Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'xO6rHmq7' = '%ALLUSERSPROFILE%\Yatc7zMEv\gq1RVA3SNmcGqL.exe'
- %ALLUSERSPROFILE%\Yatc7zMEv\gq1RVA3SNmcGqL.exe
- %TEMP%\FiYrcFGZ6.exe
- %ALLUSERSPROFILE%\Yatc7zMEv\RCX1.tmp
- %ALLUSERSPROFILE%\Yatc7zMEv\gq1RVA3SNmcGqL.exe
- %TEMP%\FiYrcFGZ6.exe
- %ALLUSERSPROFILE%\Yatc7zMEv\gq1RVA3SNmcGqL.exe
- ClassName: 'Indicator' WindowName: ''