Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Alphi' = '%TEMP%\Alphi.exe'
- '%WINDIR%\syswow64\taskkill.exe' /f /im explorer.exe
- %WINDIR%\explorer.exe
- %TEMP%\alphi.exe
- '15#.#01.65.91':443
- ClassName: 'CabinetWClass' WindowName: ''
- ClassName: 'Progman' WindowName: ''
- ClassName: '' WindowName: ''
- '%WINDIR%\syswow64\explorer.exe'