Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '5kMEir5Iva' = '%ALLUSERSPROFILE%\yQ0kBjVDel\AHXFM6gyzy8l5G.exe'
- %ALLUSERSPROFILE%\yQ0kBjVDel\AHXFM6gyzy8l5G.exe
- %TEMP%\tmeYIL5IWqowmW.exe
- %ALLUSERSPROFILE%\yQ0kBjVDel\RCX1.tmp
- %ALLUSERSPROFILE%\yQ0kBjVDel\AHXFM6gyzy8l5G.exe
- %TEMP%\tmeYIL5IWqowmW.exe
- %ALLUSERSPROFILE%\yQ0kBjVDel\AHXFM6gyzy8l5G.exe
- ClassName: 'Indicator' WindowName: ''