Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'yrgit' = '%HOMEPATH%\yrgit\61516.vbs'
- '%HOMEPATH%\yrgit\jSWWW.exe' oWpqZfofzE
- '<SYSTEM32>\taskkill.exe' /IM mshta.exe
- '<SYSTEM32>\mshta.exe'
- %HOMEPATH%\yrgit\DAjLlgxREby.TIF
- %HOMEPATH%\yrgit\33611.cmd
- %HOMEPATH%\yrgit\61516.vbs
- %HOMEPATH%\yrgit\awzCEWRehd.EUH
- %HOMEPATH%\yrgit\jSWWW.exe
- %HOMEPATH%\yrgit\oWpqZfofzE
- %HOMEPATH%\yrgit\DAjLlgxREby.TIF
- %HOMEPATH%\yrgit\61516.vbs
- %HOMEPATH%\yrgit\33611.cmd
- %HOMEPATH%\yrgit\awzCEWRehd.EUH
- %HOMEPATH%\yrgit\jSWWW.exe
- %HOMEPATH%\yrgit\oWpqZfofzE
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'