Техническая информация
- <SYSTEM32>\Microsoft\Protect\S-1-5-18\Preferred
- <SYSTEM32>\Microsoft\Protect\S-1-5-18\3a88283e-a605-4929-bfca-02c064fc0394
- %ALLUSERSPROFILE%\Application Data\Windows Genuine Advantage\Data\data.dat
- '20#.#6.232.182':80
- '20#.#6.232.182':443
- 20#.#6.232.182/reporting/xmlevent.ashx?v=#
- DNS ASK ge#####.microsoft.com
- DNS ASK mp#.###.microsoft.com