Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '234191879023221' = '%WINDIR%\1896135161\3437229804_.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '234191879023221' = '%WINDIR%\1896135161\3437229804_.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%WINDIR%\1896135161\3437229804_.exe' = '%WINDIR%\1896135161\3437229804...
- %WINDIR%\1896135161\3437229804_.exe
- %WINDIR%\1896135161\3437229804_.exe
- '%WINDIR%\1896135161\3437229804_.exe'