Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = '"%APPDATA%\mAatghh92HD0aqhr\brfTqKR2ZxPy.exe",explorer.exe'
- CasinoHack.exe
- %TEMP%\Casino.exe
- %TEMP%\CasinoHack.exe
- %TEMP%\V4.exe
- %APPDATA%\mAatghh92HD0aqhr\brfTqKR2ZxPy.exe
- %APPDATA%\mAatghh92HD0aqhr\brfTqKR2ZxPy.exe
- '%TEMP%\Casino.exe'
- '%TEMP%\CasinoHack.exe'
- '%TEMP%\V4.exe'