Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'fetg565gh59579055a59579055' = '%HOMEPATH%\59579055\59579055.exe'
- %HOMEPATH%\59579055\59579055.exe
- '%WINDIR%\syswow64\shutdown.exe' /R /F /T 05
- '%WINDIR%\syswow64\cmd.exe' /c rEG aDD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v fetg565gh59579055a59579055 /d "%HOMEPATH%\59579055\59579055.exe" /F
- '%WINDIR%\syswow64\reg.exe' aDD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v fetg565gh59579055a59579055 /d "%HOMEPATH%\59579055\59579055.exe" /F
- '%WINDIR%\syswow64\shutdown.exe' /R /F /T 05' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c rEG aDD HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v fetg565gh59579055a59579055 /d "%HOMEPATH%\59579055\59579055.exe" /F' (with hidden window)