Техническая информация
- %WINDIR%\Tasks\At2.job
- %WINDIR%\Tasks\At1.job
- '<SYSTEM32>\at.exe' 19:27 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\eu2i.exe""
- '<SYSTEM32>\cmd.exe' /C at 19:27 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\eu2i.exe""
- '%TEMP%\nsb6.tmp\ns8.tmp' <SYSTEM32>\cmd.exe /C at 19:32 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\r2p3.exe""
- '<SYSTEM32>\at.exe' 19:32 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\r2p3.exe""
- '<SYSTEM32>\cmd.exe' /C at 19:32 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\r2p3.exe""
- '%TEMP%\7za.exe' x "%TEMP%\a1.7z" -aoa -o%HOMEPATH%\Local Settings\Temp -p~@S23js@@vBz99432@t9 "" ""
- '%APPDATA%\General-CleanTool.exe'
- '%TEMP%\RarSFX0\CleanTool.exe'
- '%TEMP%\nsb6.tmp\ns7.tmp' <SYSTEM32>\cmd.exe /C at 19:27 /every:M,T,W,Th,F,Sa,Su ""%WINDIR%\eu2i.exe""
- '%TEMP%\qzgsn.exe'
- %TEMP%\nsg5.tmp
- %WINDIR%\eu2i.exe
- %TEMP%\AheadCleanToolTempFile.tmp
- %TEMP%\RarSFX0\NeroCheck.exe
- %TEMP%\qzgsn.exe
- %WINDIR%\icp3.exe
- %TEMP%\nsb6.tmp\ns7.tmp
- %TEMP%\nsb6.tmp\ns8.tmp
- %TEMP%\nsb6.tmp\nsExec.dll
- %WINDIR%\bclm.exe
- %WINDIR%\r2p3.exe
- %APPDATA%\General-CleanTool.exe
- %TEMP%\nsg3.tmp\ExecDos.dll
- %TEMP%\a1.7z
- %TEMP%\nso2.tmp
- %TEMP%\7za.exe
- %TEMP%\RarSFX0\CleanTool.cfg
- %TEMP%\RarSFX0\CleanTool.exe
- %TEMP%\RarSFX0\CTREBOOT.exe
- %TEMP%\RarSFX0\CleanNV.exe
- %TEMP%\RarSFX0\CleanToolN7.cfg
- %TEMP%\RarSFX0\CleanToolN8.cfg
- %WINDIR%\bclm.exe
- %WINDIR%\r2p3.exe
- %WINDIR%\eu2i.exe
- %WINDIR%\icp3.exe
- %TEMP%\nsb6.tmp\ns7.tmp
- %TEMP%\nsg3.tmp\ExecDos.dll
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''