Техническая информация
- '%WINDIR%\syswow64\taskkill.exe' /f /im uu.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im uu_ball.exe
- C:\onerun.bat
- 'no##.youdao.com':443
- DNS ASK no##.youdao.com
- ClassName: '' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c C:\onerun.bat' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c C:\onerun.bat
- '%WINDIR%\syswow64\reg.exe' delete HKEY_CURRENT_USER\Software\Netease /f
- '%WINDIR%\syswow64\reg.exe' delete HKEY_CURRENT_USER\Software\Netease\NeteaseGacc /f
- '%WINDIR%\syswow64\reg.exe' delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Netease /f
- '%WINDIR%\syswow64\reg.exe' delete HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Netease\NeteaseGacc /f