Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'LiqqiGmita' = 'regsvr32.exe "%ALLUSERSPROFILE%\Application Data\LiqqiGmita\DontAtku.elv"'
- '<SYSTEM32>\regsvr32.exe' "%TEMP%\\~00022188.tmp"
- %WINDIR%\Explorer.EXE
- %ALLUSERSPROFILE%\Application Data\LiqqiGmita\DontAtku.elv
- %TEMP%\~00022188.tmp
- ClassName: 'Indicator' WindowName: ''