Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'explorer.exe' = '%APPDATA%\CRNJEUFU\explorer.exe'
- '%APPDATA%\CRNJEUFU\explorer.exe'
- '%APPDATA%\CRNJEUFU\explorer.exe'
- '%TEMP%\7ZipSfx.001\QLTAOCWMLSEDCNQ.exe' -iKMRWHKUAXBMMKJNPHQ.QKG -jCFLCRFEHCLEYWVCXKD.PLR -kVLNCYXWUMASM.QHD -s"%APPDATA%\CRNJEUFU\explorer.exe"
- '%TEMP%\7ZipSfx.000\QLTAOCWMLSEDCNQ.exe' -iKMRWHKUAXBMMKJNPHQ.QKG -jCFLCRFEHCLEYWVCXKD.PLR -kVLNCYXWUMASM.QHD -s"<Полный путь к файлу>"
- %TEMP%\7ZipSfx.001\VLNCYXWUMASM.QHD
- %TEMP%\7ZipSfx.001\CFLCRFEHCLEYWVCXKD.PLR
- %TEMP%\7ZipSfx.001\QLTAOCWMLSEDCNQ.exe
- %TEMP%\7ZipSfx.001\KMRWHKUAXBMMKJNPHQ.QKG
- %APPDATA%\CRNJEUFU\explorer.exe
- %TEMP%\7ZipSfx.000\VLNCYXWUMASM.QHD
- %TEMP%\7ZipSfx.000\CFLCRFEHCLEYWVCXKD.PLR
- %TEMP%\7ZipSfx.000\QLTAOCWMLSEDCNQ.exe
- %TEMP%\7ZipSfx.000\KMRWHKUAXBMMKJNPHQ.QKG
- %APPDATA%\CRNJEUFU\explorer.exe
- %TEMP%\7ZipSfx.001\KMRWHKUAXBMMKJNPHQ.QKG
- %TEMP%\7ZipSfx.001\CFLCRFEHCLEYWVCXKD.PLR
- %TEMP%\7ZipSfx.001\VLNCYXWUMASM.QHD
- %TEMP%\7ZipSfx.001\QLTAOCWMLSEDCNQ.exe
- %TEMP%\7ZipSfx.000\KMRWHKUAXBMMKJNPHQ.QKG
- %TEMP%\7ZipSfx.000\CFLCRFEHCLEYWVCXKD.PLR
- %TEMP%\7ZipSfx.000\VLNCYXWUMASM.QHD
- %TEMP%\7ZipSfx.000\QLTAOCWMLSEDCNQ.exe