Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\doshow_2008] 'Start' = '00000002'
- %PROGRAM_FILES%\doshow\doshow
- <SYSTEM32>\cmd.exe /c %TEMP%\PQESWB.bat
- %TEMP%\PQESWB.bat
- %PROGRAM_FILES%\doshow\doshow
- %PROGRAM_FILES%\doshow\doshow
- '55###.rhelper.com':8088
- DNS ASK 55###.rhelper.com
- ClassName: 'Shell_TrayWnd' WindowName: ''