Техническая информация
- %WINDIR%\Tasks\At1.job
- <SYSTEM32>\at.exe /delete /y
- <SYSTEM32>\at.exe 4:59 %WINDIR%\check.bat
- <SYSTEM32>\at.exe 4:60 %WINDIR%\igfxext.exe
- <SYSTEM32>\cmd.exe /c ""%WINDIR%\update.bat" "
- <SYSTEM32>\cmd.exe /c ""%WINDIR%\winupdate.bat" "
- <SYSTEM32>\tskill.exe ravmon
- <SYSTEM32>\attrib.exe +h %WINDIR%\ver.ini
- %WINDIR%\check.bat
- %WINDIR%\ver.ini
- %WINDIR%\systmp.txt
- %WINDIR%\update.bat
- %WINDIR%\winupdate.bat
- %WINDIR%\igfxext.exe
- C:\VMPFull_Tencent.COM
- %WINDIR%\ver.ini
- %TEMP%\~DFBEAB.tmp
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''