Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\bgJAIFNMRLXO.lnk
- '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe'
- '%APPDATA%\LYDB.exe' "%APPDATA%\RKVdY.au3"
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
- %APPDATA%\RKVdY.au3
- %APPDATA%\LYDB.exe
- %HOMEPATH%\7kYlSh1cFhXLByD1\RKVdY.au3
- %HOMEPATH%\7kYlSh1cFhXLByD1\LYDB.exe
- %APPDATA%\LYDB.exe в %HOMEPATH%\7kYlSh1cFhXLByD1\LYDB.exe
- %APPDATA%\RKVdY.au3 в %HOMEPATH%\7kYlSh1cFhXLByD1\RKVdY.au3
- '46.#0.33.71':19555
- ClassName: 'Shell_TrayWnd' WindowName: ''