Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '0eZTY9AbOy3JkH' = '%ALLUSERSPROFILE%\jyn4yH4ii1s0Qf\SyJa8aq9HTnKJnR.exe'
- %ALLUSERSPROFILE%\jyn4yH4ii1s0Qf\SyJa8aq9HTnKJnR.exe
- %ALLUSERSPROFILE%\jyn4yH4ii1s0Qf\RCX1.tmp
- %ALLUSERSPROFILE%\jyn4yH4ii1s0Qf\SyJa8aq9HTnKJnR.exe
- %ALLUSERSPROFILE%\jyn4yH4ii1s0Qf\SyJa8aq9HTnKJnR.exe
- ClassName: 'Indicator' WindowName: ''