Техническая информация
- '<SYSTEM32>\conhost.exe' --type=renderer --disable-direct-npapi-requests --lang=en-US --disable-client-side-phishing-detection --with-feature:enhanced-autofill --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3792.3.271421116\1369334339" /prefetch:673131151
- '%WINDIR%\explorer.exe' /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
- '%WINDIR%\explorer.exe' /s , "http://www.he##123.net/"
- <APATH_ALLOC_DIR>\0314_01DC0000_21.ndmp
- <APATH_ALLOC_DIR>\0314_01E00000_22.ndmp
- <APATH_ALLOC_DIR>\0314_01BD0000_19.ndmp
- <APATH_ALLOC_DIR>\0314_01D70000_20.ndmp
- <APATH_ALLOC_DIR>\0314_020B0000_25.ndmp
- <APATH_ALLOC_DIR>\0314_021B0000_26.ndmp
- <APATH_ALLOC_DIR>\0314_01F70000_23.ndmp
- <APATH_ALLOC_DIR>\0314_01FB0000_24.ndmp
- <APATH_ALLOC_DIR>\0314_00410000_13.ndmp
- <APATH_ALLOC_DIR>\0314_004E0000_14.ndmp
- <APATH_ALLOC_DIR>\0314_00270000_11.ndmp
- <APATH_ALLOC_DIR>\0314_00370000_12.ndmp
- <APATH_ALLOC_DIR>\0314_01720000_17.ndmp
- <APATH_ALLOC_DIR>\0314_019F0000_18.ndmp
- <APATH_ALLOC_DIR>\0314_005F0000_15.ndmp
- <APATH_ALLOC_DIR>\0314_01250000_16.ndmp
- <APATH_ALLOC_DIR>\0314_7FFDD000_37.ndmp
- <APATH_ALLOC_DIR>\0314_7FFDE000_38.ndmp
- <APATH_ALLOC_DIR>\0314_7FFDB000_35.ndmp
- <APATH_ALLOC_DIR>\0314_7FFDC000_36.ndmp
- %TEMP%\etilqs_wAenr1HvZ9DH45z
- %TEMP%\etilqs_2pCOtfJ7tPuaRjT
- <APATH_ALLOC_DIR>\0314_7FFDF000_39.ndmp
- <APATH_ALLOC_DIR>\0314_7FFE0000_40.ndmp
- <APATH_ALLOC_DIR>\0314_77990000_29.ndmp
- <APATH_ALLOC_DIR>\0314_7F6F0000_30.ndmp
- <APATH_ALLOC_DIR>\0314_022B0000_27.ndmp
- <APATH_ALLOC_DIR>\0314_023B0000_28.ndmp
- <APATH_ALLOC_DIR>\0314_7FFD9000_33.ndmp
- <APATH_ALLOC_DIR>\0314_7FFDA000_34.ndmp
- <APATH_ALLOC_DIR>\0314_7FFB0000_31.ndmp
- <APATH_ALLOC_DIR>\0314_7FFD8000_32.ndmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1146.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\156C.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\F5E.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\104A.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\1DEA.tmp
- %APPDATA%\Roaming\Microsoft\Windows\Recent\CustomDestinations\UXH8LWMFON5PQUO0MHL2.temp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\18A9.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1A31.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\MANIFEST-000002
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\000002.dbtmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\MANIFEST-000001
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\000001.dbtmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\History Provider Cache
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\DB7.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\LOG
- %TEMP%\etilqs_dztUFj8drIUVwh5
- <APATH_ALLOC_DIR>\0314_00150000_5.ndmp
- <APATH_ALLOC_DIR>\0314_001C0000_6.ndmp
- <APATH_ALLOC_DIR>\0314_00130000_3.ndmp
- <APATH_ALLOC_DIR>\0314_00140000_4.ndmp
- <APATH_ALLOC_DIR>\0314_00250000_9.ndmp
- <APATH_ALLOC_DIR>\0314_00260000_10.ndmp
- <APATH_ALLOC_DIR>\0314_001D0000_7.ndmp
- <APATH_ALLOC_DIR>\0314_00210000_8.ndmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\MANIFEST-000002
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\000002.dbtmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\MANIFEST-000001
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\000001.dbtmp
- <APATH_ALLOC_DIR>\0314_00020000_1.ndmp
- <APATH_ALLOC_DIR>\0314_00030000_2.ndmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\LOG
- <APATH_ALLOC_DIR>\0314_00010000_0.ndmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\184B.tmp~RFc1988.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1472.tmp~RFc16f9.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1A21.tmp~RFc1aef.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\MANIFEST-000001
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\CURRENT~RFc1ffe.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1116.tmp~RFc118d.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\MANIFEST-000001
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\CURRENT~RFbf7f5.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\D0A.tmp~RFc0ecf.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1049.tmp~RFc1064.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\F4D.tmp~RFc0fc8.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\184B.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\184B.tmp~RFc1988.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1A31.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1A21.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\18A9.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\184B.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\156C.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1472.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1472.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1472.tmp~RFc16f9.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1A21.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1A21.tmp~RFc1aef.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\000002.dbtmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\CURRENT
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\CURRENT в %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\CURRENT~RFc1ffe.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\000001.dbtmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Extension State\CURRENT
- %APPDATA%\Roaming\Opera Software\Opera Stable\1DEA.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Preferences
- %APPDATA%\Roaming\Microsoft\Windows\Recent\CustomDestinations\UXH8LWMFON5PQUO0MHL2.temp в %APPDATA%\Roaming\Microsoft\Windows\Recent\CustomDestinations\8548f632abe97aa3.customDestinations-ms
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\DB7.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\D0A.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\D0A.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\D0A.tmp~RFc0ecf.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\CURRENT в %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\CURRENT~RFbf7f5.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\000001.dbtmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\CURRENT
- %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\000002.dbtmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Extension Rules\CURRENT
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\F5E.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\F4D.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1146.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1116.tmp
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1116.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1116.tmp~RFc118d.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1049.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1049.tmp~RFc1064.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\F4D.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\F4D.tmp~RFc0fc8.TMP
- %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\104A.tmp в %APPDATA%\Roaming\Opera Software\Opera Stable\Jump List Icons\1049.tmp
- DNS ASK bi##.#ikimedia.org
- DNS ASK ap#.###sys.opera.com
- DNS ASK dn#.##ftncsi.com
- DNS ASK sl####i.yandex.ru
- DNS ASK au######te.geo.opera.com
- DNS ASK en.###ipedia.org
- DNS ASK re###.opera.com
- DNS ASK k.###inming.com
- DNS ASK www.ic#.com
- DNS ASK www.google.com
- DNS ASK k.####uogeng.com
- DNS ASK www.he##123.net
- DNS ASK i.##0.ru
- DNS ASK www.go##le.ru
- DNS ASK si#####ck2.opera.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Opera_MessageWindow' WindowName: '%APPDATA%\Roaming\Opera Software\Opera Stable'