Техническая информация
- '%APPDATA%\Roaming\Msuser\packpack.exe' QzpcVXNlcnNcRkZQWE9NRVZcQXBwRGF0YVxMb2NhbFxUZW1wXH5ERkJDMUQudG1wLmV4ZQA= 2
- '%TEMP%\~DFBC1D.tmp.exe' QzpcYmYzMmQzYjBcYjY2MmVmNDkuZXhlAA== 1
- %APPDATA%\Roaming\Microsoft\Crypto\RSA\S-1-5-21-2832440558-3064306045-1455513625-1000\7ee83745df35bad5ccfc8cd8875de253_97c09787-6498-4b10-8f65-9471d842c55e
- %TEMP%\~DFDF28.tmp
- %TEMP%\~DFDF48.tmp
- %TEMP%\~DFBC1D.tmp.exe
- %APPDATA%\Roaming\Msuser\packpack.exe
- %APPDATA%\Roaming\Microsoft\Protect\S-1-5-21-2832440558-3064306045-1455513625-1000\c664bbfb-26d1-47e7-89a1-c6cce305271a
- %TEMP%\~DFBC1D.tmp.exe
- DNS ASK fe###rama.com
- DNS ASK hi###akan.com
- DNS ASK go###ird.com
- DNS ASK dn#.##ftncsi.com
- ClassName: '' WindowName: '441576/2460'
- ClassName: '' WindowName: '446287/1428'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'MainForm' WindowName: ''
- ClassName: 'Unicode' WindowName: ''
- ClassName: '' WindowName: '439205/620'