Technical Information
- [HKLM\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%TEMP%\msdencnqpuws.sys'
- 'WinRing0_1_2_0' %TEMP%\msdencnqpuws.sys
- %WINDIR%\explorer.exe
- %TEMP%\msdencnqpuws.sys
- 'po##.#ashvault.pro':80
- 'po##.#ashvault.pro':80
- DNS ASK po##.#ashvault.pro
- '%WINDIR%\explorer.exe'