Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'LiqqiGmita' = 'regsvr32.exe "%ALLUSERSPROFILE%\Application Data\LiqqiGmita\DontAtku.elv"'
- '<SYSTEM32>\regsvr32.exe' "%TEMP%\\~0002A761.tmp"
- <SYSTEM32>\cscript.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2500' = '00000003'
- %ALLUSERSPROFILE%\Application Data\LiqqiGmita\DontAtku.elv
- %TEMP%\~0002A761.tmp
- ClassName: 'dW0U' WindowName: 'Ss7BYe'
- ClassName: '' WindowName: 'JnFSMl6Q'