Техническая информация
- [HKLM\System\CurrentControlSet\Services\LNWXMCIN] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\LNWXMCIN] 'ImagePath' = '%ALLUSERSPROFILE%\bztnmuravikm\nupnxrtquxuu.exe'
- 'LNWXMCIN' %ALLUSERSPROFILE%\bztnmuravikm\nupnxrtquxuu.exe
- <SYSTEM32>\conhost.exe
- %WINDIR%\explorer.exe
- %ALLUSERSPROFILE%\bztnmuravikm\nupnxrtquxuu.exe
- %WINDIR%\temp\ectcyaocqevu.sys
- '%ALLUSERSPROFILE%\bztnmuravikm\nupnxrtquxuu.exe'
- '<SYSTEM32>\sc.exe' delete "LNWXMCIN"
- '<SYSTEM32>\sc.exe' create "LNWXMCIN" binpath= "%ALLUSERSPROFILE%\bztnmuravikm\nupnxrtquxuu.exe" start= "auto"
- '<SYSTEM32>\sc.exe' stop eventlog
- '<SYSTEM32>\sc.exe' start "LNWXMCIN"
- '%WINDIR%\explorer.exe'