

"cmd.exe" wrote 32 bytes to a remote process "C:\Windows\SysWOW64\reg.exe" (Handle: 296) "cmd.exe" wrote 8 bytes to a remote process "C:\Windows\SysWOW64\reg.exe" (Handle: 296) "cmd.exe" wrote 4 bytes to a remote process "C:\Windows\SysWOW64\reg.exe" (Handle: 296) "cmd.exe" wrote 1500 bytes to a remote process "C:\Windows\SysWOW64\reg.exe" (Handle: 296) "DriverPack.exe" wrote 52 bytes to a remote process "C:\Windows\SysWOW64\mshta.exe" (Handle: 488) "DriverPack.exe" wrote 32 bytes to a remote process "C:\Windows\SysWOW64\mshta.exe" (Handle: 488) "DriverPack.exe" wrote 8 bytes to a remote process "C:\Windows\SysWOW64\mshta.exe" (Handle: 488) "DriverPack.exe" wrote 4 bytes to a remote process "C:\Windows\SysWOW64\mshta.exe" (Handle: 488) "DriverPack.exe" wrote 1500 bytes to a remote process "C:\Windows\SysWOW64\mshta.exe" (Handle: 488)

"wscript.exe" wrote 52 bytes to a remote process "C:\Users\%USERNAME%\AppData\Local\Temp\7ZipSfx.000\DriverPack.exe" (Handle: 824) "wscript.exe" wrote 32 bytes to a remote process "C:\Users\%USERNAME%\AppData\Local\Temp\7ZipSfx.000\DriverPack.exe" (Handle: 824) "wscript.exe" wrote 8 bytes to a remote process "C:\Users\%USERNAME%\AppData\Local\Temp\7ZipSfx.000\DriverPack.exe" (Handle: 824) "wscript.exe" wrote 4 bytes to a remote process "C:\Users\%USERNAME%\AppData\Local\Temp\7ZipSfx.000\DriverPack.exe" (Handle: 824) "wscript.exe" wrote 1500 bytes to a remote process "%TEMP%\7ZipSfx.000\DriverPack.exe" (Handle: 824)
