Техническая информация
- [<HKLM>\SYSTEM\ControlSet003\Services\ysbhgt] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet002\Services\ysbhgt] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\ysbhgt] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k ysbhgt
- <SYSTEM32>\hkplnm.dll
- <SYSTEM32>\00061dca.sys
- '5a##.8866.org':1080
- DNS ASK 5a##.8866.org