Техническая информация
- [HKLM\System\CurrentControlSet\Services\PYArkService] 'ImagePath' = '<DRIVERS>\PYArkSafe.sys'
- 'PYArkService' <DRIVERS>\PYArkSafe.sys
- [HKLM\System\CurrentControlSet\Services\PYArkService] 'Group' = 'FSFilter Activity Monitor'
- <DRIVERS>\pyarksafe.sys
- %WINDIR%\temp\uddb6b1.tmp
- %WINDIR%\pyark.log
- %WINDIR%\temp\uddb6b1.tmp
- <DRIVERS>\pyarksafe.sys
- 'py##fe.cn':80
- http://py##fe.cn//update.html
- http://py##fe.cn/update.html
- DNS ASK py##fe.cn