Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\st.lnk
- 'C:\Users\%USERNAME%\AppData\Local\st.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\ztmp\t6007.bat" "C:\Users\%USERNAME%\AppData\Local\st.exe" "
- C:\Users\%USERNAME%\AppData\Local\libwinpthread-1.dll
- C:\Users\%USERNAME%\AppData\Local\libstdc++-6.dll
- C:\Users\%USERNAME%\AppData\Local\ssleay32.dll
- %TEMP%\ztmp\t6056.exe
- %TEMP%\ztmp\t6007.bat
- C:\Users\%USERNAME%\AppData\Local\libgcc_s_seh-1.dll
- C:\Users\%USERNAME%\AppData\Local\svchost.exe
- C:\Users\%USERNAME%\AppData\Local\st.exe
- C:\Users\%USERNAME%\AppData\Local\zlib1.dll
- C:\Users\%USERNAME%\AppData\Local\libeay32.dll
- C:\Users\%USERNAME%\AppData\Local\libcurl.dll
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''