Техническая информация
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2.tmp" "%TEMP%\CSC1.tmp"
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\csc.exe /noconfig @"%TEMP%\4fnvw9xq.cmdline"
- <Текущая директория>\iherror.log
- %TEMP%\4fnvw9xq.dll
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\CONFIG\security.config.cch.new
- <LS_APPDATA>\ApplicationHistory\<Имя вируса>.exe.bf81a5f0.ini
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\CONFIG\enterprisesec.config.cch.new
- %TEMP%\4fnvw9xq.cmdline
- %TEMP%\4fnvw9xq.0.cs
- %TEMP%\4fnvw9xq.out
- %TEMP%\RES2.tmp
- %TEMP%\CSC1.tmp
- %TEMP%\4fnvw9xq.dll
- %TEMP%\4fnvw9xq.out
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\CONFIG\enterprisesec.config.cch.2444.102875
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\CONFIG\security.config.cch.2444.102859
- %TEMP%\CSC1.tmp
- %TEMP%\RES2.tmp
- %TEMP%\4fnvw9xq.0.cs
- %TEMP%\4fnvw9xq.cmdline
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\CONFIG\enterprisesec.config.cch в %WINDIR%\Microsoft.NET\Framework\v1.1.4322\CONFIG\enterprisesec.config.cch.2444.102875
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\CONFIG\security.config.cch в %WINDIR%\Microsoft.NET\Framework\v1.1.4322\CONFIG\security.config.cch.2444.102859