Техническая информация
- msedge.exe
- [HKCU\Software\Martin Prikryl\WinSCP 2\Sessions]
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\microsoft\movies\system information.txt
- %LOCALAPPDATA%\microsoft\movies\installed software.txt
- %APPDATA%\thunderbird\profiles\gbmwccb6.default-release\places.sqlite-shm
- %APPDATA%\thunderbird\profiles\gbmwccb6.default-release\cookies.sqlite-shm
- %LOCALAPPDATA%\microsoft\movies\gecko browsers\bookmarks.txt
- %LOCALAPPDATA%\microsoft\movies\retrieved map.txt
- %LOCALAPPDATA%\microsoft\m.zip
- %LOCALAPPDATA%\microsoft\movies\gecko browsers\bookmarks.txt
- %LOCALAPPDATA%\microsoft\movies\installed software.txt
- %LOCALAPPDATA%\microsoft\movies\retrieved map.txt
- %LOCALAPPDATA%\microsoft\movies\system information.txt
- %LOCALAPPDATA%\microsoft\m.zip
- '20#.#59.90.117':8080
- DNS ASK ap#.#pify.org
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Compress-Archive -Path "%LOCALAPPDATA%\Microsoft\Movies" -DestinationPath "%LOCALAPPDATA%\Microsoft\m.zip" (со скрытым окном)