Техническая информация
- %WINDIR%\microsoft.net\framework\v4.0.30319\installutil.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\installutil.exe
- %TEMP%\drvhdd.exe
- %TEMP%\usbdrvi.exe
- %TEMP%\wincpu.exe
- %TEMP%\winlogonw.exe
- %TEMP%\winplayeer.exe
- 'dg#####n20785.hopto.org':35800
- 'dg#####n20785.hopto.org':35800
- DNS ASK dg#####n20785.hopto.org
- '%TEMP%\drvhdd.exe'
- '%TEMP%\usbdrvi.exe'
- '%TEMP%\wincpu.exe'
- '%TEMP%\winlogonw.exe'
- '%TEMP%\winplayeer.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMgAwAA==' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMgAwAA==
- '%WINDIR%\microsoft.net\framework\v4.0.30319\installutil.exe'
- '%WINDIR%\syswow64\cmd.exe'