Техническая информация
- Средство контроля пользовательских учетных записей (UAC)
- '<SYSTEM32>\taskkill.exe' /IM cmd.exe /F
- <SYSTEM32>\cmd.exe
- %TEMP%\inpwdja.exe
- %TEMP%\mnrjvryib.exe
- %TEMP%\bde8.tmp\bde9.tmp\bdea.bat
- %TEMP%\be07.tmp\be08.tmp\be09.bat
- %TEMP%\bde8.tmp\bde9.tmp\bdea.bat
- %TEMP%\be07.tmp\be08.tmp\be09.bat
- ClassName: '' WindowName: ''
- '%TEMP%\inpwdja.exe'
- '%TEMP%\mnrjvryib.exe'
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\BDE8.tmp\BDE9.tmp\BDEA.bat %TEMP%\Mnrjvryib.exe"
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\BE07.tmp\BE08.tmp\BE09.bat %TEMP%\Inpwdja.exe"
- '<SYSTEM32>\cmd.exe' /k <SYSTEM32>\reg.exe ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f