Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Control\Session manager] 'BootExecute' = 'autocheck autochk *'
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'Win32' = 'C:\Download\wualctl32.exe'
- [<HKLM>\SYSTEM\ControlSet002\Control\Session manager] 'BootExecute' = 'autocheck autochk *'
- [<HKLM>\SYSTEM\CurrentControlSet\Control\Session manager] 'BootExecute' = 'autocheck autochk *'
- DNS ASK do###.t35.com
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\ControlSet001\Control\Session manager" /v BootExecute /t REG_MULTI_SZ /d "autocheck autochk *" /f' (со скрытым окном)
- '<SYSTEM32>\sc.exe' delete GbpSv' (со скрытым окном)
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\ControlSet002\Control\Session manager" /v BootExecute /t REG_MULTI_SZ /d "autocheck autochk *" /f' (со скрытым окном)
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\Control\Session manager" /v BootExecute /t REG_MULTI_SZ /d "autocheck autochk *" /f' (со скрытым окном)
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\ControlSet001\Control\Session manager" /v BootExecute /t REG_MULTI_SZ /d "autocheck autochk *" /f
- '<SYSTEM32>\sc.exe' delete GbpSv
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\ControlSet002\Control\Session manager" /v BootExecute /t REG_MULTI_SZ /d "autocheck autochk *" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\Control\Session manager" /v BootExecute /t REG_MULTI_SZ /d "autocheck autochk *" /f