Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'winassists' = '<SYSTEM32>\pcalua.exe -a %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\wiassistf.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\wiassistf.exe
- http://19#.#.118.121/2.exe как %appdata%\winassists.exe
- %TEMP%\abctfhghghghghВЈ.sct
- %PROGRAMDATA%\hrjytrj.cmd
- %APPDATA%\winassists.exe
- %APPDATA%\winassists.exe
- http://19#.#.118.121/2.exe
- '%APPDATA%\winassists.exe'
- '%WINDIR%\syswow64\cmd.exe' /c REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v winassists /t REG_SZ /d <SYSTEM32>\pcalua.exe" -a %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\wiassi...
- '%WINDIR%\syswow64\reg.exe' ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v winassists /t REG_SZ /d <SYSTEM32>\pcalua.exe" -a %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\wiassistf.exe...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Start-Process %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\wiassistf.exe