Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\virus bind.bat
- <SYSTEM32>\net1.exe user 28587 /add
- <SYSTEM32>\net1.exe user 4910 /add
- <SYSTEM32>\net1.exe user 2958 /add
- <SYSTEM32>\schtasks.exe /delete TMM
- <SYSTEM32>\schtasks.exe /delete UserTask
- <SYSTEM32>\net1.exe user 22216 /add
- <SYSTEM32>\net1.exe user 30717 /add
- <SYSTEM32>\net1.exe user 3084 /add
- <SYSTEM32>\cmd.exe /c """%TEMP%\selfdel0.bat"" "
- <SYSTEM32>\net1.exe user 12640 /add
- <SYSTEM32>\net1.exe user 11269 /add
- <SYSTEM32>\net1.exe user 27893 /add
- <SYSTEM32>\attrib.exe +h +r "<SYSTEM32>"
- <SYSTEM32>\attrib.exe +h +r "%HOMEPATH%\desktop"
- <SYSTEM32>\schtasks.exe /delete Consolidator
- <SYSTEM32>\cmd.exe /c """%TEMP%\2.tmp\batchfile.bat"" "
- <SYSTEM32>\attrib.exe +h +r "%HOMEPATH%\start menu\programs\startup"
- <SYSTEM32>\attrib.exe +h +r "C:"
- <SYSTEM32>\schtasks.exe /delete ResolutionHost
- <SYSTEM32>\schtasks.exe /delete MP Scheduled Scan
- <SYSTEM32>\schtasks.exe /delete SystemSoundsService
- <SYSTEM32>\schtasks.exe /delete AppleSoftwareUpdate
- <SYSTEM32>\schtasks.exe /delete HotStart
- <SYSTEM32>\schtasks.exe /delete SR
- <SYSTEM32>\virus bind.bat
- %HOMEPATH%\Desktop\virus bind.bat
- %TEMP%\selfdel0.bat
- %TEMP%\1.tmp\b2e.exe
- %TEMP%\2.tmp\batchfile.bat
- C:\virus bind.bat
- %TEMP%\1.tmp\b2e.exe
- %TEMP%\2.tmp\batchfile.bat