Техническая информация
- %WINDIR%\syswow64\resmon.exe
- %WINDIR%\syswow64\fondue.exe
- %WINDIR%\syswow64\makecab.exe
- %WINDIR%\syswow64\fontview.exe
- %WINDIR%\syswow64\openwith.exe
- %WINDIR%\syswow64\fc.exe
- %WINDIR%\syswow64\resmon.exe
- %WINDIR%\syswow64\fondue.exe
- %WINDIR%\syswow64\makecab.exe
- %WINDIR%\syswow64\fontview.exe
- %WINDIR%\syswow64\openwith.exe
- <Текущая директория>\lol»»·ôöúêörxelyjmn.exe
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- %LOCALAPPDATA%\microsoft\windows\history\desktop.ini
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\low\smartscreencache.dat
- %LOCALAPPDATA%\packages\windows_ie_ac_001\ac\<INETFILES>\msimgsiz.dat
- %LOCALAPPDATA%\packages\windows_ie_ac_001\ac\inethistory\desktop.ini
- %LOCALAPPDATA%\packages\windows_ie_ac_001\ac\<INETFILES>\smartscreencache.dat
- %WINDIR%\servicestate\winhttpautoproxysvc\data\cachev3.dat
- %LOCALAPPDATA%\microsoft\vault\userprofileroaming\latest.dat
- 'sh##o.im':443
- 'sh##o.im':443
- DNS ASK sh##o.im
- '%WINDIR%\syswow64\fc.exe'
- '%WINDIR%\syswow64\rundll32.exe' InetCpl.cpl,ClearMyTracksByProcess 255 (со скрытым окном)
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' -ResetDestinationList
- '%WINDIR%\syswow64\rundll32.exe' <SYSTEM32>\inetcpl.cpl,ClearMyTracksByProcess Flags:255 WinX:0 WinY:0 IEFrame:00000000