Техническая информация
- [<HKCU>\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts]
- [<HKCU>\Identities\{91255D00-95D9-49F5-8E84-7C027F5283B7}\Software\Microsoft\Internet Account Manager\Accounts]
- [<HKCU>\Identities\{91255D00-95D9-49F5-8E84-7C027F5283B7}\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts]
- [<HKCU>\Software\Microsoft\MSNMessenger]
- [<HKCU>\Software\Yahoo\Pager]
- [<HKCU>\Software\Microsoft\IdentityCRL]
- [<HKCU>\Software\Microsoft\Windows Live Mail]
- <PATH_SAMPLE>stub.exe
- %TEMP%\passwortfox.exe
- %TEMP%\iepv.exe
- %TEMP%\mailpv.exe
- %TEMP%\mspass.exe
- %TEMP%\produkey.exe
- %TEMP%\pspv.exe
- %TEMP%\rdpv.exe
- %TEMP%\whk.exe
- %TEMP%\iecacheview.exe
- %TEMP%\iehv.exe
- C:\iehistory.txt
- C:\iecacheview.txt
- <PATH_SAMPLE>stub.exe
- %TEMP%\iepv.exe
- '%TEMP%\passwortfox.exe' /stext C:\PasswortFox.txt
- '%TEMP%\passwortfox.exe' /stext C:\InternetExplorer.txt
- '%TEMP%\mailpv.exe' /stext C:\MailPasses.txt
- '%TEMP%\mspass.exe' /stext C:\MessengerPasses.txt
- '%TEMP%\produkey.exe' /stext C:\ProduKey.txt
- '%TEMP%\pspv.exe' /stext C:\ProtectedStorage.txt
- '%TEMP%\rdpv.exe' /stext C:\RemoteDesktop.txt
- '%TEMP%\whk.exe' /stext C:\Whirelless.txt
- '%TEMP%\iecacheview.exe' /stext C:\IECacheView.txt
- '%TEMP%\iehv.exe' /stext C:\IeHistory.txt