Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'qISM4Gtp9' = '%ALLUSERSPROFILE%\HgdFJ6aWnyj\5A0Dt5JT.exe'
- %ALLUSERSPROFILE%\HgdFJ6aWnyj\5A0Dt5JT.exe
- %TEMP%\Zm9h5egTrb4LlKG.exe
- %ALLUSERSPROFILE%\HgdFJ6aWnyj\RCX1.tmp
- %ALLUSERSPROFILE%\HgdFJ6aWnyj\5A0Dt5JT.exe
- %TEMP%\Zm9h5egTrb4LlKG.exe
- %ALLUSERSPROFILE%\HgdFJ6aWnyj\5A0Dt5JT.exe
- ClassName: 'Indicator' WindowName: ''