Техническая информация
- %TEMP%\ixp000.tmp\mayaim~1.exe
- %TEMP%\_mei10602\tcl\encoding\cp861.enc
- %TEMP%\_mei10602\tcl\encoding\cp862.enc
- %TEMP%\_mei10602\tcl\encoding\cp863.enc
- %TEMP%\_mei10602\tcl\encoding\cp864.enc
- %TEMP%\_mei10602\tcl\encoding\cp865.enc
- %TEMP%\_mei10602\tcl\encoding\cp866.enc
- %TEMP%\_mei10602\tcl\encoding\cp874.enc
- %TEMP%\_mei10602\tcl\encoding\cp1257.enc
- %TEMP%\_mei10602\tcl\encoding\cp932.enc
- %TEMP%\_mei10602\tcl\encoding\cp936.enc
- %TEMP%\_mei10602\tcl\encoding\cp949.enc
- %TEMP%\_mei10602\tcl\encoding\cp950.enc
- %TEMP%\_mei10602\tcl\encoding\dingbats.enc
- %TEMP%\_mei10602\tcl\encoding\ebcdic.enc
- %TEMP%\_mei10602\tcl\encoding\cp860.enc
- %TEMP%\_mei10602\tcl\encoding\cp857.enc
- %TEMP%\_mei10602\tcl\encoding\cp855.enc
- %TEMP%\_mei10602\tcl\encoding\cp852.enc
- %TEMP%\_mei10602\tcl\encoding\cp850.enc
- %TEMP%\_mei10602\tcl\encoding\cp775.enc
- %TEMP%\_mei10602\tcl\encoding\cp737.enc
- %TEMP%\_mei10602\tcl\encoding\cp437.enc
- %TEMP%\_mei10602\tcl\encoding\cp1258.enc
- %TEMP%\_mei10602\tcl\encoding\cp869.enc
- %TEMP%\_mei10602\tcl\encoding\cp1256.enc
- %TEMP%\_mei10602\tcl\encoding\cp1255.enc
- %TEMP%\_mei10602\tcl\encoding\cp1254.enc
- %TEMP%\_mei10602\tcl\encoding\cp1253.enc
- %TEMP%\_mei10602\tcl\encoding\cp1252.enc
- %TEMP%\_mei10602\tcl\encoding\cp1251.enc
- %TEMP%\_mei10602\tcl\encoding\cp1250.enc
- %TEMP%\_mei10602\tcl\encoding\euc-cn.enc
- %TEMP%\_mei10602\tcl\encoding\euc-jp.enc
- %TEMP%\_mei10602\tcl\encoding\euc-kr.enc
- %TEMP%\_mei10602\tcl\encoding\gb12345.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-7.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-8.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-9.enc
- %TEMP%\_mei10602\tcl\encoding\jis0201.enc
- %TEMP%\_mei10602\tcl\encoding\jis0208.enc
- %TEMP%\_mei10602\tcl\encoding\jis0212.enc
- %TEMP%\_mei10602\tcl\encoding\koi8-u.enc
- %TEMP%\_mei10602\tcl\encoding\cns11643.enc
- %TEMP%\_mei10602\tcl\encoding\ksc5601.enc
- %TEMP%\_mei10602\tcl\encoding\maccenteuro.enc
- %TEMP%\_mei10602\tcl\encoding\maccroatian.enc
- %TEMP%\_mei10602\tcl\encoding\maccyrillic.enc
- %TEMP%\_mei10602\tcl\encoding\macdingbats.enc
- %TEMP%\_mei10602\tcl\encoding\macgreek.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-6.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-10.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-5.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-1.enc
- %TEMP%\_mei10602\tcl\encoding\gb1988.enc
- %TEMP%\_mei10602\tcl\encoding\gb2312-raw.enc
- %TEMP%\_mei10602\tcl\encoding\gb2312.enc
- %TEMP%\_mei10602\tcl\encoding\iso2022-jp.enc
- %TEMP%\_mei10602\tcl\encoding\iso2022-kr.enc
- %TEMP%\_mei10602\tcl\encoding\iso2022.enc
