Technical Information
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe, %TEMP%\WindowsCache\re.bat'
- %APPDATA%\microsoft\windows\start menu\programs\startup\re.bat
- %TEMP%\rarsfx0\re.bat
- %TEMP%\rarsfx0\x.bat
- %TEMP%\rarsfx0\x.vbs
- nul
- %TEMP%\windowscache\re.bat
- \device\harddiskvolume1\boot\bcd.log
- \device\harddiskvolume1\boot\bcd
- ClassName: 'Edit' WindowName: ''
- '<SYSTEM32>\wscript.exe' "%TEMP%\RarSFX0\X.vbs"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\RarSFX0\X.bat" "
- '<SYSTEM32>\net.exe' session
- '<SYSTEM32>\net1.exe' session
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "Shell" /t REG_SZ /d "explorer.exe, %TEMP%\WindowsCache\re.bat" /f
- '<SYSTEM32>\shutdown.exe' /r /f /t 0
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\RarSFX0\X.bat" "' (with hidden window)