Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\runonce] 'Char' = '<SYSTEM32>\charity.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WINReG' = '<SYSTEM32>\charity.exe'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\Windows Firewall.lnk
- %ALLUSERSPROFILE%\drama\temp\bat.exe
- <SYSTEM32>\reg.exe add hkey_current_user\software\microsoft\windows\currentversion\runonce /v Char /t reg_sz /d <SYSTEM32>\charity.exe /f
- <SYSTEM32>\reg.exe add hkey_local_machine\software\microsoft\windows\currentversion\run /v WINReG /t reg_sz /d <SYSTEM32>\charity.exe /f
- <SYSTEM32>\cmd.exe /c ""%TEMP%\bat.bat" > NUL"
- %ALLUSERSPROFILE%\drama\temp\actmovie.$AA
- %TEMP%\bat.bat
- %ALLUSERSPROFILE%\drama\temp\bat.$$A
- %ALLUSERSPROFILE%\drama\temp\actmovie.$$A
- %ALLUSERSPROFILE%\drama\temp\bat.exe
- %TEMP%\bat.bat
- %ALLUSERSPROFILE%\drama\temp\actmovie.$$A
- %ALLUSERSPROFILE%\drama\temp\actmovie.$$A в %ALLUSERSPROFILE%\drama\temp\actmovie.exe
- %ALLUSERSPROFILE%\drama\temp\actmovie.$AA в %ALLUSERSPROFILE%\drama\temp\actmovie.$$A
- %ALLUSERSPROFILE%\drama\temp\bat.$$A в %ALLUSERSPROFILE%\drama\temp\bat.exe
- ClassName: 'InstItClass' WindowName: ''