Техническая информация
- %TEMP%\9rdft8kz.0.cs
- %TEMP%\9rdft8kz.cmdline
- %TEMP%\9rdft8kz.out
- %TEMP%\cscb368.tmp
- %TEMP%\resb369.tmp
- %TEMP%\9rdft8kz.dll
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %TEMP%\resb369.tmp
- %TEMP%\cscb368.tmp
- %TEMP%\9rdft8kz.dll
- %TEMP%\9rdft8kz.cmdline
- %TEMP%\9rdft8kz.out
- %TEMP%\9rdft8kz.0.cs
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK microsoft.com
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\9rdft8kz.cmdline"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESB369.tmp" "%TEMP%\CSCB368.tmp"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\9rdft8kz.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESB369.tmp" "%TEMP%\CSCB368.tmp"