Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%WINDIR%\WinRing0x64.sys'
- 'WinRing0_1_2_0' %WINDIR%\WinRing0x64.sys
- %WINDIR%\avgrec.exe
- %WINDIR%\winring0x64.sys
- %WINDIR%\config.json
- 'hi##me.cyou':80
- 'sites.google.com':443
- 'lh#.####leusercontent.com':443
- 'xm##ool.eu':443
- http://www.hi##me.cyou/
- DNS ASK hi##me.cyou
- DNS ASK xm##ool.eu
- DNS ASK sites.google.com
- DNS ASK lh#.####leusercontent.com
- '%WINDIR%\avgrec.exe' ""