Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'ejzgg' = '%TEMP%\ejzgg\13282.vbs'
- '%TEMP%\ejzgg\svchost.VzvowSYrEe' QsdnjE.EGU
- '<SYSTEM32>\taskkill.exe' /IM mshta.exe
- '<SYSTEM32>\mshta.exe'
- '<SYSTEM32>\wscript.exe' "%TEMP%\ejzgg\jkqOnPcAhE.vbs"
- %TEMP%\ejzgg\kGqZHe.OVD
- %TEMP%\ejzgg\76157.cmd
- %TEMP%\ejzgg\13282.vbs
- %TEMP%\ejzgg\QsdnjE.EGU
- %TEMP%\ejzgg\MjurCJ.MHJ
- %TEMP%\ejzgg\svchost.VzvowSYrEe
- %TEMP%\ejzgg\jkqOnPcAhE.vbs
- %TEMP%\ejzgg\kGqZHe.OVD
- %TEMP%\ejzgg\13282.vbs
- %TEMP%\ejzgg\76157.cmd
- %TEMP%\ejzgg\QsdnjE.EGU
- %TEMP%\ejzgg\MjurCJ.MHJ
- %TEMP%\ejzgg\svchost.VzvowSYrEe
- %TEMP%\ejzgg\jkqOnPcAhE.vbs
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'