Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\360svc] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\360svc] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- [<HKLM>\system\cURRENTcONTROLsET\sERVICES\360svc\Parameters] 'ServiceDll' = 'C:\Documents and Settings\Local User\ntuser.dll'
- '360svc' <SYSTEM32>\svchost.exe -k netsvcs
- C:\documents and settings\local user\ntuser.dll
- 'we####.meibu.com':1900
- DNS ASK we####.meibu.com
- '%WINDIR%\syswow64\svchost.exe' -k netsvcs