Technical Information
- <SYSTEM32>\tasks\nvngxupdatecheckdaily_{78821544-1544-1544-1544-788215441544}
- %WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe
- iexplore.exe
- firefox.exe process, nss3.dll module
- iexplore.exe process, wininet.dll module
- [<HKCU>\Software\Martin Prikryl]
- [<HKLM>\Software\Wow6432Node\Martin Prikryl]
- %APPDATA%\mozilla\firefox\profiles.ini
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %APPDATA%\opera software\opera stable\login data
- %APPDATA%\thunderbird\profiles.ini
- %ProgramFiles(x86)%\steam\config\config.vdf
- %ProgramFiles(x86)%\steam\config\dialogconfig.vdf
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %HOMEPATH%\desktop\508softwareandos.doc
- %HOMEPATH%\desktop\adhd_and_obesity.docx
- %HOMEPATH%\desktop\holycrosschurchinstructions.docx
- %HOMEPATH%\desktop\nwfieldnotes1966.docx
- %HOMEPATH%\desktop\sdszfo.docx
- %HOMEPATH%\desktop\uep_form_786_bulletin_1726i602.doc
- %TEMP%\4dd3.tmp
- %TEMP%\tmpfa4e.tmp
- %TEMP%\tmpfa4d.tmp
- %TEMP%\tmpfa4c.tmp
- %TEMP%\tmpfa4b.tmp
- %TEMP%\tmpfa3b.tmp
- %TEMP%\tmpfa3a.tmp
- %TEMP%\tmpfa39.tmp
- %TEMP%\tmpfa38.tmp
- %TEMP%\tmpfa26.tmp
- %TEMP%\tmpfa60.tmp
- %TEMP%\tmpfa25.tmp
- %TEMP%\tmpfa24.tmp
- %TEMP%\tmpfa14.tmp
- %TEMP%\tmpfa13.tmp
- %TEMP%\tmpfa12.tmp
- %TEMP%\tmpfa11.tmp
- %TEMP%\tmpfa10.tmp
- %TEMP%\tmpfa37.tmp
- %TEMP%\tmpf9d3.tmp
- %TEMP%\tmpfa71.tmp
- %TEMP%\tmp219c.tmp
- %TEMP%\tmp218c.tmp
- %TEMP%\tmp218b.tmp
- %TEMP%\tmp218a.tmp
- %TEMP%\tmp2189.tmp
- %TEMP%\tmp2178.tmp
- %TEMP%\tmp2177.tmp
- %TEMP%\tmp2176.tmp
- %TEMP%\tmpfa0f.tmp
- %TEMP%\tmpfa5f.tmp
- %TEMP%\tmpfac8.tmp
- %TEMP%\tmpfab7.tmp
- %TEMP%\tmpfa97.tmp
- %TEMP%\tmpfa86.tmp
- %TEMP%\tmpfa85.tmp
- %TEMP%\tmpfa75.tmp
- %TEMP%\tmpfa74.tmp
- %TEMP%\tmpfa73.tmp
- %TEMP%\tmp2145.tmp
- %TEMP%\tmpfa72.tmp
- %TEMP%\tmpf9fe.tmp
- %TEMP%\tmpf9fd.tmp
- %TEMP%\tmpf9fc.tmp
- %TEMP%\tmpf96f.tmp
- %TEMP%\tmpf996.tmp
- %TEMP%\tmpf995.tmp
- %TEMP%\tmpf984.tmp
- %TEMP%\tmpf983.tmp
- %TEMP%\tmpf982.tmp
- %TEMP%\tmpf981.tmp
- %TEMP%\tmpf971.tmp
- %TEMP%\tmp219d.tmp
- %TEMP%\tmpf998.tmp
- %TEMP%\tmpf95e.tmp
- %TEMP%\tmpf95d.tmp
- %TEMP%\tmpf95c.tmp
- %TEMP%\tmpf95b.tmp
- %TEMP%\tmpf94b.tmp
- %TEMP%\tmpf94a.tmp
