Техническая информация
- <SYSTEM32>\tasks\nvngxupdatecheckdaily_{aefe271c-271c-271c-271c-aefe271c271c}
- %TEMP%\5c1b.tmp
- %APPDATA%\bsjvvee
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %APPDATA%\uwgcjiu
- %APPDATA%\bsjvvee
- %APPDATA%\uwgcjiu
- %TEMP%\5c1b.tmp
- 'ge##o.club':443
- DNS ASK ge##o.club
- '%APPDATA%\bsjvvee'
- '%APPDATA%\bsjvvee' ' (со скрытым окном)
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /format:csv
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\SecurityCenter2 Path FirewallProduct Get displayName /format:csv
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\SecurityCenter2 Path AntiSpywareProduct Get displayName /format:csv
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\cimv2 Path Win32_Processor Get Name,DeviceID,NumberOfCores /format:csv
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\cimv2 Path Win32_Product Get Name,Version /format:csv
- '<SYSTEM32>\taskeng.exe' {5FAE2BC5-494A-46B5-8251-F5C0EB564855} S-1-5-21-1960123792-2022915161-3775307078-1001:kiiatlxpy\user:Interactive:[1]