Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'zFB4rM3hsM3T' = '%ALLUSERSPROFILE%\dBntKeFQl\4WUx9UKsFtx1FRD.exe'
- %ALLUSERSPROFILE%\dBntKeFQl\4WUx9UKsFtx1FRD.exe
- %TEMP%\NT0Wu84G.exe
- %ALLUSERSPROFILE%\dBntKeFQl\RCX1.tmp
- %ALLUSERSPROFILE%\dBntKeFQl\4WUx9UKsFtx1FRD.exe
- %TEMP%\NT0Wu84G.exe
- %ALLUSERSPROFILE%\dBntKeFQl\4WUx9UKsFtx1FRD.exe
- ClassName: 'Indicator' WindowName: ''