Техническая информация
- <SYSTEM32>\tasks\windowsupdatesync
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %HOMEPATH%\desktop\applicantform_en.doc
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %HOMEPATH%\desktop\coffee.bmp
- %APPDATA%\opera software\opera stable\login data
- %HOMEPATH%\desktop\dashborder_96.bmp
- %HOMEPATH%\desktop\issi2013_template_for_posters.docx
- %HOMEPATH%\desktop\nwfieldnotes1966.docx
- %HOMEPATH%\desktop\sdszfo.docx
- %HOMEPATH%\desktop\uep_form_786_bulletin_1726i602.doc
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %TEMP%\c7f3cd8c8595dacf.tmp\extras\autofill\chrome-webdata.sqlite
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\backup.log
- %TEMP%\c7f3cd8c8595dacf.tmp\extras\autofill\edge-webdata.sqlite
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\applicantform_en.doc.part
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\backup.log
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\backup.log
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\backup.log
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\backup.log
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\addons.json.part
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\login data.part
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\cookies.part
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\local state.part
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\coffee.bmp.part
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\cert9.db.part
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\login data.part
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\dashborder_96.bmp.part
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\cookies.sqlite.part
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\preferences.part
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\issi2013_template_for_posters.docx.part
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\nwfieldnotes1966.docx.part
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\preferences.part
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\secure preferences.part
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\extensions.json.part
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\sdszfo.docx.part
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\manifest.json.part
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\formhistory.sqlite.part
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\local state.part
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\uep_form_786_bulletin_1726i602.doc.part
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\bookmarks.html
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\extensions.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\key4.db.part
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\manifest.json.part
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\places.sqlite.part
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\manifest.json.part
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\bookmarks.html
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\extensions.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\history.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\chrome-summary.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\chrome-passwords.csv
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\history.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\chrome-summary.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\chrome-passwords.csv
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\chrome-passwords.csv
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\login data.part
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\preferences.part
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\prefs.js.part
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\secure preferences.part
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\local state.part
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\manifest.json.part
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\manifest.json.part
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\bookmarks.html
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\extensions.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\history.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\chrome-summary.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\firefox-passwords.csv
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\chrome-passwords.csv
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\firefox-passwords.csv
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\chrome-summary.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\chrome-passwords.csv
- %TEMP%\c7f3cd8c8595dacf.tmp\browser-passwords.csv
- %TEMP%\c7f3cd8c8595dacf.tmp\passwords.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\sysinfo.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\extras\installed-software.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\extras\email\thunderbird\gbmwccb6.default-release\key4.db
- %TEMP%\c7f3cd8c8595dacf.tmp\extras\email\thunderbird\gbmwccb6.default-release\cert9.db
- %TEMP%\c7f3cd8c8595dacf.tmp\extras\screenshot.png
- %TEMP%\c7f3cd8c8595dacf.tmp\extras\browser-tabs\chrome\current session
- %TEMP%\c7f3cd8c8595dacf.tmp\extras\browser-tabs\opera\current session
- %TEMP%\c7f3cd8c8595dacf.tmp\session.txt
- %TEMP%\backup-standalone\backup-20260618-160355_stlxbhdekvue.zip
- %TEMP%\.wup\backup-20260618-160355_stlxbhdekvue.zip.enc
- %TEMP%\.backup-pending-upload
- nul
- %TEMP%\.wup\backup-20260618-160355_stlxbhdekvue.zip.enc
- %TEMP%\c7f3cd8c8595dacf.tmp\browser-passwords.csv
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\login data
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\preferences
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\secure preferences
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\bookmarks.html
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\chrome-passwords.csv
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\extensions.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\history.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\backup.log
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\chrome-passwords.csv
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\chrome-summary.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\manifest.json
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\backup.log
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\manifest.json
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\login data
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\preferences
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\secure preferences
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\bookmarks.html
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\chrome-passwords.csv
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\extensions.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\history.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\backup.log
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\chrome-passwords.csv
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\chrome-summary.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\manifest.json
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\backup.log
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\chrome-summary.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\manifest.json
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\login data
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\preferences
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\backup.log
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\bookmarks.html
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\chrome-passwords.csv
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\chrome-summary.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\extensions.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\history.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\manifest.json