- %TEMP%\tmpf939.tmp
- %TEMP%\tmpf938.tmp
- %TEMP%\tmpf970.tmp
- %TEMP%\tmp2146.tmp
- %TEMP%\tmpf999.tmp
- %TEMP%\tmpf9ac.tmp
- %TEMP%\tmpf9aa.tmp
- %TEMP%\tmpf9fb.tmp
- %TEMP%\tmpf9fa.tmp
- %TEMP%\tmpf9e9.tmp
- %TEMP%\tmpf9e8.tmp
- %TEMP%\tmpf9e7.tmp
- %TEMP%\tmpf9e6.tmp
- %TEMP%\tmpf9e5.tmp
- %TEMP%\tmpf9ab.tmp
- %TEMP%\tmpf9e4.tmp
- %TEMP%\tmpf997.tmp
- %TEMP%\tmpf9d2.tmp
- %TEMP%\tmpf9c1.tmp
- %TEMP%\tmpf9c0.tmp
- %TEMP%\tmpf9bf.tmp
- %TEMP%\tmpf9be.tmp
- %TEMP%\tmpf9ae.tmp
- %TEMP%\tmpf9ad.tmp
- %TEMP%\tmpf9d4.tmp
- %TEMP%\tmp219e.tmp
- %TEMP%\tmp219f.tmp
- %TEMP%\tmp21b0.tmp
- %TEMP%\tmp22b9.tmp
- %TEMP%\tmp22b8.tmp
- %TEMP%\tmp22b7.tmp
- %TEMP%\tmp22b6.tmp
- %TEMP%\tmp22b5.tmp
- %TEMP%\tmp22b4.tmp
- %TEMP%\tmp22a3.tmp
- %TEMP%\tmp22a2.tmp
- %TEMP%\tmp22ba.tmp
- %TEMP%\tmp22a1.tmp
- %TEMP%\tmp229f.tmp
- %TEMP%\tmp229e.tmp
- %TEMP%\tmp228e.tmp
- %TEMP%\tmp228d.tmp
- %TEMP%\tmp228c.tmp
- %TEMP%\tmp228b.tmp
- %TEMP%\tmp227a.tmp
- %TEMP%\tmp2279.tmp
- %TEMP%\tmp22a0.tmp
- %TEMP%\tmp22f5.tmp
- %TEMP%\tmpf937.tmp
- %TEMP%\tmp22cc.tmp
- %TEMP%\tmp231d.tmp
- %TEMP%\tmp231c.tmp
- %TEMP%\tmp230b.tmp
- %TEMP%\tmp230a.tmp
- %TEMP%\tmp2309.tmp
- %TEMP%\tmp2308.tmp
- %TEMP%\tmp2307.tmp
- %TEMP%\tmp22f7.tmp
- %TEMP%\tmp2278.tmp
- %TEMP%\tmp22f6.tmp
- %TEMP%\tmp22f4.tmp
- %TEMP%\tmp22f3.tmp
- %TEMP%\tmp22f2.tmp
- %TEMP%\tmp22e1.tmp
- %TEMP%\tmp22e0.tmp
- %TEMP%\tmp22df.tmp
- %TEMP%\tmp22ce.tmp
- %TEMP%\tmp22cd.tmp
- %TEMP%\tmp22ca.tmp
- %TEMP%\tmp223c.tmp
- %TEMP%\tmp2277.tmp
- %TEMP%\tmp2213.tmp
- %TEMP%\tmp2200.tmp
- %TEMP%\tmp21ff.tmp
- %TEMP%\tmp21fe.tmp
- %TEMP%\tmp21fd.tmp
- %TEMP%\tmp21ed.tmp
- %TEMP%\tmp21ec.tmp
- %TEMP%\tmp21eb.tmp
- %TEMP%\tmp21ea.tmp
- %TEMP%\tmp2201.tmp
- %TEMP%\tmp21d9.tmp
- %TEMP%\tmp21d7.tmp
- %TEMP%\tmp21d6.tmp
- %TEMP%\tmp21d5.tmp
- %TEMP%\tmp21c5.tmp
- %TEMP%\tmp21c4.tmp
- %TEMP%\tmp21b3.tmp
- %TEMP%\tmp21b2.tmp
- %TEMP%\tmp21b1.tmp
- %TEMP%\tmp21d8.tmp
- %TEMP%\tmp233d.tmp
- %TEMP%\tmp2275.tmp
- %TEMP%\tmp2214.tmp
- %TEMP%\tmp2264.tmp
- %TEMP%\tmp2263.tmp
- %TEMP%\tmp2262.tmp
- %TEMP%\tmp2261.tmp
- %TEMP%\tmp2260.tmp
- %TEMP%\tmp225f.tmp
- %TEMP%\tmp224f.tmp
- %TEMP%\tmp224e.tmp
- %TEMP%\tmp2276.tmp
- %TEMP%\tmp223d.tmp
- %TEMP%\tmp223b.tmp
- %TEMP%\tmp223a.tmp
