Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\nonplacental.vbs
- %WINDIR%\syswow64\svchost.exe
- [HKCU\Software\FTPWare\COREFTP\Sites\]
- [HKCU\Software\Martin Prikryl\WinSCP 2\Sessions\]
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %APPDATA%\opera software\opera stable\login data
- %TEMP%\aut3190.tmp
- %TEMP%\savager
- %LOCALAPPDATA%\uncolonizing\nonplacental.exe
- %TEMP%\aut42e5.tmp
- %APPDATA%\microsoft\windows\templates\dbs\logindata
- %APPDATA%\microsoft\windows\templates\dbs\webdata
- %APPDATA%\microsoft\windows\templates\dbs\global-messages
- %TEMP%\outlook logging\firstrun.log
- %WINDIR%\inf\outlook\outlperf.h
- %WINDIR%\inf\outlook\outlperf.ini
- %WINDIR%\syswow64\perfstringbackup.tmp
- %WINDIR%\syswow64\perfstringbackup.ini
- 'sh##ip.net':80
- http://sh##ip.net/
- DNS ASK sh##ip.net
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- ClassName: 'mspim_wnd32' WindowName: 'Microsoft Outlook'
- '%LOCALAPPDATA%\uncolonizing\nonplacental.exe'
- '%WINDIR%\syswow64\svchost.exe'
- '%ProgramFiles(x86)%\microsoft office\office16\outlook.exe' -Embedding