Техническая информация
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\Security Center.exe" "Security Center.exe" ENABLE
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- %TEMP%\sex.pdf
- %TEMP%\security_center_protected.exe
- %APPDATA%\security center.exe
- %TEMP%\security_center_protected.exe
- %APPDATA%\security center.exe
- 'el#####y369.linkpc.net':3489
- DNS ASK el#####y369.linkpc.net
- ClassName: 'Registry Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- ClassName: 'File Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: 'Process Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- '%TEMP%\security_center_protected.exe'
- '%APPDATA%\security center.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\Security Center.exe" "Security Center.exe" ENABLE' (со скрытым окном)
- '%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrord32.exe' "%TEMP%\sex.pdf"