Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'xzLk5vNkBXHfFuVK' = '%ALLUSERSPROFILE%\C30AMNErPfh4rb0\Ad2NqmddlruOi4V.exe'
- %ALLUSERSPROFILE%\C30AMNErPfh4rb0\Ad2NqmddlruOi4V.exe
- %TEMP%\EDUnRKg4H4QEHyg.exe
- %ALLUSERSPROFILE%\C30AMNErPfh4rb0\RCX1.tmp
- %ALLUSERSPROFILE%\C30AMNErPfh4rb0\Ad2NqmddlruOi4V.exe
- %TEMP%\EDUnRKg4H4QEHyg.exe
- %ALLUSERSPROFILE%\C30AMNErPfh4rb0\Ad2NqmddlruOi4V.exe
- ClassName: 'Indicator' WindowName: ''