Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Hcq83fL0fkxTfP5' = '%ALLUSERSPROFILE%\S4bo3ARFaPpa\6k91AVBLg8JC.exe'
- %ALLUSERSPROFILE%\S4bo3ARFaPpa\6k91AVBLg8JC.exe
- %TEMP%\vaC1ewCcmj.exe
- %ALLUSERSPROFILE%\S4bo3ARFaPpa\RCX1.tmp
- %ALLUSERSPROFILE%\S4bo3ARFaPpa\6k91AVBLg8JC.exe
- %TEMP%\vaC1ewCcmj.exe
- %ALLUSERSPROFILE%\S4bo3ARFaPpa\6k91AVBLg8JC.exe
- ClassName: 'Indicator' WindowName: ''