[KeyLogger] GSI.exe
* C:\ProgramData\OIXNJF
GSI.exe - c10b5fbfd0c1672f3cd84fc5c2454e1063c47ebe
* delete reg value
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | GSI Start
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | GSI Start
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run | IUG Start
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | IUG Start
|
|