Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Nationalcqs] 'Start' = '00000002'
- '<SYSTEM32>\lyxrym.exe'
- 'C:\Бпё®°н2.exe'
- 'C:\Server.exe'
- <SYSTEM32>\lyxrym.exe
- C:\Бпё®°н2.exe
- C:\Server.exe
- C:\Server.exe
- 'dy####995.codns.com':1004
- DNS ASK dy####995.codns.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '__GH_Sudden_Attack__' WindowName: 'SuddenAttack'