- %TEMP%\.wup\backup-20260618-160355_stlxbhdekvue.zip.enc
- %TEMP%\.backup-pending-upload
- <SYSTEM32>\tasks\windowsupdatesync
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\cookies
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\local state
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\applicantform_en.doc
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\coffee.bmp
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\dashborder_96.bmp
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\issi2013_template_for_posters.docx
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\nwfieldnotes1966.docx
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\sdszfo.docx
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\uep_form_786_bulletin_1726i602.doc
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\local state
- %TEMP%\c7f3cd8c8595dacf.tmp\extras\autofill\chrome-webdata.sqlite
- %TEMP%\c7f3cd8c8595dacf.tmp\extras\autofill\edge-webdata.sqlite
- %TEMP%\c7f3cd8c8595dacf.tmp\extras\browser-tabs\chrome\current session
- %TEMP%\c7f3cd8c8595dacf.tmp\extras\browser-tabs\opera\current session
- %TEMP%\c7f3cd8c8595dacf.tmp\extras\email\thunderbird\gbmwccb6.default-release\cert9.db
- %TEMP%\c7f3cd8c8595dacf.tmp\extras\email\thunderbird\gbmwccb6.default-release\key4.db
- %TEMP%\c7f3cd8c8595dacf.tmp\extras\installed-software.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\extras\screenshot.png
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\addons.json
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\cert9.db
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\cookies.sqlite
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\extensions.json
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\firefox-passwords.csv
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\formhistory.sqlite
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\key4.db
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\places.sqlite
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\prefs.js
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\firefox-passwords.csv
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\local state
- %TEMP%\c7f3cd8c8595dacf.tmp\passwords.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\session.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\sysinfo.txt
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\applicantform_en.doc.part в %TEMP%\c7f3cd8c8595dacf.tmp\desktop\applicantform_en.doc
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\addons.json.part в %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\addons.json
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\local state.part в %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\local state
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\coffee.bmp.part в %TEMP%\c7f3cd8c8595dacf.tmp\desktop\coffee.bmp
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\cookies.part в %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\cookies
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\login data.part в %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\login data
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\cert9.db.part в %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\cert9.db
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\login data.part в %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\login data
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\dashborder_96.bmp.part в %TEMP%\c7f3cd8c8595dacf.tmp\desktop\dashborder_96.bmp
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\preferences.part в %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\preferences
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\cookies.sqlite.part в %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\cookies.sqlite
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\issi2013_template_for_posters.docx.part в %TEMP%\c7f3cd8c8595dacf.tmp\desktop\issi2013_template_for_posters.docx
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\preferences.part в %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\preferences
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\nwfieldnotes1966.docx.part в %TEMP%\c7f3cd8c8595dacf.tmp\desktop\nwfieldnotes1966.docx
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\secure preferences.part в %TEMP%\c7f3cd8c8595dacf.tmp\edge\default\secure preferences
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\extensions.json.part в %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\extensions.json
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\sdszfo.docx.part в %TEMP%\c7f3cd8c8595dacf.tmp\desktop\sdszfo.docx
- %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\manifest.json.part в %TEMP%\c7f3cd8c8595dacf.tmp\opera-stable\manifest.json
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\local state.part в %TEMP%\c7f3cd8c8595dacf.tmp\edge\local state
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\formhistory.sqlite.part в %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\formhistory.sqlite
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\uep_form_786_bulletin_1726i602.doc.part в %TEMP%\c7f3cd8c8595dacf.tmp\desktop\uep_form_786_bulletin_1726i602.doc
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\key4.db.part в %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\key4.db
- %TEMP%\c7f3cd8c8595dacf.tmp\edge\manifest.json.part в %TEMP%\c7f3cd8c8595dacf.tmp\edge\manifest.json
- %TEMP%\c7f3cd8c8595dacf.tmp\desktop\manifest.json.part в %TEMP%\c7f3cd8c8595dacf.tmp\desktop\manifest.json
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\places.sqlite.part в %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\places.sqlite
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\login data.part в %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\login data
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\preferences.part в %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\preferences
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\prefs.js.part в %TEMP%\c7f3cd8c8595dacf.tmp\firefox\dnyauhh1.default-release\prefs.js
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\secure preferences.part в %TEMP%\c7f3cd8c8595dacf.tmp\chrome\default\secure preferences
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\local state.part в %TEMP%\c7f3cd8c8595dacf.tmp\chrome\local state
- %TEMP%\c7f3cd8c8595dacf.tmp\chrome\manifest.json.part в %TEMP%\c7f3cd8c8595dacf.tmp\chrome\manifest.json
- %TEMP%\c7f3cd8c8595dacf.tmp\firefox\manifest.json.part в %TEMP%\c7f3cd8c8595dacf.tmp\firefox\manifest.json
- 'ip##pi.com':80
- '10#.#9.91.194':9091
- 'sc#############l-reviews-frankfurt.trycloudflare.com':443
- http://ip##pi.com/json/
- http://10#.##.91.194:9091/api/tunnel-url via 10#.#9.91.194
- '<DNS_SERVER>':53
- 'sc#############l-reviews-frankfurt.trycloudflare.com':443
- DNS ASK ip##pi.com
- DNS ASK sc#############l-reviews-frankfurt.trycloudflare.com
- '<SYSTEM32>\reg.exe' query HKCU\Software\SimonTatham\PuTTY\Sessions
- '<SYSTEM32>\reg.exe' query "HKCU\Software\Microsoft\Terminal Server Client\Servers"
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall /s /v DisplayName
- '<SYSTEM32>\reg.exe' query HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall /s /v DisplayName
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall /s /v DisplayName
- '<SYSTEM32>\reg.exe' query HKCU\Software\Microsoft\Office\16.0\Outlook\Search /s
- '<SYSTEM32>\reg.exe' query HKCU\Software\Microsoft\Office\15.0\Outlook\Search /s
- '<SYSTEM32>\reg.exe' query HKCU\Software\HeidiSQL\Servers /s
- '<SYSTEM32>\reg.exe' query HKCU\Software\SplitmediaLabs\XSplit /s
- '<SYSTEM32>\schtasks.exe' /delete /tn WindowsUpdateSync /f
- '<SYSTEM32>\schtasks.exe' /create /tn WindowsUpdateSync /tr \"<Полный путь к файлу>\" /sc ONLOGON /rl HIGHEST /f