Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'svhost' = '%WINDIR%\svchost.exe'
- '%TEMP%\EnvoyRus_1722.exe'
- '%WINDIR%\svchost.exe'
- %TEMP%\nsx51.tmp\NSISpcre.dll
- %TEMP%\nsx51.tmp\System.dll
- %TEMP%\nss50.tmp
- %TEMP%\nsm53.tmp
- %TEMP%\nsx51.tmp\inetcn.dll
- %TEMP%\nsx51.tmp\modern-header.bmp
- %TEMP%\nsz4E.tmp\System.dll
- %TEMP%\nsj4D.tmp
- %TEMP%\nsa4B.tmp\inetcn.dll
- %TEMP%\nsz4E.tmp\inetcn.dll
- %TEMP%\nsz4E.tmp\modern-header.bmp
- %TEMP%\nsz4E.tmp\NSISpcre.dll
- %TEMP%\nsb57.tmp\inetcn.dll
- %TEMP%\nsb57.tmp\modern-header.bmp
- %TEMP%\nsb57.tmp\NSISpcre.dll
- %TEMP%\nsu5A.tmp\NSISpcre.dll
- %TEMP%\nsu5A.tmp\System.dll
- %TEMP%\nse59.tmp
- %TEMP%\nsr54.tmp\modern-header.bmp
- %TEMP%\nsr54.tmp\NSISpcre.dll
- %TEMP%\nsr54.tmp\System.dll
- %TEMP%\nsb57.tmp\System.dll
- %TEMP%\nsl56.tmp
- %TEMP%\nsr54.tmp\inetcn.dll
- %TEMP%\nsa4B.tmp\modern-header.bmp
- %TEMP%\nsz42.tmp\NSISpcre.dll
- %TEMP%\nsz42.tmp\System.dll
- %TEMP%\nsu41.tmp
- %TEMP%\nsx44.tmp
- %TEMP%\nsz42.tmp\inetcn.dll
- %TEMP%\nsz42.tmp\modern-header.bmp
- %TEMP%\nsq3F.tmp\System.dll
- %TEMP%\nsl3E.tmp
- %TEMP%\nsq3C.tmp\inetcn.dll
- %TEMP%\nsq3F.tmp\inetcn.dll
- %TEMP%\nsq3F.tmp\modern-header.bmp
- %TEMP%\nsq3F.tmp\NSISpcre.dll
- %TEMP%\nsb48.tmp\inetcn.dll
- %TEMP%\nsb48.tmp\modern-header.bmp
- %TEMP%\nsb48.tmp\NSISpcre.dll
- %TEMP%\nsa4B.tmp\NSISpcre.dll
- %TEMP%\nsa4B.tmp\System.dll
- %TEMP%\nsk4A.tmp
- %TEMP%\nsd45.tmp\modern-header.bmp
- %TEMP%\nsd45.tmp\NSISpcre.dll
- %TEMP%\nsd45.tmp\System.dll
- %TEMP%\nsb48.tmp\System.dll
- %TEMP%\nsw47.tmp
- %TEMP%\nsd45.tmp\inetcn.dll
- %TEMP%\nsu5A.tmp\modern-header.bmp
- %TEMP%\nsa72.tmp\System.dll
- %TEMP%\nsv71.tmp
- %TEMP%\nsc6F.tmp\inetcn.dll
- %TEMP%\nsa72.tmp\inetcn.dll
- %TEMP%\nsa72.tmp\modern-header.bmp
- %TEMP%\nsa72.tmp\NSISpcre.dll
- %TEMP%\nsw6E.tmp
- %TEMP%\nsi6C.tmp\inetcn.dll
- %TEMP%\nsi6C.tmp\modern-header.bmp
- %TEMP%\nsc6F.tmp\modern-header.bmp
- %TEMP%\nsc6F.tmp\NSISpcre.dll
- %TEMP%\nsc6F.tmp\System.dll
- %TEMP%\nse78.tmp\modern-header.bmp
- %TEMP%\nse78.tmp\NSISpcre.dll
- %TEMP%\nse78.tmp\System.dll
- %TEMP%\nsn7B.tmp\System.dll
- %TEMP%\nsi7A.tmp
- %TEMP%\nse78.tmp\inetcn.dll
- %TEMP%\nsf75.tmp\NSISpcre.dll
