Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'authy' = '%PROGRAMDATA%\AuthyFiles\write.exe'
- '%PROGRAMDATA%\authyfiles\write.exe'
- %TEMP%\1.a
- %PROGRAMDATA%\authyfiles\write.exe
- %PROGRAMDATA%\authyfiles\propsys.dll
- %PROGRAMDATA%\authyfiles\7xuem5m.tmp
- %PROGRAMDATA%\authyfiles\write.exe.config
- %TEMP%\1.a
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding