Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{A0XC6A98-A14C-J35H-46UD-F5AR862J2AH5}] 'StubPath' = '%PROGRAM_FILES%\NetServices\Schied.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{A0XC6A98-A14C-J35H-46UD-F5AR862J2AH5}] 'StubPath' = '<Полный путь к вирусу>'
- %PROGRAM_FILES%\NetServices\Schied.exe
- <SYSTEM32>\ping.exe -n 2 localhost
- %PROGRAM_FILES%\NetServices\Schied.exe
- %PROGRAM_FILES%\NetServices\Schied.exe