Техническая информация
- %WINDIR%\explorer.exe
- %WINDIR%\syswow64\raserver.exe
- %WINDIR%\syswow64\msiexec.exe
- %WINDIR%\syswow64\help.exe
- %WINDIR%\syswow64\rundll32.exe
- %WINDIR%\syswow64\systray.exe
- %WINDIR%\syswow64\chkdsk.exe
- %WINDIR%\syswow64\cmmon32.exe
- %WINDIR%\syswow64\napstat.exe
- %WINDIR%\syswow64\control.exe
- %WINDIR%\syswow64\wininit.exe
- %WINDIR%\syswow64\wuapp.exe
- iexplore.exe
- firefox.exe
- Процесс iexplore.exe, модуль wininet.dll
- Процесс firefox.exe, модуль nss3.dll
- %WINDIR%\syswow64\autofmt.exe
- DNS ASK co###naksoy.com
- DNS ASK ne###co.cricket
- '%WINDIR%\syswow64\raserver.exe'
- '%WINDIR%\syswow64\cmd.exe' del "<Полный путь к файлу>"
- '%WINDIR%\syswow64\msiexec.exe'
- '%WINDIR%\syswow64\help.exe'
- '%WINDIR%\syswow64\rundll32.exe'
- '%WINDIR%\syswow64\systray.exe'
- '%WINDIR%\syswow64\chkdsk.exe'
- '%WINDIR%\syswow64\cmmon32.exe'
- '%WINDIR%\syswow64\napstat.exe'
- '%WINDIR%\syswow64\control.exe'
- '%WINDIR%\syswow64\wininit.exe'
- '%WINDIR%\syswow64\wuapp.exe'
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\syswow64\cscript.exe'