Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,<SYSTEM32>\nvsv032.exe'
- <SYSTEM32>\nvsv032.exe
- 'sm#####.usa100.toadmin.com':80
- sm#####.usa100.toadmin.com/index/opening.asp
- DNS ASK sm#####.usa100.toadmin.com