Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '8130192a' = '%APPDATA%\Roaming\8130192a.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] '*130192a' = '%APPDATA%\Roaming\8130192a.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '8130192' = 'C:\8130192a\8130192a.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] '*130192' = 'C:\8130192a\8130192a.exe'
- '<SYSTEM32>\bcdedit.exe' /set {default} recoveryenabled No
- '<SYSTEM32>\bcdedit.exe' /set {default} bootstatuspolicy ignoreallfailures
- '<SYSTEM32>\vssvc.exe'
- '%WINDIR%\explorer.exe'
- '<SYSTEM32>\svchost.exe' netsvcs
- '<SYSTEM32>\vssadmin.exe' Delete Shadows /All /Quiet
- <SYSTEM32>\svchost.exe
- %WINDIR%\explorer.exe
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\8130192a.exe
- %APPDATA%\Roaming\8130192a.exe
- C:\8130192a\8130192a.exe
- ClassName: 'Indicator' WindowName: ''