Техническая информация
- %TEMP%\CwjHwlBOttdXuU0\»сИЎЧўІбВл.exe
- <SYSTEM32>\msiexec.exe -Embedding B6AD42594647297115DCDCC509A1A7F1 C
- <SYSTEM32>\msiexec.exe /V
- <SYSTEM32>\msiexec.exe /package "%TEMP%\CwjHwlBOttdXuU0\setup.msi"
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\A8FABA189DB7D25FBA7CAC806625FD30
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\A8FABA189DB7D25FBA7CAC806625FD30
- %TEMP%\MSI4.tmp
- %TEMP%\MSI3.tmp
- %TEMP%\CwjHwlBOttdXuU0\setup.msi
- %TEMP%\nsn2.tmp
- %TEMP%\CwjHwlBOttdXuU0\»сИЎЧўІбВл.exe
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5
- %TEMP%\227d1.msi
- %TEMP%\MSI4.tmp
- %TEMP%\MSI3.tmp
- 'cs######4-crl.verisign.com':80
- 'crl.verisign.com':80
- 'wp#d':80
- cs######4-crl.verisign.com/CSC3-2004.crl
- crl.verisign.com/pca3.crl
- wp#d/wpad.dat
- DNS ASK cs######4-crl.verisign.com
- DNS ASK crl.verisign.com
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: ''