Техническая информация
- '%TEMP%\ins6375\ins.exe' /e5362944 /u50d1d9d5-cf90-407c-820a-35e05bc06f2f
- '%TEMP%\ins6375\ins6375.exe' ins.exe /e5362944 /u50d1d9d5-cf90-407c-820a-35e05bc06f2f
- '<SYSTEM32>\wermgr.exe' "-outproc" "836" "4200"
- C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_80072f78_805ff6e6daf5fedbb13daf2b1d56b5cbd7ea195_cab_0b6055cd\client_manifest.txt
- %WINDIR%\Temp\OutofProcReport1072702.txt
- C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_7.6.7600.256_d2caf64b7dbca2d781154d2562964c262846251_cab_0cc05f10\Report.wer
- %TEMP%\ins6375\ins6375.exe
- %TEMP%\ins6375\ins.exe
- %WINDIR%\Temp\OutofProcReport1072702.txt
- '20#.#6.232.182':80
- 'download.windowsupdate.com':80
- 'ap#.#ocdn.com':80
- 20#.#6.232.182/fwlink/?Li######################################################################################################
- ap#.#ocdn.com/installer/50d1d9d5-cf90-407c-820a-35e05bc06f2f/5362944/config
- DNS ASK www.up####.microsoft.com
- DNS ASK go.###rosoft.com
- DNS ASK do#####d.microsoft.com
- DNS ASK ap#.#ocdn.com
- DNS ASK download.windowsupdate.com