Technical Information
- ClassName: 'FileMonClass', WindowName: ''
- ClassName: 'RegMonClass', WindowName: ''
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: 'PROCEXPL', WindowName: ''
- ClassName: 'gdkWindowToplevel', WindowName: 'The Wireshark Network Analyzer'
- %ALLUSERSPROFILE%\temp:e0ec633e
- %APPDATA%\microsoft\crypto\rsa\s-1-5-21-4226853953-3309226944-3078887307-1000\88603cb2913a7df3fbd16b5f958e6447_8cf7b530-613e-439b-a8c5-ccfc0e745400
- %TEMP%\ГіГ§ГГ Г© ñâîèõ ïîñèòèòåëåé!.exe
- %TEMP%\pse11\5d81f8d432ad5d48d4d7b4c8382e58ba\php.ini
- %TEMP%\pse11\php\php5ts.dll
- %TEMP%\pse11\php\modules\php_bcompiler.dll
- %TEMP%\pse11\php\modules\php_bz2.dll
- '15#.#01.65.91':443
- DNS ASK sp####ivai.hut4.ru
- '%TEMP%\ГіГ§ГГ Г© ñâîèõ ïîñèòèòåëåé!.exe'
- '%WINDIR%\syswow64\cmd.exe' /c del "<Full path to file>" >> NUL
- '%WINDIR%\syswow64\cmd.exe' /c del "<Full path to file>" >> NUL' (with hidden window)