- %TEMP%\_mei10602\tcl\encoding\maciceland.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-3.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-11.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-13.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-14.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-15.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-16.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-2.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-4.enc
- %TEMP%\_mei10602\tcl\encoding\koi8-r.enc
- %TEMP%\_mei10602\tcl\encoding\big5.enc
- %TEMP%\_mei10602\select.pyd
- %TEMP%\u68u6bk7.out
- %TEMP%\vbcf8a0.tmp
- %TEMP%\resf8a1.tmp
- <Текущая директория>.exe
- %TEMP%\gdrfxiay.0.vb
- %TEMP%\gdrfxiay.cmdline
- %TEMP%\vbcfd03.tmp
- %TEMP%\resef20.tmp
- %TEMP%\resfd04.tmp
- C:\kms.exe
- %TEMP%\mbe3abjp.0.vb
- %TEMP%\mbe3abjp.cmdline
- %TEMP%\mbe3abjp.out
- %TEMP%\vbc167.tmp
- %TEMP%\u68u6bk7.cmdline
- %TEMP%\u68u6bk7.0.vb
- C:\documents and settings.exe
- %TEMP%\resf47c.tmp
- %TEMP%\vbcf46c.tmp
- %TEMP%\h2jnso2s.out
- %TEMP%\h2jnso2s.cmdline
- %TEMP%\h2jnso2s.0.vb
- C:\$recycle.bin.exe
- %TEMP%\gdrfxiay.out
- %TEMP%\vbcef0f.tmp
- %TEMP%\anm-ncs7.out
- %TEMP%\anm-ncs7.cmdline
- %TEMP%\anm-ncs7.0.vb
- %ALLUSERSPROFILE%\system32\xjhowdtzln.ico
- C:\system32\svchost
- %TEMP%\ixp000.tmp\svchost.exe
- %TEMP%\res168.tmp
- C:\msocache.exe
- %TEMP%\njyghkjm.0.vb
- %TEMP%\njyghkjm.cmdline
- %TEMP%\_mei10602\_lzma.pyd
- %TEMP%\_mei10602\_socket.pyd
- %TEMP%\_mei10602\_tkinter.pyd
- %TEMP%\_mei10602\base_library.zip
- %TEMP%\_mei10602\libcrypto-1_1.dll
- %TEMP%\_mei10602\python311.dll
- %TEMP%\_mei10602\tcl86t.dll
- %TEMP%\_mei10602\tcl\encoding\ascii.enc
- %TEMP%\_mei10602\tcl8\8.4\platform-1.0.18.tm
- %TEMP%\_mei10602\tcl8\8.4\platform\shell-1.1.4.tm
- %TEMP%\_mei10602\tcl8\8.5\msgcat-1.6.1.tm
- %TEMP%\_mei10602\tcl8\8.5\tcltest-2.5.3.tm
- %TEMP%\_mei10602\tcl8\8.6\http-2.9.5.tm
- %TEMP%\_mei10602\tcl\auto.tcl
- %TEMP%\_mei10602\_hashlib.pyd
- %TEMP%\qu4azzkm.out
- %TEMP%\_mei10602\_decimal.pyd
- %APPDATA%\system32
- %TEMP%\njyghkjm.out
- %TEMP%\vbc5f9.tmp
- %TEMP%\res5fa.tmp
- C:\perflogs.exe
- %TEMP%\qu4azzkm.0.vb
- %TEMP%\qu4azzkm.cmdline
- %TEMP%\_mei10602\tcl\clock.tcl
- %TEMP%\_mei10602\vcruntime140.dll
- %TEMP%\vbcb94.tmp
- %TEMP%\resba5.tmp
- C:\recovery.exe
- D:\system32\svchost
- %TEMP%\ixp001.tmp\cheat.exe
- %TEMP%\ixp001.tmp\dmmeif~1.exe
- %TEMP%\_mei10602\_bz2.pyd
- %TEMP%\_mei10602\tcl\encoding\macjapan.enc
- C:\system32\svchost
- D:\system32\svchost
- %TEMP%\resef20.tmp
- %TEMP%\_mei10602\tcl\encoding\iso8859-16.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-15.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-14.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-13.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-11.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-10.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-1.enc
- %TEMP%\_mei10602\tcl\encoding\iso2022.enc
