Техническая информация
- %WINDIR%\sleep.exe 500
- <SYSTEM32>\cmd.exe /c ""%TEMP%\temg_tmp.bat" "
- <SYSTEM32>\cmd.exe /c ""%ALLUSERSPROFILE%\Application Data\wd\u.bat" "
- %TEMP%\nsd3.tmp\AccessControl.dll
- %WINDIR%\tbgw.ico
- %ALLUSERSPROFILE%\Application Data\WD\u.bat
- %TEMP%\temg_tmp.bat
- %ALLUSERSPROFILE%\Desktop\МФ±¦№єОп.url2
- %ALLUSERSPROFILE%\Desktop\Internat Exlporer.url2
- %ALLUSERSPROFILE%\Application Data\WD\kswbc.dll
- %TEMP%\nsd3.tmp\FindProcDLL.dll
- %TEMP%\nsn2.tmp
- %ALLUSERSPROFILE%\Application Data\WD\kwsui.dll
- %ALLUSERSPROFILE%\Application Data\WD\kwssp.dll
- %ALLUSERSPROFILE%\Application Data\WD\kswebshield.dll
- %TEMP%\nsd3.tmp\FindProcDLL.dll
- %TEMP%\nsd3.tmp\AccessControl.dll
- %ALLUSERSPROFILE%\Desktop\МФ±¦№єОп.url2 в %ALLUSERSPROFILE%\Desktop\МФ±¦№єОп.url
- %ALLUSERSPROFILE%\Desktop\Internat Exlporer.url2 в %ALLUSERSPROFILE%\Desktop\Internat Exlporer.url