Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\BITS] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\wuauserv] 'Start' = '00000002'
- %WINDIR%\regedit.exe /s C:\autoupdate.reg
- %WINDIR%\regedit.exe /e C:\temfile.tem HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
- <SYSTEM32>\net.exe stop bits
- <SYSTEM32>\net1.exe stop bits
- <SYSTEM32>\net1.exe start bits
- <SYSTEM32>\net1.exe start wuauserv
- <SYSTEM32>\find.exe "wuauserv" C:\temfile.tem
- %WINDIR%\regedit.exe /s C:\AutoStart.reg
- <SYSTEM32>\net1.exe stop wuauserv
- <SYSTEM32>\find.exe "2000"
- <SYSTEM32>\find.exe "Microsoft Windows [░ц▒╛ 5"
- <SYSTEM32>\chcp.com
- <SYSTEM32>\find.exe "936"
- <SYSTEM32>\net1.exe user "%USERNAME%"
- <SYSTEM32>\net.exe stop wuauserv
- <SYSTEM32>\find.exe "XP"
- <SYSTEM32>\find.exe "*%USERNAME%s"
- C:\temfile.tem
- C:\AutoStart.reg
- %TEMP%\bt8647.bat
- C:\autoupdate.reg
- %TEMP%\bt8647.bat
- C:\AutoStart.reg
- C:\temfile.tem
- C:\autoupdate.reg
- ClassName: 'RegEdit_RegEdit' WindowName: ''