Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\] 'Shell' = 'C:\inkballopener.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HelpPane.exe] 'Debugger' = '534526134.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sethc.exe] 'Debugger' = '534526134.exe'
- Интерпретатора командной строки (CMD)
- Диспетчера задач (Taskmgr)
- Редактора реестра (RegEdit)
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoLogoff' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoControlPanel' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoClose' = '00000001'
- C:\inkballopener.exe
- '%WINDIR%\syswow64\cmd.exe' /c msg * what the dog doin' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c wmic os where primary=1 reboot' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c msg * what the dog doin
- '%WINDIR%\syswow64\cmd.exe' /c wmic os where primary=1 reboot
- '%WINDIR%\syswow64\wbem\wmic.exe' os where primary=1 reboot