Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'System Debugger' = 'c:\00669730630076732E-0200167811001779062.exe /a'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe "c:\00669730630076732E-0200167811001779062.exe /a"'
- '<SYSTEM32>\tskill.exe' taskmgr
- '%WINDIR%\XXInstall\ps.exe' taskmgr
- '<SYSTEM32>\ipconfig.exe' /release
- 'C:\00669730630076732E-0200167811001779062.exe' /a
- '<SYSTEM32>\shutdown.exe' -s -f -t 30
- %WINDIR%\XXInstall\ps.exe
- C:\00669730630076732E-0200167811001779062.exe
- C:\00669730630076732E-0200167811001779062.exe