Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'BVNSEUHJ' = 'C:\ProgramData\gotham.exe'
- '<SYSTEM32>\attrib.exe' +s +h "C:\ProgramData\gotham.exe"
- '<SYSTEM32>\attrib.exe' +s -h "%APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FFPXOMEV.exe"
- C:\ProgramData\gotham.exe
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FFPXOMEV.exe
- C:\ProgramData\gotham.exe
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FFPXOMEV.exe
- ClassName: 'Indicator' WindowName: ''