Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,<SYSTEM32>\nvsvo32.exe'
- <SYSTEM32>\nvsvo32.exe
- 'sm#####57.us7.hap02.com':80
- sm#####57.us7.hap02.com/index/opening.asp
- DNS ASK sm#####57.us7.hap02.com