Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\Windows Updater.lnk
- '%TEMP%\nsg2.tmp\7z.exe' x "%TEMP%\adobe-updater-pack-utility.7z" -o"%HOMEPATH%\Desktop" "Adguard.url" -aoa -y -pfreewayforme
- '%TEMP%\deleter.exe' /sfx=<Полный путь к вирусу>
- '%TEMP%\nsg2.tmp\7z.exe' x "%TEMP%\adobe-updater-pack-utility.7z" -o"%PROGRAM_FILES%\Adobe" "adobe-updater-startup-utility.exe" -aoa -y -pfreewayforme
- '%TEMP%\nsg2.tmp\7z.exe' x "%TEMP%\adobe-updater-pack-utility.7z" -o"%PROGRAM_FILES%\Adobe" "windows-updater.ico" -aoa -y -pfreewayforme
- %PROGRAM_FILES%\Adobe\windows-updater.ico
- %PROGRAM_FILES%\Adobe\adobe-updater-startup-utility.exe
- %TEMP%\deleter.exe
- %HOMEPATH%\Desktop\Adguard.url
- %TEMP%\nsg2.tmp\execDos.dll
- %TEMP%\adobe-updater-pack-utility.7z
- %TEMP%\nsg2.tmp\KillProc.dll
- %TEMP%\nsg2.tmp\7z.dll
- %TEMP%\nsg2.tmp\7z.exe
- %TEMP%\nsg2.tmp\execDos.dll
- %TEMP%\nsg2.tmp\KillProc.dll
- %TEMP%\nsg2.tmp\7z.exe
- %TEMP%\adobe-updater-pack-utility.7z
- %TEMP%\nsg2.tmp\7z.dll