Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'uwininlt' = '%ProgramFiles%\Windows Sidebar\wininlt\uwininlt.exe'
- ClassName: 'OLLYDBG', WindowName: ''
- ClassName: 'GBDYLLO', WindowName: ''
- ClassName: 'pediy06', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- 'localhost':1036
- 'co####r.wininlt.com':80
- 'go###e.co.kr':80
- 'up####.wininlt.com':80
- 'dd###.wininlt.com':80
- http://co####r.wininlt.com/analysis/live.php?uq##########
- http://www.go###e.co.kr/ via go###e.co.kr
- http://up####.wininlt.com/uwininlt.ts3
- http://up####.wininlt.com/uwininlt.ts2
- http://dd###.wininlt.com/sum.xml
- DNS ASK co####r.wininlt.com
- DNS ASK www.go###e.co.kr
- DNS ASK up####.wininlt.com
- DNS ASK dd###.wininlt.com
- ClassName: '18467-41' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''