Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Command Processor] 'AutoRun' = ''
- '<SYSTEM32>\reg.exe' add "HKLM\Software\Microsoft\Command Processor" /v AutoRun /t REG_EXPAND_SZ /d "%WINDIR%\jzml.cmd" /f
- %WINDIR%\jzml.cmd
- %TEMP%\bt5181.bat
- %TEMP%\bt5181.bat