In almost every five minutes, I come out of the AVG avg stop downloading files and do not know which program wants to download these files.
I have read this before WMI Infections
So, i opened this question because, i think this malware variant used WMI to maintain persistence.
I have read this too : Explained: WMI hijackers
Effectively, the script to be executed is hidden from the user, and the script (as a file) isn’t stored on the system. Which is why it is considered as another fileless infection. WMI techniques were used by malware like Stuxnet in the past.