Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'xB1vttQysgFNqZ' = '%ALLUSERSPROFILE%\CKcn8M8MSAy\ICfWaAnPgIi.exe'
- %ALLUSERSPROFILE%\CKcn8M8MSAy\ICfWaAnPgIi.exe
- %TEMP%\WLiF1tLsHzw.exe
- %ALLUSERSPROFILE%\CKcn8M8MSAy\RCX1.tmp
- %ALLUSERSPROFILE%\CKcn8M8MSAy\ICfWaAnPgIi.exe
- %TEMP%\WLiF1tLsHzw.exe
- %ALLUSERSPROFILE%\CKcn8M8MSAy\ICfWaAnPgIi.exe
- ClassName: 'Indicator' WindowName: ''