Техническая информация
- '<SYSTEM32>\ping.exe' 127.0.0.1
- '<SYSTEM32>\cmd.exe' /c ping 127.0.0.1 && reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce" /v os9ui /t REG_SZ /d "C:\os9uios9ui\os9ui.vbs" /f
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe'
- '<SYSTEM32>\cmd.exe' /c ping 127.0.0.1 && move C:\os9uios9ui\os9ui.vbs "%HOMEPATH%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\os9ui.vbs"
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe
- C:\os9uios9ui\os9ui.vbs
- ClassName: 'MS_WINHELP' WindowName: ''