Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '96ED8AD4.exe' = '%APPDATA%\96ED8AD4.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Firefox' = '%TEMP%\Firefox.exe'
- %APPDATA%\96ED8AD4.exe
- <SYSTEM32>\cmd.exe /c ""%TEMP%\Rc4kikQ.bat" "
- <SYSTEM32>\alg.exe
- %TEMP%\Firefox.exe
- %APPDATA%\96ED8AD4.exe
- %TEMP%\Rc4kikQ.bat
- ClassName: 'Indicator' WindowName: ''