Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\wininit.exe
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\wininit.exe" "wininit.exe" ENABLE
- %TEMP%\autd98e.tmp
- %TEMP%\autda2b.tmp
- %TEMP%\windscribe.exe
- %TEMP%\is-ckpbr.tmp\windscribe.tmp
- %TEMP%\setup log 2019-10-22 #001.txt
- %TEMP%\is-vj4qt.tmp\_isetup\_setup64.tmp
- %TEMP%\autd98e.tmp
- %TEMP%\autda2b.tmp
- DNS ASK mi#########rdsblack.freedynamicdns.net
- ClassName: 'Qt5QWindowIcon' WindowName: 'Windscribe'
- '%APPDATA%\microsoft\windows\start menu\programs\startup\wininit.exe'
- '%TEMP%\windscribe.exe'
- '%TEMP%\is-ckpbr.tmp\windscribe.tmp' /SL5="$C0224,16364339,486912,%TEMP%\Windscribe.exe"
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\wininit.exe" "wininit.exe" ENABLE' (со скрытым окном)