Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\chaleao.exe
- %TEMP%\71bfea85ebeba2ed4409a76cb38b8f3336847440.png
- ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''
- '%HOMEPATH%\Start Menu\Programs\Startup\chaleao.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %TEMP%\71bfea85ebeba2ed4409a76cb38b8f3336847440.png
- '<SYSTEM32>\cmd.exe' /c %TEMP%\71bfea85ebeba2ed4409a76cb38b8f3336847440.png