- %TEMP%\_mei10602\tcl\encoding\iso2022-kr.enc
- %TEMP%\_mei10602\tcl\encoding\iso2022-jp.enc
- %TEMP%\_mei10602\tcl\encoding\gb2312.enc
- %TEMP%\_mei10602\tcl\encoding\gb2312-raw.enc
- %TEMP%\_mei10602\tcl\encoding\gb1988.enc
- %TEMP%\_mei10602\tcl\encoding\euc-kr.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-3.enc
- %TEMP%\_mei10602\tcl\encoding\euc-jp.enc
- %TEMP%\_mei10602\tcl\encoding\euc-cn.enc
- %TEMP%\_mei10602\tcl\encoding\ebcdic.enc
- %TEMP%\_mei10602\tcl\encoding\dingbats.enc
- %TEMP%\_mei10602\tcl\encoding\cp950.enc
- %TEMP%\_mei10602\tcl\encoding\cp949.enc
- %TEMP%\_mei10602\tcl\encoding\cp936.enc
- %TEMP%\_mei10602\tcl\encoding\cp932.enc
- %TEMP%\_mei10602\tcl\encoding\cp874.enc
- %TEMP%\_mei10602\tcl\encoding\cp869.enc
- %TEMP%\_mei10602\tcl\encoding\cp866.enc
- %TEMP%\_mei10602\tcl\encoding\cp865.enc
- %TEMP%\_mei10602\tcl\encoding\gb12345.enc
- %TEMP%\_mei10602\tcl\encoding\cp1252.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-4.enc
- %TEMP%\_mei10602\_lzma.pyd
- %TEMP%\_mei10602\_hashlib.pyd
- %TEMP%\_mei10602\_decimal.pyd
- %TEMP%\_mei10602\_bz2.pyd
- %TEMP%\_mei10602\vcruntime140.dll
- %TEMP%\_mei10602\tcl86t.dll
- %TEMP%\_mei10602\tcl8\8.6\http-2.9.5.tm
- %TEMP%\_mei10602\tcl8\8.5\tcltest-2.5.3.tm
- %TEMP%\_mei10602\tcl8\8.5\msgcat-1.6.1.tm
- %TEMP%\_mei10602\tcl8\8.4\platform-1.0.18.tm
- %TEMP%\_mei10602\tcl8\8.4\platform\shell-1.1.4.tm
- %TEMP%\_mei10602\tcl\encoding\macjapan.enc
- %TEMP%\_mei10602\tcl\encoding\maciceland.enc
- %TEMP%\_mei10602\tcl\encoding\cp864.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-2.enc
- %TEMP%\_mei10602\tcl\encoding\maccyrillic.enc
- %TEMP%\_mei10602\tcl\encoding\maccroatian.enc
- %TEMP%\_mei10602\tcl\encoding\maccenteuro.enc
- %TEMP%\_mei10602\tcl\encoding\ksc5601.enc
- %TEMP%\_mei10602\tcl\encoding\koi8-u.enc
- %TEMP%\_mei10602\tcl\encoding\koi8-r.enc
- %TEMP%\_mei10602\tcl\encoding\jis0212.enc
- %TEMP%\_mei10602\tcl\encoding\jis0208.enc
- %TEMP%\_mei10602\tcl\encoding\jis0201.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-9.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-8.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-7.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-6.enc
- %TEMP%\_mei10602\tcl\encoding\macdingbats.enc
- %TEMP%\_mei10602\tcl\encoding\iso8859-5.enc
- %TEMP%\_mei10602\tcl\encoding\cp863.enc
- %TEMP%\_mei10602\tcl\encoding\cp862.enc
- %TEMP%\_mei10602\tcl\encoding\cp861.enc
- %TEMP%\u68u6bk7.cmdline
- %TEMP%\njyghkjm.0.vb
- %TEMP%\vbc5f9.tmp
- %TEMP%\res5fa.tmp
- %TEMP%\mbe3abjp.0.vb
- %TEMP%\mbe3abjp.out
- %TEMP%\mbe3abjp.cmdline
- %TEMP%\vbc167.tmp
- %TEMP%\res168.tmp
- %TEMP%\gdrfxiay.0.vb
- %TEMP%\gdrfxiay.cmdline
- %TEMP%\gdrfxiay.out
- %TEMP%\vbcfd03.tmp
- %TEMP%\_mei10602\_socket.pyd
- %TEMP%\njyghkjm.cmdline
- %TEMP%\u68u6bk7.out
- %TEMP%\u68u6bk7.0.vb
- %TEMP%\vbcf8a0.tmp
- %TEMP%\resf8a1.tmp
