Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'bhVA4JGYZXGzX' = '%ALLUSERSPROFILE%\Z0D2M4nN8\lJYuFjwcdbDQoPUB.exe'
- %ALLUSERSPROFILE%\Z0D2M4nN8\lJYuFjwcdbDQoPUB.exe
- %TEMP%\qI2Sur5IBGxeS.exe
- %ALLUSERSPROFILE%\Z0D2M4nN8\RCX1.tmp
- %ALLUSERSPROFILE%\Z0D2M4nN8\lJYuFjwcdbDQoPUB.exe
- %TEMP%\qI2Sur5IBGxeS.exe
- %ALLUSERSPROFILE%\Z0D2M4nN8\lJYuFjwcdbDQoPUB.exe
- ClassName: 'Indicator' WindowName: ''