Technical Information
- '%WINDIR%\fx45.exe' /q /norestart
- '<SYSTEM32>\p\plugandplay__.exe' -install
- '%WINDIR%\fx45.exe' (downloaded from the Internet)
- '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe' -UseCLSID {B5091CB1-DF4D-4543-956D-161CCA2CE762} -Comment "NGen Worker Process"
- '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe' -UseCLSID {9B8B892B-270A-4E8A-9D7C-E0D614F39828} -Comment "NGen Worker Process"
- '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\ngen.exe' update /force /queue
- %WINDIR%\fx45.exe
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\fifo.log
- <SYSTEM32>\p\o.txt
- <SYSTEM32>\p\plugandplay__.exe
- %WINDIR%\assembly\NativeImages_v4.0.30319_32\index1c.dat
- %WINDIR%\assembly\NativeImages_v4.0.30319_32\index1b.dat
- %WINDIR%\assembly\NativeImages_v2.0.50727_32\indexa5.dat
- '20#.#6.232.182':80
- 'an######llectiononline.com':80
- 'wp#d':80
- http://download.microsoft.com/download/B/A/4/BA4A7E71-2906-4B2D-A0E1-80CF16844F5F/dotNetFx45_Full_setup.exe via 20#.#6.232.182
- http://an######llectiononline.com/inst_b.php?p=############
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK download.microsoft.com
- DNS ASK an######llectiononline.com
- DNS ASK wp#d