Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\WCYC2ManConn] 'Start' = '00000002'
- <SYSTEM32>\WinC2yc32.exe
- %PROGRAM_FILES%\CFёЯЧЛМ¬ёЁЦъНш°ЙјТНҐНЁУГНёКУ°ж0.exe
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\WinC2yc32.exe
- %PROGRAM_FILES%\CFёЯЧЛМ¬ёЁЦъНш°ЙјТНҐНЁУГНёКУ°ж0.exe
- %TEMP%\CFёЯЧЛМ¬ёЁЦъНш°ЙјТНҐНЁУГНёКУ°ж041.exe
- %PROGRAM_FILES%\CFёЯЧЛМ¬ёЁЦъНш°ЙјТНҐНЁУГНёКУ°ж0.exe
- 'go####.dbbog.com':8090
- DNS ASK go####.dbbog.com
- ClassName: 'Shell_TrayWnd' WindowName: ''