- %TEMP%\tmp2239.tmp
- %TEMP%\tmp2229.tmp
- %TEMP%\tmp2228.tmp
- %TEMP%\tmp2227.tmp
- %TEMP%\tmp2226.tmp
- %TEMP%\tmp2215.tmp
- %TEMP%\tmp2212.tmp
- %TEMP%\tmp22cb.tmp
- %TEMP%\tmpf936.tmp
- %TEMP%\tmpf8b3.tmp
- %TEMP%\tmpf294.tmp
- %TEMP%\tmpf293.tmp
- %TEMP%\tmpf283.tmp
- %TEMP%\tmpf282.tmp
- %TEMP%\tmpf281.tmp
- %TEMP%\tmpf280.tmp
- %TEMP%\tmpf27f.tmp
- %TEMP%\tmpf26e.tmp
- %TEMP%\tmpf26c.tmp
- %TEMP%\tmpf296.tmp
- %TEMP%\tmpf26b.tmp
- %TEMP%\tmpf113.tmp
- %TEMP%\tmpf0f3.tmp
- %TEMP%\c80d.tmp-shm
- %TEMP%\c80d.tmp
- %TEMP%\c7fd.tmp
- %TEMP%\c7fc.tmp
- %TEMP%\tmpf26d.tmp
- %LOCALAPPDATA%\microsoft\vault\4bf4c442-9b8a-41a0-b380-dd4a704ddb28\policy.vpol
- %TEMP%\tmpf2a7.tmp
- %TEMP%\tmpf2f8.tmp
- %TEMP%\tmpf2f7.tmp
- %TEMP%\tmpf2f6.tmp
- %TEMP%\tmpf2f5.tmp
- %TEMP%\tmpf2e5.tmp
- %TEMP%\tmpf2e4.tmp
- %TEMP%\tmpf2e3.tmp
- %TEMP%\tmpf2e2.tmp
- %TEMP%\c7eb.tmp
- %TEMP%\tmpf295.tmp
- %TEMP%\tmpf2cf.tmp
- %TEMP%\tmpf2ce.tmp
- %TEMP%\tmpf2bd.tmp
- %TEMP%\tmpf2bc.tmp
- %TEMP%\tmpf2bb.tmp
- %TEMP%\tmpf2ba.tmp
- %TEMP%\tmpf2aa.tmp
- %TEMP%\tmpf2a9.tmp
- %TEMP%\tmpf2d0.tmp
- %TEMP%\tmpf2a8.tmp
- %TEMP%\c7ea.tmp
- %TEMP%\c7da.tmp
- %TEMP%\c7c9.tmp
- %APPDATA%\opera software\opera stable\extensions\obmagbjicmljlnpdmjnkbnhhokplebpd\10.1.1.2_0\manifest.json
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\cfkgiclmhiahbejmkjdaomoeeedpkajf\10.1.1.2_0\manifest.json
- %APPDATA%\opera software\opera stable\extensions\obmagbjicmljlnpdmjnkbnhhokplebpd\10.1.1.2_0\bg.js
- %APPDATA%\opera software\opera stable\extensions\obmagbjicmljlnpdmjnkbnhhokplebpd\10.1.1.2_0\images\toolbaricon\48x48.png
- %APPDATA%\opera software\opera stable\extensions\obmagbjicmljlnpdmjnkbnhhokplebpd\10.1.1.2_0\images\48x48.png
- %APPDATA%\opera software\opera stable\extensions\obmagbjicmljlnpdmjnkbnhhokplebpd\10.1.1.2_0\images\48x48-gray.png
- %APPDATA%\opera software\opera stable\extensions\obmagbjicmljlnpdmjnkbnhhokplebpd\10.1.1.2_0\images\128x128.png
- %APPDATA%\opera software\opera stable\extensions\obmagbjicmljlnpdmjnkbnhhokplebpd\10.1.1.2_0\_locales\ru\messages.json
- %TEMP%\tmpf309.tmp
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\cfkgiclmhiahbejmkjdaomoeeedpkajf\10.1.1.2_0\_locales\ru\messages.json
