Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'XpMoniter_INFO' = '"<SYSTEM32>\XpMoniter.exe" /run'
- <SYSTEM32>\XpMoniter.exe
- <SYSTEM32>\rundll32.exe <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %HOMEPATH%\Templates\јєГЯЗа.JPG
- <SYSTEM32>\XpMoniter.exe
- %HOMEPATH%\Recent\јєГЯЗа.lnk
- <SYSTEM32>\update.ini
- %HOMEPATH%\Recent\Templates.lnk
- %HOMEPATH%\Templates\јєГЯЗа.JPG
- <SYSTEM32>\MSAgent.exe
- <SYSTEM32>\XpMoniter.exe
- <SYSTEM32>\mfc42dbg.dll
- <SYSTEM32>\windrv.dat
- 'ha#####00.cafe24.com':80
- ha#####00.cafe24.com/aa/10/update.ini
- DNS ASK ha#####00.cafe24.com
- '<IP-адрес в локальной сети>':1035
- ClassName: 'MG2GFX' WindowName: '?????? ????'
- ClassName: '' WindowName: '???? ??????????'
- ClassName: 'Afx:00400000:b' WindowName: '?????? 7????'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Afx:00400000:b' WindowName: '?????? ??????????'
- ClassName: 'TFmMSAgent' WindowName: '___'
- ClassName: 'TFmMoniter' WindowName: '___'
- ClassName: 'Afx:00400000:b' WindowName: '?????? ??????'
- ClassName: 'Afx:00400000:b' WindowName: '????????2'
- ClassName: 'Afx:00400000:b' WindowName: '?????? ?????????? ????'