Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'system.exe' = '<SYSTEM32>\system.exe'
- %TEMP%\ixp000.tmp\2В·Г¶Г¶Гі~1.exe
- %WINDIR%\syswow64\system.reg
- %WINDIR%\syswow64\system.exe
- %WINDIR%\temp\1.bat
- %WINDIR%\temp\1.vbs
- %WINDIR%\temp\system.exe
- %TEMP%\tmp$$$.vbs
- %TEMP%\ixp000.tmp\2В·Г¶Г¶Гі~1.exe
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%TEMP%\ixp000.tmp\2В·Г¶Г¶Гі~1.exe'
- '%WINDIR%\syswow64\system.exe'
- '%WINDIR%\syswow64\wscript.exe' "%WINDIR%\temp\1.vbs"
- '%WINDIR%\syswow64\regedit.exe' /s system.reg
- '%WINDIR%\syswow64\cmd.exe' /c 1.bat (со скрытым окном)
- '%WINDIR%\syswow64\cscript.exe' //nologo %LOCALAPPDATA%\Temp.\tmp$$$.vbs
- '%TEMP%\ixp000.tmp\2В·Г¶Г¶Гі~1.exe' (со скрытым окном)