- %LOCALAPPDATA%\pgujaxlxrcsvmyi7_u4gifnp2ry7iifm
- %TEMP%\8385.tmp.exe
- %TEMP%\78ca.tmp.exe
- %TEMP%\6b04.tmp.exe
- %TEMP%\5aec.tmp.exe
- %TEMP%\54a4.tmp.exe
- %APPDATA%\srbtref
- %APPDATA%\ihbrcfv
- %APPDATA%\opera software\opera stable\extensions\obmagbjicmljlnpdmjnkbnhhokplebpd\10.1.1.2_0\_locales\en\messages.json
- %TEMP%\tmpf2d1.tmp
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\cfkgiclmhiahbejmkjdaomoeeedpkajf\10.1.1.2_0\images\128x128.png
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\cfkgiclmhiahbejmkjdaomoeeedpkajf\10.1.1.2_0\images\toolbaricon\48x48.png
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\cfkgiclmhiahbejmkjdaomoeeedpkajf\10.1.1.2_0\images\48x48-gray.png
- %TEMP%\c7b8.tmp
- %TEMP%\c7b7.tmp
- %TEMP%\c73a.tmp
- %TEMP%\c739.tmp
- %TEMP%\c728.tmp
- %TEMP%\c727.tmp
- %TEMP%\c5ee.tmp
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\cfkgiclmhiahbejmkjdaomoeeedpkajf\10.1.1.2_0\images\48x48.png
- %TEMP%\c5dd.tmp-shm
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\cfkgiclmhiahbejmkjdaomoeeedpkajf\10.1.1.2_0\_locales\en\messages.json
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\2f1a6504-0641-44cf-8bb5-3612d865f2e5.vsch
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\3ccd5499-87a8-4b10-a215-608888dd3b55.vsch
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\policy.vpol
- %TEMP%\ab91.tmp.exe
- %TEMP%\9b5a.tmp.exe
- %TEMP%\918a.tmp.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\cfkgiclmhiahbejmkjdaomoeeedpkajf\10.1.1.2_0\bg.js
- %TEMP%\c5dd.tmp
- %TEMP%\tmpf30a.tmp
- %TEMP%\tmpf30b.tmp
- %TEMP%\tmpf30c.tmp
- %TEMP%\tmpf891.tmp
- %TEMP%\tmpf636.tmp
- %TEMP%\tmpf635.tmp
- %TEMP%\tmpf624.tmp
- %TEMP%\tmpf613.tmp
- %TEMP%\tmpf612.tmp
- %TEMP%\tmpf611.tmp
- %TEMP%\tmpf601.tmp
- %TEMP%\tmpf892.tmp
- %TEMP%\tmpf600.tmp
- %TEMP%\tmpf5fe.tmp
- %TEMP%\tmpf5fd.tmp
- %TEMP%\tmpf5fc.tmp
- %TEMP%\tmpf5fb.tmp
- %TEMP%\tmpf5ea.tmp
- %TEMP%\tmpf5e9.tmp
- %TEMP%\tmpf5e8.tmp
- %TEMP%\tmpf5e7.tmp
- %TEMP%\tmpf5ff.tmp
- %TEMP%\tmpf8dc.tmp
- %TEMP%\tmpf916.tmp
- %TEMP%\tmpf8b4.tmp
- %TEMP%\tmpf914.tmp
- %TEMP%\tmpf913.tmp
- %TEMP%\tmpf902.tmp
- %TEMP%\tmpf901.tmp
- %TEMP%\tmpf900.tmp
- %TEMP%\tmpf8ff.tmp
