Техническая информация
- <SYSTEM32>\tasks\createexplorershellunelevatedtask
- %WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe
- %WINDIR%\explorer.exe
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %TEMP%\content\1212-2992-<Имя файла>.exe-16-15-20-592.dump
- %TEMP%\tmp_pass
- %TEMP%\tmp_cookies
- %TEMP%\tmp_pass
- %TEMP%\tmp_cookies
- %TEMP%\tmp_pass
- %TEMP%\tmp_cookies
- %TEMP%\tmp_pass
- 'kn######died.gl.at.ply.gg':50473
- DNS ASK kn######died.gl.at.ply.gg
- ClassName: 'Progman' WindowName: ''
- ClassName: 'Proxy Desktop' WindowName: ''
- '%WINDIR%\explorer.exe'
- '%WINDIR%\microsoft.net\framework\v4.0.30319\cvtres.exe' Client know-studied.gl.at.ply.gg 50473 HLTysKKVp (со скрытым окном)
- '%WINDIR%\explorer.exe' /NoUACCheck