Техническая информация
- [<HKLM>\SYSTEM\CurrentControlSet\Control\SecurityProviders] 'SecurityProviders' = 'credssp.dll, msimg64.dll'
- %TEMP%\~er7bf8.tmp
- <SYSTEM32>\msimg64.dll
- %TEMP%\~er7bf8.tmp
- http://www.google.com/
- DNS ASK google.com
- ClassName: 'Static' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c takeown /f "<SYSTEM32>\msimg64.dll" && icacls "<SYSTEM32>\msimg64.dll" /grant administrators:F' (со скрытым окном)
- '%ProgramFiles%\internet explorer\iexplore.exe' www.google.com' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c takeown /f "<SYSTEM32>\msimg64.dll" && icacls "<SYSTEM32>\msimg64.dll" /grant administrators:F
- '%ProgramFiles%\internet explorer\iexplore.exe' www.google.com
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\msimg64.dll"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\msimg64.dll" /grant administrators:F