Техническая информация
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'Privacy' = '%PROGRAMDATA%\Internet Explorer\Microsoft\iexplorer.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'Privacy' = '%PROGRAMDATA%\Internet Explorer\Microsoft\iexplorer.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Byte' = '%PROGRAMDATA%\Internet Explorer\Microsoft\iexplorer.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Hex' = '%PROGRAMDATA%\Internet Explorer\Microsoft\iexplorer.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Active Setup\Installed Components\{W264105Q-OK7P-5EL2-1LE4-F5U81WO5056Q}] 'StubPath' = '%PROGRAMDATA%\Internet Explorer\Microsoft\iexplorer.exe Restart'
- %WINDIR%\syswow64\explorer.exe
- iexplorer.exe
- %PROGRAMDATA%\internet explorer\microsoft\iexplorer.exe
- %TEMP%\xx--xx--xx.txt
- %APPDATA%\logs.dat
- %TEMP%\xxx.xxx
- %TEMP%\uuu.uuu
- %APPDATA%\logs.dat
- %TEMP%\xx--xx--xx.txt
- %TEMP%\uuu.uuu
- %TEMP%\xxx.xxx
- %TEMP%\uuu.uuu
- %TEMP%\xxx.xxx
- DNS ASK mi######t-dynamic.ddns.net
- ClassName: 'shell_traywnd' WindowName: ''
- '%PROGRAMDATA%\internet explorer\microsoft\iexplorer.exe'
- '%WINDIR%\syswow64\explorer.exe'