Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows\Currentversion\Run] 'System' = '%WINDIR%\config\csrss.exe'
- %TEMP%\rarsfx0\csrss.exe
- %TEMP%\rarsfx0\comdlg32.ocx
- %TEMP%\rarsfx0\mswinsck.ocx
- %TEMP%\rarsfx0\richtx32.ocx
- %WINDIR%\syswow64\config.xmc
- DNS ASK se######agency.no-ip.biz
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\rarsfx0\csrss.exe'
- '%WINDIR%\syswow64\cmd.exe' /c regsvr32 /s richtx32.ocx (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c regsvr32 /s Mswinsck.ocx (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c regsvr32 /s comdlg32.ocx (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c REG ADD HKLM\Software\Microsoft\Windows\Currentversion\Run\ /v System /d %WINDIR%\config\csrss.exe /f (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c echo [Empty] > "<SYSTEM32>\config.xmc" (со скрытым окном)
- '%WINDIR%\syswow64\regsvr32.exe' /s Mswinsck.ocx
- '%WINDIR%\syswow64\regsvr32.exe' /s comdlg32.ocx
- '%WINDIR%\syswow64\regsvr32.exe' /s richtx32.ocx
- '%WINDIR%\syswow64\reg.exe' ADD HKLM\Software\Microsoft\Windows\Currentversion\Run\ /v System /d %WINDIR%\config\csrss.exe /f