Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '1e6f17d9' = '<SYSTEM32>\regsvr32.exe %APPDATA%\1e6f17d9.dll'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '1e6f17d' = '<SYSTEM32>\regsvr32.exe C:\1e6f17d9\1e6f17d9.dll'
- '%WINDIR%\explorer.exe'
- %WINDIR%\explorer.exe
- %APPDATA%\1e6f17d9.dll
- C:\1e6f17d9\1e6f17d9.dll
- ClassName: 'Indicator' WindowName: ''