Техническая информация
- [HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%\Microsoft\CoreRuntime' = '00000000'
- Процесс ~7bb3.tmp, модуль Amsi.dll
- Процесс searchprotocolhost.exe, модуль Amsi.dll
- Процесс searchfilterhost.exe, модуль Amsi.dll
- Процесс taskhostw.exe, модуль Amsi.dll
- Процесс sihost.exe, модуль Amsi.dll
- Процесс ~7bb3.tmp, модуль ntdll.dll
- Процесс searchprotocolhost.exe, модуль ntdll.dll
- Процесс searchfilterhost.exe, модуль ntdll.dll
- Процесс taskhostw.exe, модуль ntdll.dll
- Процесс sihost.exe, модуль ntdll.dll
- %TEMP%\~7bb3.tmp
- %LOCALAPPDATA%\microsoft\coreruntime\searchprotocolhost.exe
- %LOCALAPPDATA%\microsoft\coreruntime\searchfilterhost.exe
- %LOCALAPPDATA%\microsoft\coreruntime\taskhostw.exe
- %LOCALAPPDATA%\microsoft\coreruntime\sihost.exe
- %LOCALAPPDATA%\microsoft\coreruntime\searchprotocolhost.exe
- %LOCALAPPDATA%\microsoft\coreruntime\searchfilterhost.exe
- %LOCALAPPDATA%\microsoft\coreruntime\taskhostw.exe
- %LOCALAPPDATA%\microsoft\coreruntime\sihost.exe
- DNS ASK de####sync.ipv64.de
- DNS ASK mo#####.map.fastly.net
- '%TEMP%\~7bb3.tmp'
- '%LOCALAPPDATA%\microsoft\coreruntime\searchprotocolhost.exe'
- '%LOCALAPPDATA%\microsoft\coreruntime\searchfilterhost.exe'
- '%LOCALAPPDATA%\microsoft\coreruntime\taskhostw.exe'
- '%LOCALAPPDATA%\microsoft\coreruntime\sihost.exe'
- '%TEMP%\~7bb3.tmp' (со скрытым окном)