Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\WINIO] 'ImagePath' = '%TEMP%\winio64.sys'
- 'WINIO' %TEMP%\winio64.sys
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- %TEMP%\winio64.sys
- %WINDIR%\temp\uddbc4c.tmp
- %WINDIR%\temp\cab64ea.tmp
- %WINDIR%\temp\tar64eb.tmp
- %WINDIR%\temp\uddbc4c.tmp
- %WINDIR%\temp\cab64ea.tmp
- %WINDIR%\temp\tar64eb.tmp
- 'localhost':49174
- 'te##.#ubglicense.cf':443
- 'microsoft.com':80
- 'localhost':49175
- 'te##.#ubglicense.cf':443
- DNS ASK te##.#ubglicense.cf
- DNS ASK microsoft.com
- ClassName: 'Registry Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- ClassName: 'File Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- ClassName: 'Process Monitor - Sysinternals: www.sysinternals.com' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c wmic csproduct get UUID
- '<SYSTEM32>\wbem\wmic.exe' csproduct get UUID
- '<SYSTEM32>\cmd.exe' /c wmic cpu get processorid
- '<SYSTEM32>\wbem\wmic.exe' cpu get processorid
- '<SYSTEM32>\cmd.exe' /c wmic bios get serialnumber
- '<SYSTEM32>\wbem\wmic.exe' bios get serialnumber
- '<SYSTEM32>\cmd.exe' /c wmic diskdrive get serialnumber
- '<SYSTEM32>\wbem\wmic.exe' diskdrive get serialnumber