Техническая информация
- '<SYSTEM32>\dumprep.exe' 2956 -dm 7 7 %TEMP%\WEReaee.dir00\Svchost.exe.hdmp 16325836412027148
- '<SYSTEM32>\dumprep.exe' 2988 -dm 7 7 %TEMP%\WER0530.dir00\Svchost.exe.hdmp 16325836412027148
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\sysdm.cpl,NoExecuteProcessException %TEMP%\Svchost.exe
- '<SYSTEM32>\dumprep.exe' 2988 -dm 7 7 %TEMP%\WER0530.dir00\Svchost.exe.mdmp 16325836412027128
- '%TEMP%\RarSFX0\GFQYjs.exe' "TmiEVp"
- '%TEMP%\Svchost.exe'
- '<SYSTEM32>\dumprep.exe' 2956 -dm 7 7 %TEMP%\WEReaee.dir00\Svchost.exe.mdmp 16325836412027128
- Svchost.exe
- %TEMP%\WEReaee.dir00\Svchost.exe.hdmp
- %TEMP%\WER0530.dir00\Svchost.exe.mdmp
- %TEMP%\WER0530.dir00\Svchost.exe.hdmp
- %TEMP%\WEReaee.dir00\manifest.txt
- %TEMP%\WEReaee.dir00\appcompat.txt
- %TEMP%\RarSFX0\HUajHm.txt
- %TEMP%\RarSFX0\TmiEVp
- %TEMP%\RarSFX0\GFQYjs.exe
- %TEMP%\WEReaee.dir00\Svchost.exe.mdmp
- %TEMP%\RarSFX0\uCsPsJ.exe
- %TEMP%\RarSFX0\TmiEVp
- %TEMP%\RarSFX0\uCsPsJ.exe
- %TEMP%\RarSFX0\GFQYjs.exe
- %TEMP%\RarSFX0\HUajHm.txt
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''