Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\NtmsSvc] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\6to4] 'Start' = '00000002'
- '%WINDIR%\regedit.exe'
- <SYSTEM32>\NtmsSvc32.dll
- %WINDIR%\Offline Web Pages\cache.txt
- <SYSTEM32>\Sens32.dll
- %WINDIR%\clb.dll
- %WINDIR%\Temp\ntshrui.dll
- %WINDIR%\Offline Web Pages\cache.txt
- %WINDIR%\clb.dll
- %WINDIR%\Temp\ntshrui.dll
- DNS ASK do#.##zgwq.co.cc
- DNS ASK do#.#izgwq.com
- ClassName: 'Q360SafeMainClass' WindowName: '(null)'
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '' WindowName: 'Run'