Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\360TimeProt] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\360TimeProt] 'ImagePath' = '<DRIVERS>\360TimeProt.sys'
- '360TimeProt' <SYSTEM32>\\drivers\360TimeProt.sys
- C:\temp\360timeprot.exe
- C:\temp\svchost.exe
- C:\temp\config.ini
- %TEMP%\e_4\krnln.fnr
- %TEMP%\e_4\shell.fne
- %WINDIR%\syswow64\drivers\360timeprot.sys
- %WINDIR%\syswow64\drivers\360timeprot.sys
- %WINDIR%\syswow64\drivers\360timeprot.sys
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'progman' WindowName: ''
- ClassName: 'MySrv' WindowName: ''
- 'C:\temp\svchost.exe'
- 'C:\temp\360timeprot.exe' /s