Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\HWiNFO32] 'Start' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\HWiNFO32] 'ImagePath' = '%WINDIR%\SysWOW64\drivers\HWiNFO64A.SYS'
- %TEMP%\nsza73a.tmp\userinfo.dll
- %APPDATA%\ximea\controlpanel\tools\hwinfo32.dll
- %APPDATA%\ximea\controlpanel\tools\hwinfo32.sys
- %APPDATA%\ximea\controlpanel\tools\hwinfo64a.sys
- %APPDATA%\ximea\controlpanel\tools\hwinfo64i.sys
- %APPDATA%\ximea\controlpanel\tools\hwinfo32.dat
- %APPDATA%\ximea\controlpanel\xicontrolpanel.exe
- %APPDATA%\ximea\controlpanel\xiapi32.dll
- %APPDATA%\ximea\controlpanel\libusb_u3v.dll
- %WINDIR%\syswow64\drivers\hwinfo64a.sys
- %WINDIR%\temp\uddbb7d.tmp
- %APPDATA%\ximea\controlpanel\temp\hw_arch.xml
- %APPDATA%\ximea\controlpanel\temp\fw_info.xml
- %APPDATA%\ximea\controlpanel\temp\sw_info.xml
- %TEMP%\nsza73a.tmp\userinfo.dll
- %WINDIR%\temp\uddbb7d.tmp
- http://up####s.ximea.com/upd/get?ac###################################
- DNS ASK up####s.ximea.com
- '%APPDATA%\ximea\controlpanel\xicontrolpanel.exe'