It also creates a nemurimoto.exe and a weird .pif file in appdata/local/temp. So it was 3 files in my case. I've done full scans with malwarebytes and defender after that and didn't find anything else. But there is always a chance that it could've left some other files or altered existing ones. The anal tag was for the player I guess.
I'm wondering if anyone here has noticed strange log in attempts or changes in their social media, cuz so far it seems like we're more or less safe.
Giving you all the info, I got from ChatGPT and summarized by me.
So basically virustotal can't find any threats in .exe because the .exe is not a threat. It, though, creats a nemurimoto.exe in Temp directory that is a troyan downloader. That .pif file is a troyan/some sort of a stealer. It instantly steals all the chrome/edge/opera/brave etc. cash, cookies, saved password, compresses it as archive and sends to the guy. Basically, as I undrestood, if the .pif file got created - you are fucked.
So I changed all the main passwords - mail, banks, etc - from my laptop (only the PC got infected) and went to sleep. The next morning I saw a "new attempt to log-in to your mailbox". So I changed all the passwords. And after having another chat with ChatGPT - reinstalled the system.