Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'ImagePath' = '%WINDIR%\system_32.bat'
- %TEMP%\ixp000.tmp\vir.cmd
- %WINDIR%\y.reg
- %WINDIR%\system_32.bat
- %TEMP%\ixp000.tmp\vir.cmd
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\IXP000.TMP\vir.cmd' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\IXP000.TMP\vir.cmd
- '%WINDIR%\syswow64\reg.exe' import %WINDIR%\y.reg
- '%WINDIR%\syswow64\shutdown.exe' -r -f -t 0
- '%WINDIR%\syswow64\runonce.exe' /RunOnce6432
- '%WINDIR%\syswow64\rundll32.exe' <SYSTEM32>\advpack.dll,DelNodeRunDLL32 "%TEMP%\IXP000.TMP\"