Техническая информация
- [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Load' = '%APPDATA%\Microsoft\Windows\SystemApps\RuntimeBroker.exe'
- [HKCU\Environment] 'UserInitMprLogonScript' = '%APPDATA%\Microsoft\Windows\ServiceProfiles\svchost.exe'
- nul
- %APPDATA%\microsoft\windows\systemapps\runtimebroker.exe
- %APPDATA%\microsoft\windows\serviceprofiles\svchost.exe
- %APPDATA%\microsoft\windows\systemapps\runtimebroker.exe
- %APPDATA%\microsoft\windows\serviceprofiles\svchost.exe
- DNS ASK we##p.ru
- '%APPDATA%\microsoft\windows\systemapps\runtimebroker.exe'
- '<SYSTEM32>\reg.exe' query HKLM\SOFTWARE\Microsoft\Cryptography /v MachineGuid
- '<SYSTEM32>\reg.exe' query "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /v Load
- '<SYSTEM32>\attrib.exe' +h +s %APPDATA%\Microsoft\Windows\SystemApps\RuntimeBroker.exe
- '<SYSTEM32>\attrib.exe' +h +s %APPDATA%\Microsoft\Windows\ServiceProfiles\svchost.exe
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /v Load /t REG_SZ /d %APPDATA%\Microsoft\Windows\SystemApps\RuntimeBroker.exe /f
- '<SYSTEM32>\reg.exe' add HKCU\Environment /v UserInitMprLogonScript /t REG_SZ /d %APPDATA%\Microsoft\Windows\ServiceProfiles\svchost.exe /f
- '%APPDATA%\microsoft\windows\systemapps\runtimebroker.exe' (со скрытым окном)