Техническая информация
- <SYSTEM32>\tasks\nvngxupdatecheckdaily_{aefe271c-271c-271c-271c-aefe271c271c}
- %WINDIR%\explorer.exe
- %TEMP%\5c1b.tmp
- %APPDATA%\bwshvua
- %APPDATA%\tcsbgas
- %APPDATA%\bwshvua
- %APPDATA%\tcsbgas
- %TEMP%\5c1b.tmp
- %TEMP%\5c1b.tmp
- 'ol##us.casa':443
- 'ol##us.casa':443
- DNS ASK ol##us.casa
- DNS ASK microsoft.com
- '%APPDATA%\bwshvua'
- '%APPDATA%\bwshvua' ' (со скрытым окном)
- '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /format:csv
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\SecurityCenter2 Path FirewallProduct Get displayName /format:csv
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\SecurityCenter2 Path AntiSpywareProduct Get displayName /format:csv
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\cimv2 Path Win32_Processor Get Name,DeviceID,NumberOfCores /format:csv
- '<SYSTEM32>\wbem\wmic.exe' /namespace:\\root\cimv2 Path Win32_Product Get Name,Version /format:csv
- '<SYSTEM32>\taskeng.exe' {6E5EFEF1-62A7-49FA-A7C4-C51512A4A99D} S-1-5-21-1960123792-2022915161-3775307078-1001:sfpqctpcf\user:Interactive:[1]