Техническая информация
- %ALLUSERSPROFILE%\package.xoml
- %ALLUSERSPROFILE%\ccm_deploy.xml
- %TEMP%\copyrighted_photos_all_2020-09-24.doc
- %TEMP%\ra1wjwxg.0cs
- %TEMP%\ra1wjwxg.cmdline
- %TEMP%\ra1wjwxg.out
- %TEMP%\ra1wjwxg\csc9d4bd156e44f41988d1be64386a2199.tmp
- %TEMP%\res709d.tmp
- %TEMP%\ra1wjwxg\tmp249f.tmp.dll
- %WINDIR%\temp\chrome_installer-9925305.log
- %TEMP%\res709d.tmp
- %TEMP%\ra1wjwxg\csc9d4bd156e44f41988d1be64386a2199.tmp
- %TEMP%\ra1wjwxg.0cs
- %TEMP%\ra1wjwxg\tmp249f.tmp.pdb
- %TEMP%\ra1wjwxg\tmp249f.tmp.dll
- %TEMP%\ra1wjwxg.cmdline
- %TEMP%\ra1wjwxg.out
- http://34.##.143.193/favicon.ico
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\microsoft.workflow.compiler.exe' %ALLUSERSPROFILE%\ccm_deploy.xml %WINDIR%\Temp\chrome_installer-9925305.log' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\ra1wjwxg.cmdline"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES709D.tmp" "%TEMP%\ra1wjwxg\CSC9D4BD156E44F41988D1BE64386A2199.TMP"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\microsoft.workflow.compiler.exe' %ALLUSERSPROFILE%\ccm_deploy.xml %WINDIR%\Temp\chrome_installer-9925305.log
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\ra1wjwxg.cmdline"
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES709D.tmp" "%TEMP%\ra1wjwxg\CSC9D4BD156E44F41988D1BE64386A2199.TMP"