Техническая информация
- '%TEMP%\Un_VCR.EXE'
- '<SYSTEM32>\regsvr32.exe' /u /s C:\VirusC~1\ShellScan.dll
- '<SYSTEM32>\taskkill.exe' /IM nslsrv.exe /F
- '<SYSTEM32>\reg.exe' delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Skymon" /f
- '<SYSTEM32>\regsvr32.exe' /u /s C:\VirusC~1\ProcMon.dll
- '<SYSTEM32>\taskkill.exe' /IM skymon.exe /F
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\E6BC.CMD" "
- '<SYSTEM32>\taskkill.exe' /IM SystemMon.exe /F
- '<SYSTEM32>\taskkill.exe' /IM CltAgent.exe /F
- %TEMP%\E6BC.CMD
- %TEMP%\Un_VCR.EXE
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'