Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'SystemUpdate' = '%TEMP%\8379.tmp\8389.tmp\838A.vbs'
- %TEMP%\8379.tmp\8389.tmp\838a.vbs
- %TEMP%\outlook logging\firstrun.log
- %WINDIR%\inf\outlook\outlperf.h
- %WINDIR%\inf\outlook\outlperf.ini
- %WINDIR%\syswow64\perfstringbackup.tmp
- %WINDIR%\syswow64\perfstringbackup.ini
- %WINDIR%\syswow64\perfstringbackup.tmp
- DNS ASK ne###.##ficeapps.live.com
- ClassName: 'mspim_wnd32' WindowName: 'Microsoft Outlook'
- '<SYSTEM32>\wscript.exe' %TEMP%\8379.tmp\8389.tmp\838A.vbs //Nologo
- '%ProgramFiles(x86)%\microsoft office\office16\outlook.exe' -Embedding
- '<SYSTEM32>\wscript.exe' %TEMP%\8379.tmp\8389.tmp\838A.vbs //Nologo (со скрытым окном)