Technical Information
- DNS server to '<DNS_SERVER>'
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\preferences
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\preferredapps
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\readme
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\secure preferences
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\top sites
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\visited links
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\sync data\leveldb\000003.log
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\vpn tokens
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\grshadercache\data_0
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\grshadercache\data_1
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\grshadercache\data_2
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\grshadercache\data_3
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\grshadercache\f_000001
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\grshadercache\f_000002
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\login data
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\network action predictor
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\history
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\heavy_ad_intervention_opt_out.db
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\favicons
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\shared_proto_db\log.old
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\shared_proto_db\manifest-000001
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\site characteristics database\000003.log
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\site characteristics database\current
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\site characteristics database\log
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\site characteristics database\log.old
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\grshadercache\f_000003
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\web data
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\site characteristics database\manifest-000001
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\sync data\leveldb\log
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\sync data\leveldb\log.old
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\sync data\leveldb\manifest-000001
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\dips
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\extensionactivitycomp
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\extensionactivityedge
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\shared_proto_db\log
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\sync data\leveldb\current
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\grshadercache\f_000004
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\grshadercache\f_000005
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\grshadercache\f_000006
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\variations
- %APPDATA%\app\vin\r88\runtimes\win-arm64\native\webview2loader.dll
- %APPDATA%\app\vin\r88\runtimes\win-x64\native\webview2loader.dll
- %APPDATA%\app\vin\r88\runtimes\win-x86\native\webview2loader.dll
- %APPDATA%\app\vin\r88\favicon.ico
- %APPDATA%\app\vin\r88\microsoft.web.webview2.core.dll
- %APPDATA%\app\vin\r88\microsoft.web.webview2.core.xml
- %APPDATA%\app\vin\r88\microsoft.web.webview2.winforms.xml
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\shared_proto_db\current
- %APPDATA%\app\vin\r88\microsoft.web.webview2.wpf.dll
- %APPDATA%\app\vin\r88\microsoft.web.webview2.wpf.xml
- %APPDATA%\app\vin\r88\r88.application
- %APPDATA%\app\vin\r88\r88.exe.config
- %APPDATA%\app\vin\r88\r88.exe.manifest
- %APPDATA%\app\vin\r88\r88.pdb
- %WINDIR%\syswow64\change dns.exe
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\local state
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\smartscreen\remotedata\customsettings
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\last version
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\smartscreen\local\uricache_
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\grshadercache\index
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\shadercache\data_0
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\shadercache\data_1
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\shadercache\data_2
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\shadercache\data_3
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\shadercache\index
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\smartscreen\local\uricache
- %HOMEPATH%\desktop\r88 for pc.lnk
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\smartscreen\remotedata\toptraffic
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\smartscreen\remotedata\customsettings_f95ba787499ab4fa9efff472ce383a14
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\smartscreen\remotedata\customsynchronouslookupuris
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\smartscreen\remotedata\customsynchronouslookupuris_0
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\smartscreen\remotedata\edgesettings
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\smartscreen\remotedata\edgesettings_2.0-48b11410dc937a1723bf4c5ad33ecdb286d8ec69544241bc373f753e64b396c1
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\smartscreen\remotedata\synchronouslookupuris
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\smartscreen\remotedata\synchronouslookupuris_638225692864238157
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\smartscreen\remotedata\toptraffic_638004170464094982
- %APPDATA%\app\vin\r88\microsoft.web.webview2.winforms.dll
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\shared_proto_db\000003.log
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\network\sdch dictionaries
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\f_00000b
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\f_00000c
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\f_00000d
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\f_00000e
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\index
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\code cache\js\index-dir\the-real-index
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\data_1
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\code cache\js\16063d850c42a2c1_0
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\code cache\js\3f63f2d6900ecc4a_0
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\code cache\js\cbf141f600ed1af8_0
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\code cache\js\index
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\code cache\wasm\index-dir\the-real-index
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\code cache\wasm\index
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\dawncache\data_0
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\f_000009
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\f_00000a
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\f_000008
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\f_000007
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\f_000006
- %APPDATA%\app\vin\r88\r88.exe
- %APPDATA%\app\vin\r88\app.publish\r88.exe
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\browsermetrics\browsermetrics-648d35ee-41ec.pma
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\browsermetrics\browsermetrics-648d365d-3008.pma
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\crashpad\settings.dat
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\crashpad\throttle_store.dat
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\dawncache\data_1
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\code cache\js\2e5af7c15d7df5ac_0
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\data_0
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\data_3
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\f_000001
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\f_000002
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\f_000003
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\f_000004
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\f_000005
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\cache\cache_data\data_2
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\dawncache\data_2
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\dawncache\data_3
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\dawncache\index
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\local storage\leveldb\log
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\local storage\leveldb\log.old
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\local storage\leveldb\manifest-000001
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\network\cookies
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\network\network persistent state
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\network\reporting and nel
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\network\sct auditing pending reports
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\session storage\000003.log
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\shared_proto_db\metadata\manifest-000001
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\session storage\current
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\session storage\log
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\session storage\log.old
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\session storage\manifest-000001
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\shared_proto_db\metadata\000003.log
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\shared_proto_db\metadata\current
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\shared_proto_db\metadata\log
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\local storage\leveldb\current
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\extension scripts\manifest-000001
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\gpucache\index
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\extension scripts\log
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\edgeedrop\edgeedropsqlite.db
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\extension rules\000003.log
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\extension rules\current
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\extension rules\log
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\extension rules\manifest-000001
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\extension scripts\000003.log
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\extension scripts\current
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\shared_proto_db\metadata\log.old
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\gpucache\data_2
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\extension state\000003.log
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\extension state\current
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\extension state\log
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\extension state\log.old
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\extension state\manifest-000001
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\gpucache\data_0
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\gpucache\data_1
- %APPDATA%\app\vin\r88\r88.exe.webview2\ebwebview\default\gpucache\data_3
- %APPDATA%\microsoft\windows\start menu\programs\windows\change dns.lnk
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- '<DNS_SERVER>':53
- DNS ASK microsoft.com
- ClassName: 'MS_WINHELP' WindowName: ''
- '%TEMP%\_ir_sf_temp_0\irsetup.exe' __IRAOFF:670242 "__IRAFN:<Full path to file>" "__IRCT:2" "__IRTSS:0" "__IRSID:S-1-5-21-3150914307-1777937420-491476919-1000"
- '%WINDIR%\syswow64\change dns.exe'
- '%APPDATA%\app\vin\r88\r88.exe'
- '%WINDIR%\syswow64\netsh.exe' interface ip set dns name="Wi-Fi" static 8.8.8.8 primary' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' interface ip set dns name="Local Area Connection" static 8.8.8.8 primary' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' interface ip set dns name="Ethernet" static 8.8.8.8 primary' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' interface ip set dns name="Wi-Fi" static 8.8.8.8 primary
- '%WINDIR%\syswow64\netsh.exe' interface ip add dns name="Wi-Fi" addr=8.8.4.4 index=2
- '%WINDIR%\syswow64\netsh.exe' interface ip set dns name="Local Area Connection" static 8.8.8.8 primary
- '%WINDIR%\syswow64\netsh.exe' interface ip add dns name="Local Area Connection" addr=8.8.4.4 index=2
- '%WINDIR%\syswow64\netsh.exe' interface ip set dns name="Ethernet" static 8.8.8.8 primary
- '%WINDIR%\syswow64\netsh.exe' interface ip add dns name="Ethernet" addr=8.8.4.4 index=2