Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'RuntimeBroker' = '"%APPDATA%\Microsoft\System\RuntimeBroker.exe"'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'RuntimeBroker' = '"%APPDATA%\Microsoft\System\RuntimeBroker.exe"'
- %APPDATA%\microsoft\windows\start menu\programs\startup\runtimebroker.exe
- nul
- %APPDATA%\microsoft\system\runtimebroker.exe
- %APPDATA%\microsoft\system\runtimebroker.exe
- DNS ASK we##p.ru
- '%APPDATA%\microsoft\system\runtimebroker.exe'
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Microsoft\Cryptography /v MachineGuid
- '<SYSTEM32>\reg.exe' query HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v RuntimeBroker
- '<SYSTEM32>\attrib.exe' +h +s %APPDATA%\Microsoft\System
- '<SYSTEM32>\attrib.exe' +h +s %APPDATA%\Microsoft\System\RuntimeBroker.exe
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v RuntimeBroker /t REG_SZ /d \"%APPDATA%\Microsoft\System\RuntimeBroker.exe\" /f
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce /v RuntimeBroker /t REG_SZ /d \"%APPDATA%\Microsoft\System\RuntimeBroker.exe\" /f