Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'NgOgM0pxImcL' = '%ALLUSERSPROFILE%\HCQYvh1WLIAUKc\rHD4OKIO1RfwBnqk.exe'
- %ALLUSERSPROFILE%\HCQYvh1WLIAUKc\rHD4OKIO1RfwBnqk.exe
- %TEMP%\7VTvLWG1rDuu.exe
- %ALLUSERSPROFILE%\HCQYvh1WLIAUKc\RCX1.tmp
- %ALLUSERSPROFILE%\HCQYvh1WLIAUKc\rHD4OKIO1RfwBnqk.exe
- %TEMP%\7VTvLWG1rDuu.exe
- %ALLUSERSPROFILE%\HCQYvh1WLIAUKc\rHD4OKIO1RfwBnqk.exe
- ClassName: 'Indicator' WindowName: ''