Техническая информация
- <SYSTEM32>\at.exe 20:00 /every:M,T,W,Th,F,Sa,Su """%TEMP%\BdeUnlockWizardb.exe"""
- %TEMP%\nsd3.tmp\nsExec.dll
- %TEMP%\nsd3.tmp\ns4.tmp
- %TEMP%\BackToTheFuture101.exe
- %TEMP%\nso2.tmp
- %TEMP%\BdeUnlockWizardb.exe
- %TEMP%\BackToTheFuture101.exe
- %TEMP%\BdeUnlockWizardb.exe
- %TEMP%\nsd3.tmp\nsExec.dll
- %TEMP%\nsd3.tmp\ns4.tmp