Technical Information
- <SYSTEM32>\tasks\7856757
- %TEMP%\is-u5f06.tmp\<File name>.tmp
- %TEMP%\is-3afc4.tmp\_isetup\_setup64.tmp
- %ALLUSERSPROFILE%\dir\is-0m0p8.tmp
- %TEMP%\is-3afc4.tmp\is-hb3m7.tmp
- %TEMP%\is-3afc4.tmp\is-l0lfa.tmp
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\v_k-d_j\vnktoаktе_dj.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\v_k-d_j\uninstall vnktoаktе_dj.lnk
- %HOMEPATH%\desktop\vnktoаktе_dj.lnk
- %APPDATA%\microsoft\internet explorer\quick launch\vnktoаktе_dj.lnk
- %ALLUSERSPROFILE%\dir\unins000.dat
- from %ALLUSERSPROFILE%\dir\is-0m0p8.tmp to %ALLUSERSPROFILE%\dir\unins000.exe
- from %TEMP%\is-3afc4.tmp\is-hb3m7.tmp to %TEMP%\is-3afc4.tmp\7za.exe
- from %TEMP%\is-3afc4.tmp\is-l0lfa.tmp to %TEMP%\is-3afc4.tmp\logo y.bmp
- 'vk##.org':443
- 'vk##.org':443
- DNS ASK vk##.org
- '%TEMP%\is-u5f06.tmp\<File name>.tmp' /SL5="$14023E,1074986,831488,<Full path to file>"
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN 7856757 /SC ONLOGON /TR "%ALLUSERSPROFILE%\dir\V-K_D-J.exe /H" /F /DELAY 0001:00 /RL HIGHEST