Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Krnl.sys] 'ImagePath' = '%TEMP%\Krnl.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\Krnl.sys] 'Start' = '00000001'
- '<SYSTEM32>\regsvr32.exe' /s <SYSTEM32>\WebShield.dll
- '<SYSTEM32>\cmd.exe' /c "regsvr32 /s <SYSTEM32>\WebShield.dll"
- %TEMP%\Krnl.sys
- <SYSTEM32>\WebShield.dll
- %TEMP%\Krnl.sys
- ClassName: 'SHELLDLL_DefView' WindowName: ''
- ClassName: 'TfrmQQPop' WindowName: ''
- ClassName: 'TBottomForm' WindowName: ''
- ClassName: 'Progman' WindowName: ''