Техническая информация
- [<HKCU>\Software\Microsoft\Windows\Currentversion\Policies\Explorer] 'NoLogOff' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\Currentversion\Policies\Explorer] 'NoRun' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\Currentversion\Policies\Explorer] 'NoDrives' = '03FFFFFF'
- %TEMP%\crypted.exe
- ClassName: '' WindowName: 'Windows Task Manager'
- ClassName: '#32770' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- '%TEMP%\crypted.exe'
- '%WINDIR%\syswow64\net.exe' user "user" "gargagrrrverawe3' (со скрытым окном)
- '%WINDIR%\syswow64\net.exe' user "user" "gargagrrrverawe3
- '%WINDIR%\syswow64\net1.exe' user "user" "gargagrrrverawe3
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowWarningDialog "%TEMP%\Crypted.exe"