Техническая информация
- '<SYSTEM32>\WScript.exe' "%PROGRAM_FILES%\Insata\Ikars\sanodo.vbs"
- %PROGRAM_FILES%\Insata\Ikars\Uninstall.ini
- %PROGRAM_FILES%\Insata\Ikars\Uninstall.exe
- <LS_APPDATA>\Microsoft\Windows\Temporary Internet Files\Content.IE5\YIF7DGLM\515[1]
- \Device\Mup\BVNSEUHJ*\MAILSLOT\NET\NETLOGON
- %PROGRAM_FILES%\Insata\Ikars\1.txt
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- %PROGRAM_FILES%\Insata\Ikars\albur.bat
- %PROGRAM_FILES%\Insata\Ikars\sanodo.vbs
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- '19#.#75.125.195':80
- http://19#.#75.125.195/zayats/podoxdfdf/515