Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{6I32E8RDFLMJGDFJG5-FFFFFFK2KAF-FF2F1R2-53D6-HFFWCSID5PA1A}' = '%APPDATA%\{BUD5CA7U-FFFFFKFDLGJDKFJGLDFKJGLDKFJGLKDFJGJKGSDHSIDUFH56S56DF...
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{I1P6ERFJ-1277-Y60D-4722-Y342F44RIAW6}] 'StubPath' = '%APPDATA%\{BUD5CA7U-FFFFFKFDLGJDKFJGLDFKJGLDKFJGLKDFJGJKGSDHSIDUFH56S56DF4SFFP...
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '{FLMDKGJDFJGDFKJGG3OPFR0DDDDDD34F-88F3F-IFFCFFM-FFFFFFFFU5JC-R72BH3RP3HKI}' = '%APPDATA%\{BUD5CA7U-FFFFFKFDLGJDKFJGLDFKJGLDKFJGLKDFJGJKGS...
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] '{2UHGJ1J3-N4W1-UU8VJ-MO53-FIDLFKGJDFLKJFGDKFGAGFFFFFFF8D400CO22}' = '%APPDATA%\{BUD5CA7U-FFFFFKFDLGJDKFJGLDFKJGLDKFJGLK...
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] '{2UHGJ1J3-N4W1-UU8VJ-MO53-FIDLFKGJDFLKJFGDKFGAGFFFFFFF8D400CO22}' = '%APPDATA%\{BUD5CA7U-FFFFFKFDLGJDKFJGLDFKJGLDKFJGLK...
- '%APPDATA%\{BUD5CA7U-FFFFFKFDLGJDKFJGLDFKJGLDKFJGLKDFJGJKGSDHSIDUFH56S56DF4SFFP2B8-0I8A-7R12-0F736LFN6dD3Q0ST}\IOCWS.EXE'
- %WINDIR%\Explorer.EXE
- %TEMP%\XX--XX--XX.txt
- %APPDATA%\{BUD5CA7U-FFFFFKFDLGJDKFJGLDFKJGLDKFJGLKDFJGJKGSDHSIDUFH56S56DF4SFFP2B8-0I8A-7R12-0F736LFN6dD3Q0ST}\IOCWS.EXE
- ClassName: 'Shell_TrayWnd' WindowName: ''