Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'TestUSBWorm' = '<SYSTEM32>\USBWorm.exe'
- '<SYSTEM32>\USBWorm.exe'
- '<SYSTEM32>\taskhost.exe' import key.reg
- '<SYSTEM32>\conhost.exe' /c bat.bat
- '%WINDIR%\explorer.exe' /c bat.bat
- '<SYSTEM32>\taskhost.exe' /c bat.bat
- '%WINDIR%\explorer.exe' import key.reg
- '<SYSTEM32>\reg.exe' import key.reg
- '%WINDIR%\explorer.exe' C:\
- '%WINDIR%\explorer.exe' /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
- '<SYSTEM32>\conhost.exe' import key.reg
- '<SYSTEM32>\reg.exe' /c bat.bat
- \Device\Mup\.host\Shared Folders\vm_shara\USBWorm.exe
- \Device\Mup\.host\Shared Folders\vm_shara\AutoRun.inf
- <SYSTEM32>\USBWorm.exe
- <Текущая директория>\key.reg
- <Текущая директория>\bat.bat
- \Device\Mup\.host\Shared Folders\vm_shara\AutoRun.inf
- \Device\Mup\.host\Shared Folders\vm_shara\USBWorm.exe
- <SYSTEM32>\USBWorm.exe
- <Текущая директория>\key.reg