Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'qopyh' = '%APPDATA%\SubFolder\jopyhr\qopyh.exe'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'qopyh' = '%APPDATA%\SubFolder\jopyhr\qopyh.exe'
- qopyh.exe
- %APPDATA%\gfghffnoybbksghfhkjhgvjtfjgkgkgkvvfgsthsgfzdsgathstafdaafgar.bat
- %APPDATA%\gfghffnoybbksghfhkjhgvjtfjgkgkgkvvfgsthsgfzdsgathstafdaafgar.sfx.exe
- %APPDATA%\gfghffnoybbksghfhkjhgvjtfjgkgkgkvvfgsthsgfzdsgathstafdaafgar.exe
- %APPDATA%\subfolder\jopyhr\qopyh.exe
- ClassName: 'EDIT' WindowName: ''
- '%APPDATA%\gfghffnoybbksghfhkjhgvjtfjgkgkgkvvfgsthsgfzdsgathstafdaafgar.sfx.exe' -pTf343546556jffgvhgjgVFJhdmgckffiljkklgkgy7gJHGvkftffvgvjYFTFVVJfvtyghsejgkvmhjdcfhgngkjkggvyfgfztjgkvmhjdcfhgngkjkggvVFJTf343546556jffgvhgjghdmgckffiljkklgkgy7gttshgbzfsjyjthrgery5rthfaehthfd...
- '%APPDATA%\gfghffnoybbksghfhkjhgvjtfjgkgkgkvvfgsthsgfzdsgathstafdaafgar.exe'
- '%APPDATA%\subfolder\jopyhr\qopyh.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\GfghffnoybbksghfhkjhGvJtfjgkgkgKvvfgsthsgfzdsgathstafdaafgar.bat" "