Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\Windows Sidebar.lnk
- '<SYSTEM32>\wscript.exe' "C:\ProgramData\Windows\System32\start.vbs"
- '<SYSTEM32>\wscript.exe' "C:\ProgramData\check.vbs"
- '<SYSTEM32>\cmd.exe' /c ""C:\ProgramData\Windows\System32\ds.bat" "
- '<SYSTEM32>\powercfg.exe' -change -standby-timeout-ac 0
- '<SYSTEM32>\cmd.exe' /c ""C:\ProgramData\dshfrx86.bat" "
- 'C:\ProgramData\x86.exe' -pgk6jundmwt2g
- C:\ProgramData\Windows\System32\start.vbs
- C:\ProgramData\Windows\System32\SearchIndex.exe
- C:\ProgramData\Windows\System32\ws.ico
- C:\ProgramData\Windows\System32\ds.bat
- C:\ProgramData\Windows\System32\cpuminer-conf.json
- C:\ProgramData\Windows\System32\msvcr120.dll
- C:\ProgramData\dshfrx64.bat
- C:\ProgramData\dshfrx86.bat
- C:\ProgramData\check.vbs
- C:\ProgramData\x64.exe
- C:\ProgramData\x86.exe
- C:\ProgramData\Windows\System32\ws.ico
- C:\ProgramData\Windows\System32\cpuminer-conf.json
- C:\ProgramData\Windows\System32\ds.bat
- C:\ProgramData\Windows\System32\msvcr120.dll
- C:\ProgramData\Windows\System32\SearchIndex.exe
- C:\ProgramData\Windows\System32\start.vbs
- C:\ProgramData\check.vbs
- C:\ProgramData\dshfrx64.bat
- C:\ProgramData\x86.exe
- C:\ProgramData\x64.exe
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''