Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '' = '%WINDIR%\Fonts\stup.vbs'
- %TEMP%\123.vbs
- %TEMP%\t1.25.bat
- %WINDIR%\fonts\stup.vbs
- %TEMP%\123.vbs
- '11#.#0.109.190':80
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\123.vbs"
- '%WINDIR%\syswow64\wscript.exe' "%WINDIR%\Fonts\stup.vbs"
- '%WINDIR%\syswow64\cmd.exe' /c%TEMP%\t1.25.bat&&erase %TEMP%\t1.25.bat
- '%WINDIR%\syswow64\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /ve /d "%WINDIR%\Fonts\stup.vbs" /f
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\123.vbs" (со скрытым окном)