Техническая информация
- '%APPDATA%\Roaming\nosta\woxsta.exe'
- '<SYSTEM32>\taskhost.exe' $(Arg0)
- C:\ProgramData\Microsoft\RAC\Temp\sql904D.tmp
- C:\ProgramData\Microsoft\RAC\Temp\sql908C.tmp
- %APPDATA%\Roaming\nosta\woxsta.exe
- <SYSTEM32>\Tasks\Microsoft\Windows Defender\MP Scheduled Scan
- <SYSTEM32>\PerfStringBackup.TMP
- %TEMP%\~DF9EA4794745610626.TMP
- %WINDIR%\inf\WmiApRpl\WmiApRpl.h
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- %WINDIR%\inf\WmiApRpl\0009\WmiApRpl.ini
- %WINDIR%\inf\WmiApRpl\0019\WmiApRpl.ini