Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run\] 'Microsoft Defender' = '"%ALLUSERSPROFILE%\userProcesso.exe"'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\] 'Microsoft Defender' = '"%ALLUSERSPROFILE%\userProcesso.exe"'
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook]
- [HKCU\Software\Microsoft\Internet Account Manager]
- [HKLM\Software\Microsoft\Windows Mail]
- [HKCU\Software\Microsoft\Windows Mail]
- %ALLUSERSPROFILE%\userprocesso.exe
- %LOCALAPPDATA%\microsoft\forms\frmdata64.dat
- %TEMP%\outlook logging\firstrun.log
- %WINDIR%\inf\outlook\outlperf.h
- %WINDIR%\inf\outlook\0009\outlperf.ini
- '20#.#8.64.225':82
- ClassName: 'mspim_wnd32' WindowName: 'Microsoft Outlook'
- ClassName: 'rencat' WindowName: ''
- '%ProgramFiles%\microsoft office\office14\outlook.exe' -Embedding