Техническая информация
- '<SYSTEM32>\attrib.exe' +r +s +h %WINDIR%\Installer\Herb
- '<SYSTEM32>\attrib.exe' +r +s +h %WINDIR%\Installer\Herb\*.*
- '<SYSTEM32>\wscript.exe' "%WINDIR%\Installer\Herb\45.vbs"
- '<SYSTEM32>\attrib.exe' +h %TEMP%\ztmp
- '<SYSTEM32>\replace.exe' <SYSTEM32>\services.exe <SYSTEM32>\userinit.exe
- %WINDIR%\Installer\Herb\d.bat
- %WINDIR%\Installer\Herb\45.vbs
- %WINDIR%\Installer\Herb\vf.bat
- %TEMP%\ztmp\tmp26691.bat
- %TEMP%\ztmp\tmp27211.exe
- %WINDIR%\Installer\Herb\vf.bat
- %WINDIR%\Installer\Herb\d.bat
- %WINDIR%\Installer\Herb\45.vbs
- %TEMP%\ztmp\tmp27211.exe
- ClassName: 'Shell_TrayWnd' WindowName: ''