Техническая информация
- [HKLM\System\CurrentControlSet\Services\D838f0Mh2] 'ImagePath' = '%WINDIR%\SysWOW64\D838f0Mh2.sys'
- [HKLM\System\CurrentControlSet\Services\D838f0Mh2] 'ImagePath' = '<SYSTEM32>\D838f0Mh2.sys'
- [HKLM\System\CurrentControlSet\Services\D838f0Mh2] 'Start' = '00000001'
- 'D838f0Mh2' %WINDIR%\SysWOW64\D838f0Mh2.sys
- %WINDIR%\syswow64\d838f0mh2.sys
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012024091120240912\index.dat
- 'localhost':80
- 'zh###.#0.upaiyun.com':80
- http://zh###.#0.upaiyun.com/up/zhuye.txt
- DNS ASK bu########uding.stor.sinaapp.com
- DNS ASK jy######do.stor.sinaapp.com
- DNS ASK ha####.943wg.com
- DNS ASK 52########dan000.stor.sinaapp.com
- DNS ASK ne####n.943wg.com
- DNS ASK zh###.#0.upaiyun.com
- DNS ASK cq#######11.stor.sinaapp.com
- DNS ASK my.##years.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''