Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'setup' = '<SYSTEM32>\ctfmom2.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{CED8E294-9BB8-E766-93C7-9C08E66AD7F4}] 'StubPath' = '<SYSTEM32>\ctfmom2.exe'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\ctfmom2.exe
- 'yi#####006win.3322.org':3460
- DNS ASK yi#####006win.3322.org