Техническая информация
- '<SYSTEM32>\conhost.exe' /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
- '%PROGRAM_FILES%\Internet Explorer\iexplore.exe' http://me#.do/Gjbu69g
- <LS_APPDATA>\Microsoft\Windows\Temporary Internet Files\Content.IE5\23BUYPX5\errorPageStrings[1]
- <LS_APPDATA>\Microsoft\Windows\Temporary Internet Files\Content.IE5\UEWNTWLX\NewErrorPageTemplate[1]
- <LS_APPDATA>\Microsoft\Windows\Temporary Internet Files\Content.IE5\YIF7DGLM\dnserror[1]
- <LS_APPDATA>\Microsoft\Internet Explorer\imagestore\g1bfg6d\imagestore.dat
- %APPDATA%\Roaming\Microsoft\Protect\S-1-5-21-2832440558-3064306045-1455513625-1000\722f85b4-8b60-4c25-b65c-c4500cfb4e7d
- <LS_APPDATA>\Microsoft\Windows\Temporary Internet Files\Content.IE5\3U23MFC9\httpErrorPagesScripts[1]
- <LS_APPDATA>\Microsoft\Internet Explorer\Recovery\High\Active\{E7BEB4F2-E103-11E4-9159-DDAEC8DF56F3}.dat
- %TEMP%\~DF38A2029519799E97.TMP
- <LS_APPDATA>\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{E7BEB4F0-E103-11E4-9159-DDAEC8DF56F3}.dat
- %TEMP%\~DFA9144AF02CF826C7.TMP
- <LS_APPDATA>\Microsoft\Internet Explorer\Recovery\High\Active\{F2C37394-E103-11E4-9159-DDAEC8DF56F3}.dat
- %TEMP%\~DF84D30ABD1F8AB39E.TMP
- DNS ASK dn#.##ftncsi.com
- DNS ASK ie#####t.microsoft.com
- DNS ASK ie#####e.microsoft.com
- DNS ASK do##p3.net
- DNS ASK go.###rosoft.com
- DNS ASK me#.do
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''