- %TEMP%\tmpf8ef.tmp
- %TEMP%\tmpf8ee.tmp
- %TEMP%\tmpf5e6.tmp
- %TEMP%\tmpf8ed.tmp
- %TEMP%\tmpf8db.tmp
- %TEMP%\tmpf8da.tmp
- %TEMP%\tmpf8d9.tmp
- %TEMP%\tmpf8d8.tmp
- %TEMP%\tmpf8c7.tmp
- %TEMP%\tmpf8c6.tmp
- %TEMP%\tmpf8b6.tmp
- %TEMP%\tmpf8b5.tmp
- %TEMP%\tmpf8a2.tmp
- %TEMP%\tmpf5ba.tmp
- %TEMP%\tmpf5e5.tmp
- %TEMP%\tmpf581.tmp
- %TEMP%\tmpf57e.tmp
- %TEMP%\tmpf56e.tmp
- %TEMP%\tmpf56d.tmp
- %TEMP%\tmpf56c.tmp
- %TEMP%\tmpf56b.tmp
- %TEMP%\tmpf56a.tmp
- %TEMP%\tmpf569.tmp
- %TEMP%\tmpf568.tmp
- %TEMP%\tmpf57f.tmp
- %TEMP%\tmpf557.tmp
- %TEMP%\tmpf47b.tmp
- %TEMP%\tmpf47a.tmp
- %TEMP%\tmpf469.tmp
- %TEMP%\tmpf468.tmp
- %TEMP%\tmpf467.tmp
- %TEMP%\tmpf466.tmp
- %TEMP%\tmpf455.tmp
- %TEMP%\tmpf30d.tmp
- %TEMP%\tmpf47c.tmp
- %TEMP%\tmpf915.tmp
- %TEMP%\tmpf5d4.tmp
- %TEMP%\tmpf592.tmp
- %TEMP%\tmpf5d3.tmp
- %TEMP%\tmpf5d2.tmp
- %TEMP%\tmpf5d1.tmp
- %TEMP%\tmpf5d0.tmp
- %TEMP%\tmpf5bf.tmp
- %TEMP%\tmpf5be.tmp
- %TEMP%\tmpf5bd.tmp
- %TEMP%\tmpf5bc.tmp
- %TEMP%\tmpf5d5.tmp
- %TEMP%\tmpf5bb.tmp
- %TEMP%\tmpf5b9.tmp
- %TEMP%\tmpf5a8.tmp
- %TEMP%\tmpf5a7.tmp
- %TEMP%\tmpf5a6.tmp
- %TEMP%\tmpf5a5.tmp
- %TEMP%\tmpf5a4.tmp
- %TEMP%\tmpf594.tmp
- %TEMP%\tmpf593.tmp
- %TEMP%\tmpf580.tmp
- %TEMP%\tmp233e.tmp
- %APPDATA%\ihbrcfv
- %APPDATA%\srbtref
- %LOCALAPPDATA%\pgujaxlxrcsvmyi7_u4gifnp2ry7iifm
- %TEMP%\tmpfa4c.tmp
- %TEMP%\tmpfa4e.tmp
- %TEMP%\tmpfa60.tmp
- %TEMP%\tmpfa72.tmp
- %TEMP%\tmpfa74.tmp
- %TEMP%\tmpfa85.tmp
- %TEMP%\tmpfa86.tmp
- %TEMP%\tmpfa25.tmp
- %TEMP%\tmpfa97.tmp
- %TEMP%\tmpfac8.tmp
- %TEMP%\tmp2146.tmp
- %TEMP%\tmp2177.tmp
- %TEMP%\tmp2189.tmp
- %TEMP%\tmp218b.tmp
- %TEMP%\tmp219c.tmp
- %TEMP%\tmp219e.tmp
- %TEMP%\tmpfa39.tmp
- %TEMP%\tmpfa3b.tmp
- %TEMP%\tmpfa37.tmp
- %TEMP%\tmpfa14.tmp
- %TEMP%\tmp21b2.tmp
- %TEMP%\tmpf996.tmp
- %TEMP%\tmpf998.tmp
- %TEMP%\tmpf9aa.tmp
- %TEMP%\tmpf9ac.tmp
- %TEMP%\tmpf9ae.tmp
- %TEMP%\tmpf9bf.tmp
- %TEMP%\tmp21b0.tmp
- %TEMP%\tmpf982.tmp
- %TEMP%\tmpfab7.tmp
- %TEMP%\tmpf9c1.tmp
- %TEMP%\tmpf9e8.tmp
- %TEMP%\tmpf9fa.tmp
- %TEMP%\tmpf9fc.tmp
- %TEMP%\tmpf9fe.tmp
- %TEMP%\tmpfa10.tmp
- %TEMP%\tmpfa12.tmp
- %TEMP%\tmpf9d3.tmp
- %TEMP%\tmpf9e4.tmp
- %TEMP%\tmpf9e6.tmp
- %TEMP%\tmpf5be.tmp
- %TEMP%\tmp21c4.tmp
- %TEMP%\tmp229f.tmp
