Техническая информация
- '%WINDIR%\syswow64\taskkill.exe' /F /im wxauditcslex.exe /T
- '%WINDIR%\syswow64\taskkill.exe' /F /im wxsvraidex.exe /T
- '%WINDIR%\syswow64\taskkill.exe' /F /im server.exe /T
- ClassName: 'Regmonclass', WindowName: ''
- ClassName: 'Filemonclass', WindowName: ''
- %WINDIR%\syswow64\1.bat
- ClassName: '4823-00000029' WindowName: ''
- ClassName: '18467-41' WindowName: ''
- ClassName: '' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\1.bat' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\1.bat
- '%WINDIR%\syswow64\reg.exe' add "HKCU\Software\Sicent\wx2004\Plugins" /v "╓╟╢α╩╡├√▓σ╝■" /t REG_SZ /d "wxIKeeper.dll" /f