Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'explorer.exe,%HOMEPATH%\AppData\Kernel32.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '' = 'C:\'
- cvtres.exe
- %HOMEPATH%\appdata\kernel32.exe
- %TEMP%\cvtres.exe
- DNS ASK no#.##rvebeer.com
- '%HOMEPATH%\appdata\kernel32.exe' cvtres.exe
- '%TEMP%\cvtres.exe'
- '%WINDIR%\syswow64\cmd.exe' /c reg add "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /f /v shell /t REG_SZ /d explorer.exe,"%HOMEPATH%\AppData\Kernel32.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c reg add "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /f /v shell /t REG_SZ /d explorer.exe,"%HOMEPATH%\AppData\Kernel32.exe"
- '%WINDIR%\syswow64\reg.exe' add "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /f /v shell /t REG_SZ /d explorer.exe,"%HOMEPATH%\AppData\Kernel32.exe"