Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'winssmngr' = '%APPDATA%\Microsoft\installer\{c018d68a-4554-4dd3-a844-cd3b8e04cd0a}\_6F7D1~1.EXE'
- <Имя диска съемного носителя>:\notepad.exe
- <Имя диска съемного носителя>:\wrar520.exe
- <Имя диска съемного носителя>:\winmine.exe
- <Имя диска съемного носителя>:\chromesetup.exe
- <Имя диска съемного носителя>:\hadac_newsletter_july_2010_final.docx
- <Имя диска съемного носителя>:\glidescope_review_rev_010.docx
- <Имя диска съемного носителя>:\nwfieldnotes1966.docx
- <SYSTEM32>\ctfmon.exe
- %APPDATA%\<Имя файла>.exe
- %TEMP%\rcxf.tmp
- %TEMP%\e.tmp
- %TEMP%\rcxd.tmp
- %TEMP%\rcxc.tmp
- %TEMP%\rcxb.tmp
- %TEMP%\rcxa.tmp
- %TEMP%\rcx9.tmp
- %TEMP%\rcx8.tmp
- %TEMP%\rcx7.tmp
- %TEMP%\rcx10.tmp
- %TEMP%\rcx6.tmp
- %TEMP%\rcx4.tmp
- %TEMP%\rcx3.tmp
- %TEMP%\rcx2.tmp
- %TEMP%\1.tmp
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbd031b21370
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb1e98682e87
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb6cff1e499d
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb56961960ce
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb9c1292ea7f
- %TEMP%\rcx5.tmp
- %TEMP%\rcx11.tmp
- %TEMP%\rcx12.tmp
- %TEMP%\rcx13.tmp
- %TEMP%\rcx28.tmp
- %TEMP%\rcx27.tmp
- %TEMP%\rcx26.tmp
- %TEMP%\rcx25.tmp
- %TEMP%\rcx24.tmp
- %TEMP%\rcx23.tmp
- %TEMP%\rcx22.tmp
- %TEMP%\21.tmp
- %TEMP%\rcx20.tmp
- %TEMP%\rcx1f.tmp
- %TEMP%\rcx1e.tmp
- %TEMP%\rcx1d.tmp
- %TEMP%\rcx1c.tmp
- %TEMP%\rcx1b.tmp
- %TEMP%\rcx1a.tmp
- %TEMP%\rcx19.tmp
- %TEMP%\rcx18.tmp
- %TEMP%\rcx17.tmp
- %TEMP%\rcx16.tmp
- %TEMP%\15.tmp
- %TEMP%\rcx14.tmp
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb599b2fb9f2
- %TEMP%\rcx29.tmp
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb43322acf24
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbcb61560084
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbb926fd0ef4
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb16a9a5bd84
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbbd2c146718
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb7ab5b2368b
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbc0312bc13c
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb249f0f0031
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb7d58f1cabf
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb27424f9366
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb96025f81d4
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb13a48e6360
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb6425a62728
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb2e9d180a5d
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb173413208e
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb7f0ae57e97
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\a6e85cb9d210ac7db3b5c427c8bae22d_e13ca0e1-3819-2857-6250-be1f20373d29
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb7ea70eb9a8
- %APPDATA%\microsoft\installer\{c018d68a-4554-4dd3-a844-cd3b8e04cd0a}\_6f7d185ca4f8.exe
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_ffffff0717230828
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\be1e17081cb14daa94c2ca351ba279c3_e13ca0e1-3819-2857-6250-be1f20373d29
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\dfd56e1c79a287f001d5eb1ce0f45a7c_e13ca0e1-3819-2857-6250-be1f20373d29
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbf3d5a2f413
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb1306652950
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb3f769936fd
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbf9fa21ac4c
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb72e3c6ab17
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbec58d80eec
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb542dab6cf4
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb6ad202cae5
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb6285ed7490
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbfe535aaabd
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbc9961147bb
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb65647d7de7
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb5d17692793
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb89c3eea962
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb7eac146f0c
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbe582e6cc14
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb8ca27eb2b9
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbf377510fc1
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbdd0e4b26f3
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb9a97e9f566
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbf61b90a3f6
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb7ce2ceb543
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb6679c9cc74
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbacf5425625
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb3c7083ddda
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb89aea35ad5
- %TEMP%\rcx2a.tmp
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\dfd56e1c79a287f001d5eb1ce0f45a7c_e13ca0e1-3819-2857-6250-be1f20373d29
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbf377510fc1
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb8ca27eb2b9
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbe582e6cc14
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb7eac146f0c
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb89c3eea962
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb5d17692793
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb65647d7de7
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbc9961147bb
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbfe535aaabd
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb9a97e9f566
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbdd0e4b26f3
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb6285ed7490
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbec58d80eec
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb72e3c6ab17
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbcb61560084
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb89aea35ad5
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb43322acf24
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb599b2fb9f2
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb9c1292ea7f
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb56961960ce
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb6cff1e499d
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb6ad202cae5
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb542dab6cf4
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbf61b90a3f6
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb7ce2ceb543
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb6679c9cc74
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_ffffff0717230828
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb7ea70eb9a8
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb7f0ae57e97
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb173413208e
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb2e9d180a5d
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbf3d5a2f413
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb6425a62728
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb96025f81d4
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb27424f9366
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb7d58f1cabf
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\be1e17081cb14daa94c2ca351ba279c3_e13ca0e1-3819-2857-6250-be1f20373d29
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb249f0f0031
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb7ab5b2368b
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbbd2c146718
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb16a9a5bd84
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbb926fd0ef4
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb13a48e6360
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb1306652950
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb3f769936fd
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbf9fa21ac4c
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb3c7083ddda
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbacf5425625
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbc0312bc13c
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbb1e98682e87
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\eaf5343e-dc9b45c5-9f9dbffb-518010bd\_bbbbbbd031b21370
- %APPDATA%\microsoft\crypto\aes\s-1-4-70-138890796-4284742437-459436012-966\be1e17081cb14daa94c2ca351ba279c3_e13ca0e1-3819-2857-6250-be1f20373d29
- %TEMP%\1.tmp
- %TEMP%\e.tmp
- %TEMP%\15.tmp
- %TEMP%\21.tmp
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-1229272821-842925246-1060284298-1003\f58155b4b1d5a524ca0261c3ee99fb50_5f9fe710-99e6-4c04-be62-a7f1b8b321d1
- %TEMP%\1.tmp
- %TEMP%\e.tmp
- %TEMP%\15.tmp
- %TEMP%\21.tmp
- DNS ASK th######hometheather.com
- '%APPDATA%\<Имя файла>.exe' "<Полный путь к файлу>"