Техническая информация
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%TEMP%\A9Rwibuo9_15tksf3_84.tmp\re.doc"
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1400' = '00000003'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1C00' = '00000000'
- %TEMP%\a9rwibuo9_15tksf3_84.tmp\re.doc
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\cookies-journal
- %TEMP%\etilqs_eentfxgxp8qbuag
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\cookies
- %TEMP%\a9rv6ivo2_15tksf5_84.tmp
- 'a.##mfe.co':443
- 'x1.#.lencr.org':80
- http://x1.#.lencr.org/
- 'a.##mfe.co':443
- DNS ASK a.##mfe.co
- DNS ASK x1.#.lencr.org