Техническая информация
- ClassName: 'Regmonclass', WindowName: ''
- ClassName: 'Filemonclass', WindowName: ''
- <SYSTEM32>\nsudo.exe
- <SYSTEM32>\nsudoc.exe
- %ALLUSERSPROFILE%\node
- %ALLUSERSPROFILE%\node.dll
- %ALLUSERSPROFILE%\easy remove - autodeskïµáðèГ¼þð¶ôø¹¤¾ß 3.3.0.9.exe
- %TEMP%\7-zip32.dll
- 'ba##u.com':443
- 'xz.#jtx.cn':443
- 'ba##u.com':443
- 'xz.#jtx.cn':443
- DNS ASK xz.#jtx.cn
- DNS ASK ba##u.com
- ClassName: '4823-00000029' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- ClassName: 'Easyremove3.3.0.9' WindowName: 'Easy remove 3.3.0.9'
- '<SYSTEM32>\nsudo.exe' -U:S -P:E "%ALLUSERSPROFILE%\Easy remove - AutodeskϵÁÐÈГВјГѕГђВ¶Г”Г¹¤¾ß 3.3.0.9.exe"
- '%ALLUSERSPROFILE%\easy remove - autodeskïµáðèГ¼þð¶ôø¹¤¾ß 3.3.0.9.exe'
- '<SYSTEM32>\cmd.exe' /c NSudo -U:S -P:E "%ALLUSERSPROFILE%\Easy remove - AutodeskϵÁÐÈГВјГѕГђВ¶Г”Г¹¤¾ß 3.3.0.9.exe"' (со скрытым окном)
- '%ALLUSERSPROFILE%\easy remove - autodeskïµáðèГ¼þð¶ôø¹¤¾ß 3.3.0.9.exe' ' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c NSudo -U:S -P:E "%ALLUSERSPROFILE%\Easy remove - AutodeskϵÁÐÈГВјГѕГђВ¶Г”Г¹¤¾ß 3.3.0.9.exe"