- %TEMP%\h2jnso2s.0.vb
- %TEMP%\h2jnso2s.out
- %TEMP%\h2jnso2s.cmdline
- %TEMP%\vbcf46c.tmp
- %TEMP%\resf47c.tmp
- %TEMP%\anm-ncs7.out
- %TEMP%\anm-ncs7.0.vb
- %TEMP%\anm-ncs7.cmdline
- %TEMP%\vbcef0f.tmp
- %TEMP%\resfd04.tmp
- %TEMP%\_mei10602\tcl\encoding\macgreek.enc
- %TEMP%\resba5.tmp
- %TEMP%\qu4azzkm.cmdline
- %TEMP%\vbcb94.tmp
- %TEMP%\_mei10602\tcl\encoding\cp860.enc
- %TEMP%\_mei10602\tcl\encoding\cp857.enc
- %TEMP%\_mei10602\tcl\encoding\cp855.enc
- %TEMP%\_mei10602\tcl\encoding\cp852.enc
- %TEMP%\_mei10602\tcl\encoding\cp850.enc
- %TEMP%\_mei10602\tcl\encoding\cp775.enc
- %TEMP%\_mei10602\tcl\encoding\cp737.enc
- %TEMP%\_mei10602\tcl\encoding\cp437.enc
- %TEMP%\_mei10602\tcl\encoding\cp1258.enc
- %TEMP%\_mei10602\tcl\encoding\cp1257.enc
- %TEMP%\_mei10602\tcl\encoding\cp1256.enc
- %TEMP%\_mei10602\tcl\encoding\cp1255.enc
- %TEMP%\qu4azzkm.out
- %TEMP%\_mei10602\tcl\encoding\cp1254.enc
- %TEMP%\njyghkjm.out
- %TEMP%\_mei10602\tcl\encoding\cp1251.enc
- %TEMP%\_mei10602\tcl\encoding\cp1250.enc
- %TEMP%\_mei10602\tcl\encoding\cns11643.enc
- %TEMP%\_mei10602\tcl\encoding\big5.enc
- %TEMP%\_mei10602\tcl\encoding\ascii.enc
- %TEMP%\_mei10602\tcl\clock.tcl
- %TEMP%\_mei10602\tcl\auto.tcl
- %TEMP%\_mei10602\select.pyd
- %TEMP%\_mei10602\python311.dll
- %TEMP%\_mei10602\libcrypto-1_1.dll
- %TEMP%\_mei10602\base_library.zip
- %TEMP%\qu4azzkm.0.vb
- %TEMP%\_mei10602\tcl\encoding\cp1253.enc
- %TEMP%\_mei10602\_tkinter.pyd
- '6.###.ngrok.io':11577
- DNS ASK 6.###.ngrok.io
- '%TEMP%\ixp000.tmp\svchost.exe'
- '%TEMP%\ixp000.tmp\mayaim~1.exe'
- '%TEMP%\ixp001.tmp\cheat.exe'
- '%TEMP%\ixp001.tmp\dmmeif~1.exe'
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\anm-ncs7.cmdline" (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESEF20.tmp" "%TEMP%\vbcEF0F.tmp" (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\h2jnso2s.cmdline" (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF47C.tmp" "%TEMP%\vbcF46C.tmp" (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\u68u6bk7.cmdline" (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESF8A1.tmp" "%TEMP%\vbcF8A0.tmp" (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\gdrfxiay.cmdline" (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESFD04.tmp" "%TEMP%\vbcFD03.tmp" (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\mbe3abjp.cmdline" (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES168.tmp" "%TEMP%\vbc167.tmp" (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\njyghkjm.cmdline" (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES5FA.tmp" "%TEMP%\vbc5F9.tmp" (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /noconfig @"%TEMP%\qu4azzkm.cmdline" (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESBA5.tmp" "%TEMP%\vbcB94.tmp" (со скрытым окном)
- '%WINDIR%\syswow64\rundll32.exe' <SYSTEM32>\shell32.dll,OpenAs_RunDLL %APPDATA%\System32