Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'g88jmlWi' = '%ALLUSERSPROFILE%\fRAANBDJ1ib\MaZc0auSTB1e0KW3.exe'
- %ALLUSERSPROFILE%\fRAANBDJ1ib\MaZc0auSTB1e0KW3.exe
- %ALLUSERSPROFILE%\fRAANBDJ1ib\RCX1.tmp
- %ALLUSERSPROFILE%\fRAANBDJ1ib\MaZc0auSTB1e0KW3.exe
- %ALLUSERSPROFILE%\fRAANBDJ1ib\MaZc0auSTB1e0KW3.exe
- %ALLUSERSPROFILE%\fRAANBDJ1ib\RCX1.tmp в %ALLUSERSPROFILE%\fRAANBDJ1ib\MaZc0auSTB1e0KW3.exe
- ClassName: 'Indicator' WindowName: ''