Техническая информация
- %ProgramFiles(x86)%\microsoft office\office16\excel.exe
- '%WINDIR%\syswow64\rundll32.exe' C:\Users\Public\Documents\EGAooY.txt,DllRegisterServer
- %WINDIR%\explorer.exe
- %ProgramFiles%\UNP\Logs\UpdateNotificationPipeline.001.etl
- 'ad####lyasia.com':443
- DNS ASK ad####lyasia.com
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '<SYSTEM32>\taskhostw.exe' None
- '<SYSTEM32>\usoclient.exe' StartScan
- '<SYSTEM32>\apphostregistrationverifier.exe'
- '%ProgramFiles(x86)%\microsoft office\office16\excel.exe' /dde
- '<SYSTEM32>\devicecensus.exe' UserCxt
- '<SYSTEM32>\svchost.exe' -k netsvcs -p