- %TEMP%\nsf75.tmp\System.dll
- %TEMP%\nsz74.tmp
- %TEMP%\nsz77.tmp
- %TEMP%\nsf75.tmp\inetcn.dll
- %TEMP%\nsf75.tmp\modern-header.bmp
- %TEMP%\nsi6C.tmp\NSISpcre.dll
- %TEMP%\nsh60.tmp\NSISpcre.dll
- %TEMP%\nsh60.tmp\System.dll
- %TEMP%\nsc5F.tmp
- %TEMP%\nsx62.tmp
- %TEMP%\nsh60.tmp\inetcn.dll
- %TEMP%\nsh60.tmp\modern-header.bmp
- %TEMP%\nso5D.tmp\System.dll
- %TEMP%\nsi5C.tmp
- %TEMP%\nsu5A.tmp\inetcn.dll
- %TEMP%\nso5D.tmp\inetcn.dll
- %TEMP%\nso5D.tmp\modern-header.bmp
- %TEMP%\nso5D.tmp\NSISpcre.dll
- %TEMP%\nsv66.tmp\inetcn.dll
- %TEMP%\nsv66.tmp\modern-header.bmp
- %TEMP%\nsv66.tmp\NSISpcre.dll
- %TEMP%\nsi6C.tmp\System.dll
- %TEMP%\nss6B.tmp
- %TEMP%\nse68.tmp
- %TEMP%\nsm63.tmp\modern-header.bmp
- %TEMP%\nsm63.tmp\NSISpcre.dll
- %TEMP%\nsm63.tmp\System.dll
- %TEMP%\nsv66.tmp\System.dll
- %TEMP%\nsq65.tmp
- %TEMP%\nsm63.tmp\inetcn.dll
- %TEMP%\nsq3C.tmp\modern-header.bmp
- %TEMP%\nsh12.tmp\modern-header.bmp
- %TEMP%\nsh12.tmp\NSISpcre.dll
- %TEMP%\nsh12.tmp\System.dll
- %TEMP%\nsb15.tmp\System.dll
- %TEMP%\nsr14.tmp
- %TEMP%\nsh12.tmp\inetcn.dll
- %TEMP%\nsiF.tmp\NSISpcre.dll
- %TEMP%\nsiF.tmp\System.dll
- %TEMP%\nsxE.tmp
- %TEMP%\nsg11.tmp
- %TEMP%\nsiF.tmp\inetcn.dll
- %TEMP%\nsiF.tmp\modern-header.bmp
- %TEMP%\nsv1A.tmp
- %TEMP%\nsg18.tmp\inetcn.dll
- %TEMP%\nsg18.tmp\modern-header.bmp
- %TEMP%\nsa1B.tmp\modern-header.bmp
- %TEMP%\nsa1B.tmp\NSISpcre.dll
- %TEMP%\nsa1B.tmp\System.dll
- %TEMP%\nsb15.tmp\inetcn.dll
- %TEMP%\nsb15.tmp\modern-header.bmp
- %TEMP%\nsb15.tmp\NSISpcre.dll
- %TEMP%\nsg18.tmp\NSISpcre.dll
- %TEMP%\nsg18.tmp\System.dll
- %TEMP%\nsl17.tmp
- %TEMP%\nseC.tmp\inetcn.dll
- %TEMP%\nss3.tmp\modern-header.bmp
- %TEMP%\nss3.tmp\NSISpcre.dll
- %TEMP%\nss3.tmp\System.dll
- %TEMP%\nsc6.tmp\System.dll
- %TEMP%\nsr5.tmp
- %TEMP%\nss3.tmp\inetcn.dll
- %TEMP%\EnvoyRus_1722.exe
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- %TEMP%\nss2.tmp
- %WINDIR%\srt.ini
- %WINDIR%\svchost.exe
- %TEMP%\nstB.tmp
- %TEMP%\nsg9.tmp\inetcn.dll
- %TEMP%\nsg9.tmp\modern-header.bmp
- %TEMP%\nseC.tmp\modern-header.bmp
- %TEMP%\nseC.tmp\NSISpcre.dll
- %TEMP%\nseC.tmp\System.dll
- %TEMP%\nsc6.tmp\inetcn.dll
- %TEMP%\nsc6.tmp\modern-header.bmp
