Техническая информация
- [<HKLM>\software\Wow6432Node\microsoft\windows\CurrentVersion\Run] 'kiss770.cn' = '<Полный путь к файлу>'
- '%WINDIR%\syswow64\taskkill.exe' /f /im explorer.exe
- %WINDIR%\explorer.exe
- ClassName: 'Progman' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: '' WindowName: 'taskmgr.exe'
- ClassName: '' WindowName: 'sethc.exe'
- '%WINDIR%\syswow64\reg.exe' DELETE HKLM\SYSTEM\CurrentXontrolSet\Control\SafeBoot\ /va /f
- '%WINDIR%\syswow64\shutdown.exe' -s -f -t 300