Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Services Data' = '%TEMP%\Crypted.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'Windows Services Data' = '%TEMP%\Crypted.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Services Data' = '%TEMP%\wcsydrv.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'Windows Services Data' = '%TEMP%\wcsydrv.exe'
- %TEMP%\crypted.exe
- %TEMP%\wcsydrv.exe
- %TEMP%\wcsydrv.exe
- %TEMP%\crypted.exe
- '%TEMP%\crypted.exe'
- '%TEMP%\wcsydrv.exe' a
- '%WINDIR%\syswow64\cmd.exe' /c del %TEMP%\Crypted.exe > nul' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c del %TEMP%\Crypted.exe > nul