- %TEMP%\nsc6.tmp\NSISpcre.dll
- %TEMP%\nsg9.tmp\NSISpcre.dll
- %TEMP%\nsg9.tmp\System.dll
- %TEMP%\nsq8.tmp
- %TEMP%\nsa1B.tmp\inetcn.dll
- %TEMP%\nsm30.tmp\modern-header.bmp
- %TEMP%\nsm30.tmp\NSISpcre.dll
- %TEMP%\nsm30.tmp\System.dll
- %TEMP%\nsg33.tmp\System.dll
- %TEMP%\nsq32.tmp
- %TEMP%\nsm30.tmp\inetcn.dll
- %TEMP%\nst2D.tmp\NSISpcre.dll
- %TEMP%\nst2D.tmp\System.dll
- %TEMP%\nso2C.tmp
- %TEMP%\nsx2F.tmp
- %TEMP%\nst2D.tmp\inetcn.dll
- %TEMP%\nst2D.tmp\modern-header.bmp
- %TEMP%\nsx39.tmp\inetcn.dll
- %TEMP%\nsx39.tmp\modern-header.bmp
- %TEMP%\nsx39.tmp\NSISpcre.dll
- %TEMP%\nsq3C.tmp\NSISpcre.dll
- %TEMP%\nsq3C.tmp\System.dll
- %TEMP%\nsb3B.tmp
- %TEMP%\nsg33.tmp\inetcn.dll
- %TEMP%\nsg33.tmp\modern-header.bmp
- %TEMP%\nsg33.tmp\NSISpcre.dll
- %TEMP%\nsx39.tmp\System.dll
- %TEMP%\nss38.tmp
- %TEMP%\nse35.tmp
- %TEMP%\nsj2A.tmp\inetcn.dll
- %TEMP%\nsc21.tmp\modern-header.bmp
- %TEMP%\nsc21.tmp\NSISpcre.dll
- %TEMP%\nsc21.tmp\System.dll
- %TEMP%\nsg24.tmp\System.dll
- %TEMP%\nsb23.tmp
- %TEMP%\nsc21.tmp\inetcn.dll
- %TEMP%\nsy1E.tmp\NSISpcre.dll
- %TEMP%\nsy1E.tmp\System.dll
- %TEMP%\nst1D.tmp
- %TEMP%\nsx20.tmp
- %TEMP%\nsy1E.tmp\inetcn.dll
- %TEMP%\nsy1E.tmp\modern-header.bmp
- %TEMP%\nse29.tmp
- %TEMP%\nsf27.tmp\inetcn.dll
- %TEMP%\nsf27.tmp\modern-header.bmp
- %TEMP%\nsj2A.tmp\modern-header.bmp
- %TEMP%\nsj2A.tmp\NSISpcre.dll
- %TEMP%\nsj2A.tmp\System.dll
- %TEMP%\nsg24.tmp\inetcn.dll
- %TEMP%\nsg24.tmp\modern-header.bmp
- %TEMP%\nsg24.tmp\NSISpcre.dll
- %TEMP%\nsf27.tmp\NSISpcre.dll
- %TEMP%\nsf27.tmp\System.dll
- %TEMP%\nsp26.tmp
- %TEMP%\nsx51.tmp\inetcn.dll
- %TEMP%\nsz4E.tmp\System.dll
- %TEMP%\nsx51.tmp\NSISpcre.dll
- %TEMP%\nsx51.tmp\modern-header.bmp
- %TEMP%\nsz4E.tmp\NSISpcre.dll
- %TEMP%\nsa4B.tmp\System.dll
- %TEMP%\nsa4B.tmp\NSISpcre.dll
- %TEMP%\nsz4E.tmp\modern-header.bmp
- %TEMP%\nsz4E.tmp\inetcn.dll
- %TEMP%\nsx51.tmp\System.dll
- %TEMP%\nsb57.tmp\NSISpcre.dll
- %TEMP%\nsb57.tmp\modern-header.bmp
- %TEMP%\nsu5A.tmp\inetcn.dll
- %TEMP%\nsb57.tmp\System.dll
- %TEMP%\nsb57.tmp\inetcn.dll
- %TEMP%\nsr54.tmp\modern-header.bmp
- %TEMP%\nsr54.tmp\inetcn.dll
- %TEMP%\nsr54.tmp\System.dll
- %TEMP%\nsr54.tmp\NSISpcre.dll
