Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] '{f65db027-aff3-4070-886a-0d87064aabb1}' = '"%ALLUSERSPROFILE%\Application Data\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\v...
- '<SYSTEM32>\msiexec.exe' /V
- '%TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\.be\vcredist_x86.exe' -q -burn.elevated BurnPipe.{30EE3E01-77A2-43B7-8776-B2FF7FF97BF9} {7F414BF8-FC07-487C-8A83-E269ED9C6BF1} 2924
- '%ProgramFiles%\PostgreSQL\9.4\vcredist_x86.exe' /passive /norestart
- <SYSTEM32>\msvcp120.dll
- <SYSTEM32>\msvcr120.dll
- %WINDIR%\Installer\MSI4.tmp
- C:\Config.Msi\31234.rbs
- <SYSTEM32>\vcomp120.dll
- %TEMP%\dd_vcredist_x86_20161103161319_1_vcRuntimeAdditional_x86.log
- %WINDIR%\Installer\31236.msi
- %WINDIR%\Installer\31235.msi
- %TEMP%\~DF95AF.tmp
- %TEMP%\~DF2F41.tmp
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\7396C420A8E1BC1DA97F1AF0D10BAD21
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\7396C420A8E1BC1DA97F1AF0D10BAD21
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\696F3DE637E6DE85B458996D49D759AD
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\696F3DE637E6DE85B458996D49D759AD
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\F90F18257CBB4D84216AC1E1F3BB2C76
- %WINDIR%\Installer\31231.msi
- %WINDIR%\Installer\31233.ipi
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\F90F18257CBB4D84216AC1E1F3BB2C76
- %TEMP%\dd_vcredist_x86_20161103161319_0_vcRuntimeMinimum_x86.log
- %WINDIR%\Installer\31238.ipi
- <SYSTEM32>\mfc120kor.dll
- <SYSTEM32>\mfc120rus.dll
- <SYSTEM32>\mfc120ita.dll
- <SYSTEM32>\mfc120jpn.dll
- <SYSTEM32>\mfc120u.dll
- %WINDIR%\Installer\3123a.msi
- %TEMP%\~DFA549.tmp
- <SYSTEM32>\mfcm120.dll
- <SYSTEM32>\mfcm120u.dll
- <SYSTEM32>\mfc120fra.dll
- C:\Config.Msi\31239.rbs
- <SYSTEM32>\mfc120.dll
- %TEMP%\~DF16B.tmp
- %WINDIR%\Installer\MSI7.tmp
- <SYSTEM32>\mfc120chs.dll
- <SYSTEM32>\mfc120enu.dll
- <SYSTEM32>\mfc120esn.dll
- <SYSTEM32>\mfc120cht.dll
- <SYSTEM32>\mfc120deu.dll
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19
- %TEMP%\dd_vcredist_x86_20161103161319.log
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\.be\vcredist_x86.exe
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\.ba1\BootstrapperApplicationData.xml
- %TEMP%\nsd3.tmp\services.dll
- %ProgramFiles%\PostgreSQL\9.4\vcredist_x86.exe
- %TEMP%\nsn2.tmp
- %TEMP%\nsd3.tmp\System.dll
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\.ba1\wixstdba.dll
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\.ba1\logo.png
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\.ba1\license.rtf
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\.ba1\thm.xml
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\.ba1\thm.wxl
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_.DEFAULT
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.MAP
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\cab54A5CABBE7274D8A22EB58060AAB7623
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\vcRuntimeMinimum_x86
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\vcRuntimeAdditional_x86
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING.VER
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.DATA
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\cabB3E1576D1FEFBB979E13B1A5379E0B16
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING1.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING2.MAP
- %ALLUSERSPROFILE%\Application Data\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\state.rsm
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SYSTEM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SAM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SECURITY
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SOFTWARE
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\ComDb.Dat
- %ALLUSERSPROFILE%\Application Data\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.BTR
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\domain.txt
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\$WinMgmt.CFG
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\.ba1\license.rtf
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\.ba1\logo.png
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\.be\vcredist_x86.exe
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\.ba1\BootstrapperApplicationData.xml
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\.ba1\wixstdba.dll
- %ProgramFiles%\PostgreSQL\9.4\vcredist_x86.exe
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\.ba1\thm.wxl
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\.ba1\thm.xml
- %WINDIR%\Installer\31231.msi
- %WINDIR%\Installer\31233.ipi
- %WINDIR%\Installer\MSI4.tmp
- C:\Config.Msi\31234.rbs
- %WINDIR%\Installer\31236.msi
- %WINDIR%\Installer\31238.ipi
- %WINDIR%\Installer\MSI7.tmp
- C:\Config.Msi\31239.rbs
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\cabB3E1576D1FEFBB979E13B1A5379E0B16 в %ALLUSERSPROFILE%\Application Data\Package Cache\.unverified\cabB3E1576D1FEFBB979E13B1A5379E0B16
- %ALLUSERSPROFILE%\Application Data\Package Cache\.unverified\vcRuntimeAdditional_x86 в %ALLUSERSPROFILE%\Application Data\Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\vc_runtimeAdditional_x86.msi
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\.be\vcredist_x86.exe в %TEMP%\DELA.tmp
- %ALLUSERSPROFILE%\Application Data\Package Cache\.unverified\cabB3E1576D1FEFBB979E13B1A5379E0B16 в %ALLUSERSPROFILE%\Application Data\Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\cab1.cab
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\vcRuntimeAdditional_x86 в %ALLUSERSPROFILE%\Application Data\Package Cache\.unverified\vcRuntimeAdditional_x86
- %ALLUSERSPROFILE%\Application Data\Package Cache\.unverified\vcRuntimeMinimum_x86 в %ALLUSERSPROFILE%\Application Data\Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\vc_runtimeMinimum_x86.msi
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\vcRuntimeMinimum_x86 в %ALLUSERSPROFILE%\Application Data\Package Cache\.unverified\vcRuntimeMinimum_x86
- %ALLUSERSPROFILE%\Application Data\Package Cache\.unverified\cab54A5CABBE7274D8A22EB58060AAB7623 в %ALLUSERSPROFILE%\Application Data\Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\cab1.cab
- %TEMP%\{f65db027-aff3-4070-886a-0d87064aabb1}\cab54A5CABBE7274D8A22EB58060AAB7623 в %ALLUSERSPROFILE%\Application Data\Package Cache\.unverified\cab54A5CABBE7274D8A22EB58060AAB7623
- '20#.#6.232.182':80
- 'wp#d':80
- http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl via 20#.#6.232.182
- http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl via 20#.#6.232.182
- http://11#.#11.111.1/wpad.dat via wp#d
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl via 20#.#6.232.182
- DNS ASK crl.microsoft.com
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: ''