Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{6E7FA10F-561B-1D6C-93FF-2E426CE21F94}' = '%APPDATA%\{F26F893F-7E2B-817C-93FF-2E426CE21F94}\5fd059a0.exe'
- %WINDIR%\Tasks\{6E7FA10F-561B-1D6C-93FF-2E426CE21F94}.job
- <Имя диска съемного носителя>:\{465efbae-ba8c-483b-314e-aaaf24ffa11e}\38ba0056-1a5b-7248-7888-a72ae3a1a3eb.exe
- '<SYSTEM32>\svchost.exe'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\svchost.exe
- %APPDATA%\{F26F893F-7E2B-817C-93FF-2E426CE21F94}\5fd059a0.exe
- ClassName: 'Shell_TrayWnd' WindowName: ''