Техническая информация
- ClassName: 'OLLYDBG', WindowName: ''
- %TEMP%\{32365178-f29d-4c2f-9354-d5ce35675126}.ssk
- C:\xbghost\download\xlbugreport.exe
- C:\xbghost\download\xlbughandler.dll
- C:\xbghost\download\msvcr71.dll
- C:\xbghost\download\msvcp71.dll
- %HOMEPATH%\desktop\ð¡°×ò»¼üöø×°ïµГВі.lnk
- C:\xbghost\download\minizip.dll
- C:\xbghost\download\zlib1.dll
- C:\xbghost\download\minithunderplatform.exe
- C:\xbghost\download\id.dat
- C:\xbghost\download\download_engine.dll
- C:\xbghost\download\dl_peer_id.dll
- C:\xbghost\download\atl71.dll
- C:\xbghost\xldl.dll
- %TEMP%\{d7faf530-1235-4fef-903c-16ca88b2ee9c}
- C:\xbghost\dsptw.dll
- D:\xbghost\xbghostset.txt
- C:\xbghost\dsptw.dll
- %TEMP%\{d7faf530-1235-4fef-903c-16ca88b2ee9c}
- %TEMP%\{32365178-f29d-4c2f-9354-d5ce35675126}.ssk
- http://www.ba####xitong.com/xiaobai/cfgfs.txt
- http://www.xi####ixitong.com/installcount.api.php?so#######################################################################
- DNS ASK ba####xitong.com
- DNS ASK xi####ixitong.com
- DNS ASK so#####.xiaobaixitong.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- 'C:\xbghost\dsptw.dll' /A /PDR /Y
- '%WINDIR%\syswow64\cmd.exe' /C C:\XBGhost\dsptw.dll /A /PDR /Y' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C C:\XBGhost\dsptw.dll /A /PDR /Y