Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'OeKseZujMM' = '"%TEMP%\tempfile.exe"'
- process32.exe
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: 'gdkWindowToplevel', WindowName: ''
- %TEMP%\process32.exe
- %TEMP%\tempfile.exe
- %APPDATA%\chrtmp
- '%TEMP%\process32.exe'