Technical Information
- [<HKLM>\software\Wow6432Node\microsoft\windows\CurrentVersion\Run] 'Syste2.exe' = '<SYSTEM32>\Syste2.exe'
- '%WINDIR%\syswow64\taskkill.exe' /f /im explorer.exe
- %WINDIR%\explorer.exe
- %WINDIR%\syswow64\syste2.exe
- <Current directory>\girlfriend.txt
- <Current directory>\ГґВáâëý.jpg
- %WINDIR%\syswow64\syste2.exe
- ClassName: '' WindowName: 'taskmgr.exe'
- ClassName: '' WindowName: ''