Техническая информация
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'BSOD' = '%TEMP%\69C8.tmp\pogromca xp.bat'
- %TEMP%\gg.exe
- %TEMP%\hasla.jpg
- %TEMP%\69c8.tmp\pogromca xp.bat
- nul
- %WINDIR%\win.ini
- %TEMP%\69c8.tmp\pogromca xp.bat
- '%TEMP%\gg.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\69C8.tmp\pogromca xp.bat""
- '%WINDIR%\syswow64\attrib.exe' -r -s -h c:\bootmgr
- '%WINDIR%\syswow64\attrib.exe' -r -s -h c:\BOOTSECT.BAK
- '%WINDIR%\syswow64\attrib.exe' -r -s -h c:\boot.ini
- '%WINDIR%\syswow64\attrib.exe' -r -s -h c:\ntldr
- '%WINDIR%\syswow64\attrib.exe' -r -s -h c:\Boot
- '%WINDIR%\syswow64\attrib.exe' -r -s -h %WINDIR%\win.ini
- '%WINDIR%\syswow64\reg.exe' Add "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v "BSOD" /t "REG_SZ" /d "%TEMP%\69C8.tmp\pogromca xp.bat" /f