Техническая информация
- <SYSTEM32>\winlobb.exe
- <SYSTEM32>\winlomm.exe
- <SYSTEM32>\syst.exe
- <SYSTEM32>\csrsss.exe
- <SYSTEM32>\winlobb.exe (загружен из сети Интернет)
- <SYSTEM32>\winlomm.exe (загружен из сети Интернет)
- <SYSTEM32>\csrsss.exe (загружен из сети Интернет)
- <SYSTEM32>\syst.exe (загружен из сети Интернет)
- ClassName: '' WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS' WindowName: ''
- ClassName: '' WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass' WindowName: ''
- ClassName: '' WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'GBDYLLO' WindowName: ''
- ClassName: 'OLLYDBG' WindowName: ''
- ClassName: 'FilemonClass' WindowName: ''
- ClassName: 'pediy06' WindowName: ''
- <SYSTEM32>\winlomm.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\Msnloge[1].png
- <SYSTEM32>\winlobb.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\Msnsend[1].png
- <SYSTEM32>\csrsss.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\HUNTER[1].png
- <SYSTEM32>\syst.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\drbplg[1].png
- 'ju######stoll.hpg.com.br':80
- 'localhost':1035
- ju######stoll.hpg.com.br/Msnloge.png
- ju######stoll.hpg.com.br/Msnsend.png
- ju######stoll.hpg.com.br/HUNTER.png
- ju######stoll.hpg.com.br/drbplg.png
- DNS ASK ju######stoll.hpg.com.br
- ClassName: '18467-41' WindowName: ''