Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Lupita.exe' = '<LS_APPDATA>\Lupita\Lupita.exe'
- [<HKCU>\Software\Microsoft\MessengerService]
- <LS_APPDATA>\Lupita\Lupita.exe
- 'www.ih###spoir.be':80
- 'www.hw##it.com':80
- 'www.gr####-cogit.com':80
- 'www.hi####alhas.com.br':80
- 'www.ho###ilm.info':80
- 'h1######.stratoserver.net':80
- www.ih###spoir.be/espoir/wii.php
- www.hw##it.com/modules/wii.php
- www.gr####-cogit.com/gosier//images/people/wii.php
- www.hi####alhas.com.br/img_site/addo.php
- www.ho###ilm.info/features/addo.php
- h1######.stratoserver.net/wework/js/addo.php
- DNS ASK www.ih###spoir.be
- DNS ASK www.hw##it.com
- DNS ASK www.gr####-cogit.com
- DNS ASK h1######.stratoserver.net
- DNS ASK www.hi####alhas.com.br
- DNS ASK www.ho###ilm.info
- '<IP-адрес в локальной сети>':1036
- ClassName: 'Internet Explorer_Server' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Frame Tab' WindowName: ''
- ClassName: 'TabWindowClass' WindowName: ''
- ClassName: 'Shell DocObject View' WindowName: ''