Техническая информация
- %WINDIR%\Tasks\At1.job
- %TEMP%\xpkimg.exe
- %TEMP%\nsz3.tmp\ns4.tmp <SYSTEM32>\cmd.exe /C at 21:00 /every:M,T,W,Th,F,Sa,Su ""%TEMP%\wareg51.exe""
- <SYSTEM32>\at.exe 21:00 /every:M,T,W,Th,F,Sa,Su ""%TEMP%\wareg51.exe""
- %TEMP%\nsz3.tmp\nsExec.dll
- %TEMP%\nsz3.tmp\ns4.tmp
- %TEMP%\xpkimg.exe
- %TEMP%\nsi2.tmp
- %TEMP%\wareg51.exe
- %TEMP%\xpkimg.exe
- %TEMP%\wareg51.exe
- %TEMP%\nsz3.tmp\nsExec.dll
- %TEMP%\nsz3.tmp\ns4.tmp