- %TEMP%\nsz42.tmp\modern-header.bmp
- %TEMP%\nsz42.tmp\inetcn.dll
- %TEMP%\nsz42.tmp\System.dll
- %TEMP%\nsz42.tmp\NSISpcre.dll
- %TEMP%\nsq3F.tmp\System.dll
- %TEMP%\nsq3F.tmp\inetcn.dll
- %TEMP%\nsq3C.tmp\System.dll
- %TEMP%\nsq3F.tmp\NSISpcre.dll
- %TEMP%\nsq3F.tmp\modern-header.bmp
- %TEMP%\nsd45.tmp\inetcn.dll
- %TEMP%\nsb48.tmp\System.dll
- %TEMP%\nsb48.tmp\NSISpcre.dll
- %TEMP%\nsa4B.tmp\modern-header.bmp
- %TEMP%\nsa4B.tmp\inetcn.dll
- %TEMP%\nsb48.tmp\modern-header.bmp
- %TEMP%\nsd45.tmp\NSISpcre.dll
- %TEMP%\nsd45.tmp\modern-header.bmp
- %TEMP%\nsb48.tmp\inetcn.dll
- %TEMP%\nsd45.tmp\System.dll
- %TEMP%\nsu5A.tmp\modern-header.bmp
- %TEMP%\nsc6F.tmp\System.dll
- %TEMP%\nsc6F.tmp\NSISpcre.dll
- %TEMP%\nsa72.tmp\modern-header.bmp
- %TEMP%\nsa72.tmp\inetcn.dll
- %TEMP%\nsc6F.tmp\modern-header.bmp
- %TEMP%\nsi6C.tmp\NSISpcre.dll
- %TEMP%\nsi6C.tmp\modern-header.bmp
- %TEMP%\nsc6F.tmp\inetcn.dll
- %TEMP%\nsi6C.tmp\System.dll
- %TEMP%\nsa72.tmp\NSISpcre.dll
- %TEMP%\nse78.tmp\modern-header.bmp
- %TEMP%\nse78.tmp\inetcn.dll
- %TEMP%\nse78.tmp\System.dll
- %TEMP%\nse78.tmp\NSISpcre.dll
- %TEMP%\nsf75.tmp\System.dll
- %TEMP%\nsf75.tmp\inetcn.dll
- %TEMP%\nsa72.tmp\System.dll
- %TEMP%\nsf75.tmp\NSISpcre.dll
- %TEMP%\nsf75.tmp\modern-header.bmp
- %TEMP%\nsh60.tmp\inetcn.dll
- %TEMP%\nso5D.tmp\System.dll
- %TEMP%\nsh60.tmp\NSISpcre.dll
- %TEMP%\nsh60.tmp\modern-header.bmp
- %TEMP%\nso5D.tmp\NSISpcre.dll
- %TEMP%\nsu5A.tmp\System.dll
- %TEMP%\nsu5A.tmp\NSISpcre.dll
- %TEMP%\nso5D.tmp\modern-header.bmp
- %TEMP%\nso5D.tmp\inetcn.dll
- %TEMP%\nsh60.tmp\System.dll
- %TEMP%\nsv66.tmp\NSISpcre.dll
- %TEMP%\nsv66.tmp\modern-header.bmp
- %TEMP%\nsi6C.tmp\inetcn.dll
- %TEMP%\nsv66.tmp\System.dll
- %TEMP%\nsv66.tmp\inetcn.dll
- %TEMP%\nsm63.tmp\modern-header.bmp
- %TEMP%\nsm63.tmp\inetcn.dll
- %TEMP%\nsm63.tmp\System.dll
- %TEMP%\nsm63.tmp\NSISpcre.dll
- %TEMP%\nsh12.tmp\System.dll
- %TEMP%\nsh12.tmp\NSISpcre.dll
- %TEMP%\nsb15.tmp\modern-header.bmp
- %TEMP%\nsb15.tmp\inetcn.dll
- %TEMP%\nsh12.tmp\modern-header.bmp
- %TEMP%\nsiF.tmp\NSISpcre.dll
- %TEMP%\nsiF.tmp\modern-header.bmp
- %TEMP%\nsh12.tmp\inetcn.dll
- %TEMP%\nsiF.tmp\System.dll
- %TEMP%\nsb15.tmp\NSISpcre.dll
