIR%\Temp\tmp\df.011.tmp
- %WINDIR%\2.ini
- C:\ccc\conime.exe
- %WINDIR%\Temp\tmp\df.000.tmp
- %WINDIR%\1.bat
- %WINDIR%\`.bat
- %WINDIR%\Temp\tmp\df.001.tmp
- %WINDIR%\Temp\tmp\df.004.tmp
- %WINDIR%\Temp\tmp\df.005.tmp
- %WINDIR%\Temp\tmp\df.002.tmp
- %WINDIR%\Temp\tmp\df.003.tmp
- %WINDIR%\Temp\df.dat
- C:\ccc\conime.exe в %WINDIR%\Temp\Perflib_Perfdata_desc.dat
- %WINDIR%\Temp\df.dat
- C:\ccc\conime.exe
- %WINDIR%\Temp\Perflib_Perfdata_desc.dat
- 'qs####u2.3322.org':801
- 'any':801
- 'localhost':1231
- DNS ASK QS####U2.3322.ORG
- ClassName: 'Shell_TrayWnd' WindowName: ''