- %TEMP%\tmp22a1.tmp
- %TEMP%\tmp22a3.tmp
- %TEMP%\tmp22b5.tmp
- %TEMP%\tmp22b7.tmp
- %TEMP%\tmp22b9.tmp
- %TEMP%\tmp22ca.tmp
- %TEMP%\tmp22cc.tmp
- %TEMP%\tmp228e.tmp
- %TEMP%\tmpf971.tmp
- %TEMP%\tmp228c.tmp
- %TEMP%\tmp22f4.tmp
- %TEMP%\tmp22f6.tmp
- %TEMP%\tmp2307.tmp
- %TEMP%\tmp2309.tmp
- %TEMP%\tmp230b.tmp
- %TEMP%\tmp231c.tmp
- %TEMP%\tmp231d.tmp
- %TEMP%\tmp22e0.tmp
- %TEMP%\tmp22ce.tmp
- %TEMP%\tmpf984.tmp
- %TEMP%\tmp2278.tmp
- %TEMP%\tmp2239.tmp
- %TEMP%\tmp21d9.tmp
- %TEMP%\tmp21eb.tmp
- %TEMP%\tmp21ed.tmp
- %TEMP%\tmp21fe.tmp
- %TEMP%\tmp2200.tmp
- %TEMP%\tmp2212.tmp
- %TEMP%\tmp2214.tmp
- %TEMP%\tmp227a.tmp
- %TEMP%\tmp21d5.tmp
- %TEMP%\tmp21d7.tmp
- %TEMP%\tmp223b.tmp
- %TEMP%\tmp223d.tmp
- %TEMP%\tmp224f.tmp
- %TEMP%\tmp2260.tmp
- %TEMP%\tmp2262.tmp
- %TEMP%\tmp2264.tmp
- %TEMP%\tmp2276.tmp
- %TEMP%\tmp2228.tmp
- %TEMP%\tmp2226.tmp
- %TEMP%\tmpf96f.tmp
- %TEMP%\tmpf95d.tmp
- %TEMP%\tmpf95b.tmp
- %TEMP%\tmpf2a7.tmp
- %TEMP%\tmpf2a9.tmp
- %TEMP%\tmpf2ba.tmp
- %TEMP%\tmpf2bc.tmp
- %TEMP%\tmpf2ce.tmp
- %TEMP%\tmpf2d0.tmp
- %TEMP%\tmpf282.tmp
- %TEMP%\c7c9.tmp
- %TEMP%\tmpf295.tmp
- %TEMP%\tmpf2e2.tmp
- %TEMP%\tmpf309.tmp
- %TEMP%\tmpf30b.tmp
- %TEMP%\tmpf30d.tmp
- %TEMP%\tmpf466.tmp
- %TEMP%\tmpf468.tmp
- %TEMP%\tmpf47a.tmp
- %TEMP%\tmpf2e4.tmp
- %TEMP%\tmpf2f5.tmp
- %TEMP%\tmpf2f7.tmp
- %TEMP%\tmp233d.tmp
- %TEMP%\tmpf47c.tmp
- %TEMP%\tmpf26c.tmp
- %TEMP%\c5dd.tmp
- %TEMP%\c5ee.tmp
- %TEMP%\c727.tmp
- %TEMP%\c728.tmp
- %TEMP%\c739.tmp
- %TEMP%\c73a.tmp
- %TEMP%\c7b7.tmp
- %TEMP%\tmpf26e.tmp
- %TEMP%\tmpf280.tmp
- %TEMP%\c7b8.tmp
- %TEMP%\c7ea.tmp
- %TEMP%\c7eb.tmp
- %TEMP%\c7fc.tmp
- %TEMP%\c7fd.tmp
- %TEMP%\c80d.tmp-shm
- %TEMP%\c80d.tmp
- %TEMP%\tmpf113.tmp
- %TEMP%\c5dd.tmp-shm
- %TEMP%\c7da.tmp
- %TEMP%\tmp22f2.tmp
- %TEMP%\tmpf568.tmp
- %TEMP%\tmpf56e.tmp
- %TEMP%\tmpf635.tmp
- %TEMP%\tmpf636.tmp
- %TEMP%\tmpf892.tmp
- %TEMP%\tmpf8b3.tmp
- %TEMP%\tmpf8b5.tmp
- %TEMP%\tmpf8c6.tmp
- %TEMP%\tmpf8d8.tmp
- %TEMP%\tmpf56a.tmp
- %TEMP%\tmpf624.tmp
- %TEMP%\tmpf613.tmp
- %TEMP%\tmpf8ff.tmp
- %TEMP%\tmpf901.tmp
- %TEMP%\tmpf913.tmp
- %TEMP%\tmpf915.tmp
- %TEMP%\tmpf936.tmp
- %TEMP%\tmpf938.tmp
- %TEMP%\tmpf94a.tmp
- %TEMP%\tmpf8da.tmp
- %TEMP%\tmpf8ee.tmp
