Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\WinHjyo32] 'Start' = '00000002'
- '<SYSTEM32>\WinHksgd32.exe'
- '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\svchost.exe
- ClassName: 'OLLYDBG' WindowName: '(null)'
- ClassName: 'FileMonClass' WindowName: '(null)'
- <SYSTEM32>\WinHksgd32.exe
- <SYSTEM32>\WinHksgd32.exe
- 'any':3971
- 'qw#.###hishubiao.com':3971
- DNS ASK qw#.###hishubiao.com
- ClassName: '18467-41' WindowName: '(null)'