Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'systems' = '%WINDIR%\systems.exe'
- '<SYSTEM32>\cmd.exe' /c COPY "include\systems.exe" "%windir%//systems.exe"
- '<SYSTEM32>\cmd.exe' /c ping 188.138.101.230
- '<SYSTEM32>\ping.exe' 188.138.101.230
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" /v "systems" /d %WINDIR%\systems.exe
- '<SYSTEM32>\cmd.exe' /c REG QUERY HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v "systems"
- '<SYSTEM32>\reg.exe' QUERY HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v "systems"
- '<SYSTEM32>\cmd.exe' /c reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" /v "systems" /d %windir%\systems.exe
- ClassName: 'Indicator' WindowName: ''