Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\www.exe
- '<SYSTEM32>\cscript.exe' "shell_scripts/check_if_cscript_is_working.js"
- '<SYSTEM32>\ping.exe' 8.8.8.8 -n 2 -w 500
- '%TEMP%\uTorrent.exe'
- '<SYSTEM32>\mshta.exe' "%TEMP%\HYD4.tmp.1481749237\HTA\index.hta?utorrent" "%TEMP%\uTorrent.exe" /LOG "%TEMP%\HYD4.tmp.1481749237\index.hta.log" /PID "2900" /CID "HuWEaD2Xi0ZYLKpR" /VERSION "110077274" /BUCKET "0" /...
- %TEMP%\HYD4.tmp.1481749237\HTA\images\mediacaster\chrome.png
- %TEMP%\HYD4.tmp.1481749237\HTA\images\yandex_horz_ru.png
- %TEMP%\HYD4.tmp.1481749237\HTA\images\mediacaster\firefox.png
- %TEMP%\HYD4.tmp.1481749237\HTA\images\mediacaster\logo.png
- %TEMP%\HYD4.tmp.1481749237\HTA\images\mediacaster\internetexplorer.png
- %TEMP%\HYD4.tmp.1481749237\HTA\images\yandex_horz.png
- %TEMP%\HYD4.tmp.1481749237\HTA\images\main_icon.png
- %TEMP%\HYD4.tmp.1481749237\HTA\images\main_bittorrent.ico
- %TEMP%\HYD4.tmp.1481749237\HTA\images\main_utorrent.ico
- %TEMP%\HYD4.tmp.1481749237\HTA\images\yandex_browser_setup.bmp
- %TEMP%\HYD4.tmp.1481749237\HTA\images\search_protect.png
- %TEMP%\HYD4.tmp.1481749237\HTA\images\mediacaster\screenshot.png
- %TEMP%\HYD4.tmp.1481749237\HTA\shell_scripts\shell_ping_after_close.js
- %TEMP%\HYD4.tmp.1481749237\HTA\shell_scripts\shell_install_offer.js
- %TEMP%\HYD4.tmp.1481749237\HTA\styles\common.css
- %HOMEPATH%\Cookies\%USERNAME%@localhost[2].txt
- %TEMP%\HYD4.tmp.1481749237\HTA\styles\installer.css
- %TEMP%\HYD4.tmp.1481749237\HTA\shell_scripts\check_if_cscript_is_working.js
- %TEMP%\HYD4.tmp.1481749237\HTA\scripts\es5-shim.js
- %TEMP%\HYD4.tmp.1481749237\HTA\scripts\common.js
- %TEMP%\HYD4.tmp.1481749237\HTA\scripts\initialize.js
- %TEMP%\HYD4.tmp.1481749237\HTA\scripts\uninstall.js
- %TEMP%\HYD4.tmp.1481749237\HTA\scripts\install.js
- %TEMP%\HYD4.tmp.1481749237\HTA\images\logo_Yandex_RU_UA_vertical.png
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\1f91d2d17ea675d4c2c3192e241743f9_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %HOMEPATH%\Cookies\%USERNAME%@localhost[1].txt
- %APPDATA%\uTorrent\settings.dat.new
- %TEMP%\HYD4.tmp.1481749237\HTA\install.1481749238.zip
- %TEMP%\HYD4.tmp.1481749237\index.hta.log
- %APPDATA%\Microsoft\Protect\CREDHIST
- %TEMP%\www.exe
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- %TEMP%\utt3.tmp
- %TEMP%\uTorrent.exe
- %TEMP%\HYD4.tmp.1481749237\HTA\index.hta
- %TEMP%\HYD4.tmp.1481749237\HTA\i18n\pt.json
- %TEMP%\HYD4.tmp.1481749237\HTA\i18n\it.json
- %TEMP%\HYD4.tmp.1481749237\HTA\i18n\ru.json
- %TEMP%\HYD4.tmp.1481749237\HTA\images\loading.gif
- %TEMP%\HYD4.tmp.1481749237\HTA\images\bt_icon_48px.png
- %TEMP%\HYD4.tmp.1481749237\HTA\i18n\fr.json
- %TEMP%\HYD4.tmp.1481749237\HTA\i18n\br.json
- %TEMP%\HYD4.tmp.1481749237\HTA\uninstall.hta
- %TEMP%\HYD4.tmp.1481749237\HTA\i18n\de.json
- %TEMP%\HYD4.tmp.1481749237\HTA\i18n\es.json
- %TEMP%\HYD4.tmp.1481749237\HTA\i18n\en.json
- %TEMP%\utt3.tmp
- %HOMEPATH%\Cookies\%USERNAME%@localhost[1].txt
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- %APPDATA%\uTorrent\settings.dat.new в %APPDATA%\uTorrent\settings.dat
- 'localhost':1041
- DNS ASK i-##.#####.xyz.bench.utorrent.com
- DNS ASK do######-lb.utorrent.com
- DNS ASK ro####.bittorrent.com
- DNS ASK ro####.utorrent.com
- ClassName: 'HTML Application Host Window Class' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''