Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\run] 'Cvh' = '%TEMP%\s.bat'
- %TEMP%\s.bat
- ClassName: 'Chrome_MessageWindow' WindowName: '%LOCALAPPDATA%\Google\Chrome\User Data'
- ClassName: 'Mozilla_firefox_default-release-1_RemoteWindow' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\s.bat" "
- '<SYSTEM32>\ipconfig.exe' /flushdns
- '%ProgramFiles%\mozilla firefox\firefox.exe' about:config
- '%ProgramFiles%\mozilla firefox\firefox.exe' about:preferences#privacy
- '<SYSTEM32>\shutdown.exe' /r /t 0