Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'svhost.exe' = '%WINDIR%\register svhostes\svhost.exe'
- <SYSTEM32>\reg.exe add "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v svhost.exe /d "%WINDIR%\register svhostes\svhost.exe" /f
- <SYSTEM32>\cmd.exe /c """%TEMP%\ULCDRSvr.bat"""
- %TEMP%\exe1.tmp
- %TEMP%\ULCDRSvr.bat
- %TEMP%\ULCDRSvr.bat