Technical Information
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- D:\1.bat
- %LOCALAPPDATA%\44\screen.png
- C:\users\public\rehh7ft5.default-release\cert9.db
- C:\users\public\rehh7ft5.default-release\key4.db
- %TEMP%\tmp34fb.tmp.tmpdb
- %TEMP%\tmp348d.tmp.tmpdb
- C:\users\public\apc2n9d1.default-release\cert9.db
- C:\users\public\apc2n9d1.default-release\key4.db
- %TEMP%\tmp344e.tmp.tmpdb
- %TEMP%\tmp343d.tmp.dat
- %TEMP%\tmp342c.tmp.dat
- %TEMP%\tmp342b.tmp.dat
- %TEMP%\tmp33fc.tmp.dat
- %TEMP%\tmp32f1.tmp.tmpdb
- D:\test2.exe
- D:\test2.sfx.exe
- %LOCALAPPDATA%\44\process.txt
- %LOCALAPPDATA%\44\information.txt
- %TEMP%\tmp33fc.tmp.dat
- %TEMP%\tmp32f1.tmp.tmpdb
- %TEMP%\tmp342b.tmp.dat
- %TEMP%\tmp342c.tmp.dat
- %TEMP%\tmp343d.tmp.dat
- %TEMP%\tmp344e.tmp.tmpdb
- %TEMP%\tmp348d.tmp.tmpdb
- %TEMP%\tmp34fb.tmp.tmpdb
- DNS ASK fr###eoip.app
- ClassName: 'EDIT' WindowName: ''
- 'D:\test2.sfx.exe' -p123
- 'D:\test2.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""D:\1.bat" "