Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Terms.exe' = '%WINDIR%\GameLoadep.exe'
- ClassName: 'Regmonclass', WindowName: ''
- ClassName: 'Filemonclass', WindowName: ''
- %WINDIR%\gameloadep.exe
- 'sh###.weiyun.com':443
- '10#.#2.15.123':80
- '36.##1.172.221':8000
- 'sh###.weiyun.com':443
- DNS ASK sh###.weiyun.com
- ClassName: '4823-00000029' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- '%WINDIR%\gameloadep.exe'