Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Debugger' = 'C:\debugger.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Debugger' = 'C:\debugger.exe'
- <SYSTEM32>\taskkill.exe /F /IM cmd.exe
- <SYSTEM32>\taskkill.exe /F /IM regedit.exe
- <SYSTEM32>\reg.exe add "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Debugger" /t "REG_SZ" /d "C:\debugger.exe" /f
- <SYSTEM32>\reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Debugger" /t "REG_SZ" /d "C:\debugger.exe" /f
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- ClassName: '#32770' WindowName: ''