Техническая информация
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Load' = '<Полный путь к файлу>'
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Load' = '%ALLUSERSPROFILE%\WindowsApps\dasHost.exe'
- %ALLUSERSPROFILE%\windowsapps\dashost.exe
- 'ya###.csgoblock.com':80
- 'su####-smiles.com':80
- http://su####-smiles.com/
- DNS ASK ya###.csgoblock.com
- DNS ASK su####-smiles.com
- '%ALLUSERSPROFILE%\windowsapps\dashost.exe'