Техническая информация
- [HKCU\Software\Microsoft\Internet Account Manager]
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook]
- [HKLM\Software\Microsoft\Windows Mail]
- [HKCU\Software\Microsoft\Windows Mail]
- %TEMP%\8584.tmp\8585.tmp\875a.bat
- %LOCALAPPDATA%\microsoft\forms\frmdata64.dat
- %TEMP%\outlook logging\firstrun.log
- %WINDIR%\inf\outlook\outlperf.h
- %WINDIR%\inf\outlook\0009\outlperf.ini
- %TEMP%\8584.tmp\8585.tmp\875a.bat
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- '34.##9.100.209':443
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- ClassName: 'mspim_wnd32' WindowName: 'Microsoft Outlook'
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\8584.tmp\8585.tmp\875A.bat <Полный путь к файлу>" (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\outlook.exe' /safe /profile "Outlook"