- %TEMP%\nsa1B.tmp\modern-header.bmp
- %TEMP%\nsa1B.tmp\inetcn.dll
- %TEMP%\nsa1B.tmp\System.dll
- %TEMP%\nsa1B.tmp\NSISpcre.dll
- %TEMP%\nsg18.tmp\System.dll
- %TEMP%\nsg18.tmp\inetcn.dll
- %TEMP%\nsb15.tmp\System.dll
- %TEMP%\nsg18.tmp\NSISpcre.dll
- %TEMP%\nsg18.tmp\modern-header.bmp
- %TEMP%\nsc6.tmp\inetcn.dll
- %TEMP%\nss3.tmp\System.dll
- %TEMP%\nsc6.tmp\NSISpcre.dll
- %TEMP%\nsc6.tmp\modern-header.bmp
- %TEMP%\nss3.tmp\NSISpcre.dll
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\nss3.tmp\modern-header.bmp
- %TEMP%\nss3.tmp\inetcn.dll
- %TEMP%\nsc6.tmp\System.dll
- %TEMP%\nseC.tmp\NSISpcre.dll
- %TEMP%\nseC.tmp\modern-header.bmp
- %TEMP%\nsiF.tmp\inetcn.dll
- %TEMP%\nseC.tmp\System.dll
- %TEMP%\nseC.tmp\inetcn.dll
- %TEMP%\nsg9.tmp\modern-header.bmp
- %TEMP%\nsg9.tmp\inetcn.dll
- %TEMP%\nsg9.tmp\System.dll
- %TEMP%\nsg9.tmp\NSISpcre.dll
- %TEMP%\nsy1E.tmp\inetcn.dll
- %TEMP%\nsm30.tmp\NSISpcre.dll
- %TEMP%\nsm30.tmp\modern-header.bmp
- %TEMP%\nsg33.tmp\inetcn.dll
- %TEMP%\nsm30.tmp\System.dll
- %TEMP%\nsm30.tmp\inetcn.dll
- %TEMP%\nst2D.tmp\modern-header.bmp
- %TEMP%\nst2D.tmp\inetcn.dll
- %TEMP%\nst2D.tmp\System.dll
- %TEMP%\nst2D.tmp\NSISpcre.dll
- %TEMP%\nsg33.tmp\modern-header.bmp
- %TEMP%\nsq3C.tmp\inetcn.dll
- %TEMP%\nsx39.tmp\System.dll
- %TEMP%\nsq3C.tmp\NSISpcre.dll
- %TEMP%\nsq3C.tmp\modern-header.bmp
- %TEMP%\nsx39.tmp\NSISpcre.dll
- %TEMP%\nsg33.tmp\System.dll
- %TEMP%\nsg33.tmp\NSISpcre.dll
- %TEMP%\nsx39.tmp\modern-header.bmp
- %TEMP%\nsx39.tmp\inetcn.dll
- %TEMP%\nsc21.tmp\System.dll
- %TEMP%\nsc21.tmp\NSISpcre.dll
- %TEMP%\nsg24.tmp\modern-header.bmp
- %TEMP%\nsg24.tmp\inetcn.dll
- %TEMP%\nsc21.tmp\modern-header.bmp
- %TEMP%\nsy1E.tmp\NSISpcre.dll
- %TEMP%\nsy1E.tmp\modern-header.bmp
- %TEMP%\nsc21.tmp\inetcn.dll
- %TEMP%\nsy1E.tmp\System.dll
- %TEMP%\nsg24.tmp\NSISpcre.dll
- %TEMP%\nsj2A.tmp\modern-header.bmp
- %TEMP%\nsj2A.tmp\inetcn.dll
- %TEMP%\nsj2A.tmp\System.dll
- %TEMP%\nsj2A.tmp\NSISpcre.dll
- %TEMP%\nsf27.tmp\System.dll
- %TEMP%\nsf27.tmp\inetcn.dll
- %TEMP%\nsg24.tmp\System.dll
- %TEMP%\nsf27.tmp\NSISpcre.dll
- %TEMP%\nsf27.tmp\modern-header.bmp
- ClassName: '#32770' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''