Техническая информация
- %TEMP%\1.tmp\2.tmp\3.bat
- %TEMP%\tmp5.tmp
- %TEMP%\tmp6.tmp
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\tmp7.tmp
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %WINDIR%\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{7FC4D891-748B-4B42-9BD9-EEEB2398C395}.crmlog
- %TEMP%\tmp5.tmp
- %TEMP%\tmp6.tmp
- %TEMP%\tmp7.tmp
- %WINDIR%\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{BF4C4D5C-6924-41E8-9BF1-DCC37DF6F31D}.crmlog
- %WINDIR%\Registration\R000000000007.clb
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\2.tmp\3.bat" <Полный путь к файлу>"
- '<SYSTEM32>\vssvc.exe'
- '<SYSTEM32>\dllhost.exe' /Processid:{D7BA884D-10F4-4D2C-AC14-F944AE1B33CB}
- '<SYSTEM32>\dllhost.exe' /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
- '<SYSTEM32>\msdtc.exe'