Техническая информация
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %HOMEPATH%\desktop\508softwareandos.doc
- %HOMEPATH%\desktop\applicantform_en.doc
- %HOMEPATH%\desktop\hanni_umami_chapter.doc
- %HOMEPATH%\desktop\holycrosschurchinstructions.docx
- %HOMEPATH%\desktop\issi2013_template_for_posters.docx
- %APPDATA%\mozilla\firefox\profiles.ini
- C:\users\public\uelgji7fe2
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\2f1a6504-0641-44cf-8bb5-3612d865f2e5.vsch
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\3ccd5499-87a8-4b10-a215-608888dd3b55.vsch
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\policy.vpol
- %TEMP%\ovsalmgcxigfvajdvkwtonqfkjpuljxz.exe
- C:\users\public\rv4rxoes0n
- C:\users\public\t7gbw5v9cy
- C:\users\public\jpmpobnkar
- C:\users\public\i09wsbuzyj
- C:\users\public\2tnf2drief
- C:\users\public\eefjf0cf1g
- C:\users\public\oyevs83yw6
- C:\users\public\5iufiwc7ho
- C:\users\public\zzvqiceilt
- C:\users\public\spyymbncbl
- C:\users\public\c675qxvz97
- C:\users\public\xgl7ntk49h
- C:\users\public\ki9gwtm8er
- C:\users\public\rl9ledvdj5
- C:\users\public\zheg9syztw
- %LOCALAPPDATA%\microsoft\vault\4bf4c442-9b8a-41a0-b380-dd4a704ddb28\policy.vpol
- <Текущая директория>\ovsalmgcxigfvajdvkwtonqfkjpuljxz.exe.ico
- C:\users\public\uelgji7fe2
- C:\users\public\rv4rxoes0n
- C:\users\public\t7gbw5v9cy
- C:\users\public\jpmpobnkar
- C:\users\public\i09wsbuzyj
- C:\users\public\2tnf2drief
- C:\users\public\eefjf0cf1g
- C:\users\public\oyevs83yw6
- C:\users\public\5iufiwc7ho
- C:\users\public\zzvqiceilt
- C:\users\public\spyymbncbl
- C:\users\public\c675qxvz97
- C:\users\public\xgl7ntk49h
- C:\users\public\ki9gwtm8er
- C:\users\public\rl9ledvdj5
- C:\users\public\zheg9syztw
- %TEMP%\ovsalmgcxigfvajdvkwtonqfkjpuljxz.exe
- <Текущая директория>\ovsalmgcxigfvajdvkwtonqfkjpuljxz.exe.ico
- 'se###re.space':80
- 'ip##fo.io':443
- http://se###re.space/gamebase.php?qP#############################################################################################################################################################...
- DNS ASK se###re.space
- DNS ASK ip##fo.io
- '%TEMP%\ovsalmgcxigfvajdvkwtonqfkjpuljxz.exe' /stext "OVSALMGCXIGFVAJDVKWTONQFKJPULJXZ.exe.ico"