- %TEMP%\tmpf56c.tmp
- %TEMP%\tmpf8dc.tmp
- %TEMP%\tmpf293.tmp
- %TEMP%\tmpf57f.tmp
- %TEMP%\tmpf581.tmp
- %TEMP%\tmpf593.tmp
- %TEMP%\tmpf5a4.tmp
- %TEMP%\tmpf5a6.tmp
- %TEMP%\tmpf5a8.tmp
- %TEMP%\tmpf5ba.tmp
- %TEMP%\tmpf5ff.tmp
- %TEMP%\tmpf612.tmp
- %TEMP%\tmpf601.tmp
- %TEMP%\tmpf5d2.tmp
- %TEMP%\tmpf5d4.tmp
- %TEMP%\tmpf5e5.tmp
- %TEMP%\tmpf5e7.tmp
- %TEMP%\tmpf5e9.tmp
- %TEMP%\tmpf5fb.tmp
- %TEMP%\tmpf5fd.tmp
- %TEMP%\tmpf5bc.tmp
- %TEMP%\tmpf5d0.tmp
- %TEMP%\tmp233e.tmp
- %LOCALAPPDATA%\google\chrome\user data\default\secure preferences
- 'sh#####ourbalance.top':443
- '17#.#0.40.83':81
- '10#.#34.38.124':35200
- '2t##.#olganfor.ru':443
- '10############6831-service1002012510022020.space':80
- '50##.#olganfor.ru':443
- 'ap#.ip.sb':443
- 'wh###.iana.org':43
- 'WH###.RIPE.NET':43
- '86.##6.181.95':3214
- http://10############6831-service1002012510022020.space/raccon.exe
- http://10############6831-service1002012510022020.space/reestr.exe
- http://10###########lder1002002131-service1002.space/
- http://10##########older33417-01242510022020.space/
- http://10############6831-service1002012510022020.space/
- http://10#.###.38.124:35200/ via 10#.#34.38.124
- http://17#.#0.40.83:81/ via 17#.#0.40.83
- http://86.###.181.95:3214/ via 86.##6.181.95
- DNS ASK 10###########lder1002002131-service1002.space
- DNS ASK 10###########lder1002002231-service1002.space
- DNS ASK 10##########older3100231-service1002.space
- DNS ASK 10###########lder1002002431-service1002.space
- DNS ASK 10###########lder1002002531-service1002.space
- DNS ASK 10##########older33417-01242510022020.space
- DNS ASK 10############5831-service1002012510022020.space
- DNS ASK 10############6831-service1002012510022020.space
- DNS ASK te##te.in
- DNS ASK sh#####ourbalance.top
- DNS ASK 2t##.#olganfor.ru
- DNS ASK 50##.#olganfor.ru
- DNS ASK ap#.ip.sb
- DNS ASK wh###.iana.org
- DNS ASK WH###.RIPE.NET
- '%TEMP%\54a4.tmp.exe'
- '%TEMP%\5aec.tmp.exe'
- '%TEMP%\6b04.tmp.exe'
- '%TEMP%\78ca.tmp.exe'
- '%TEMP%\8385.tmp.exe'
- '%TEMP%\918a.tmp.exe'
- '%TEMP%\9b5a.tmp.exe'
- '%TEMP%\ab91.tmp.exe'
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\explorer.exe'
- '%WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe'