Техническая информация
- [<HKLM>\SYSTEM\ControlSet002\Control\Session Manager] 'BootExecute' = ''
- [<HKLM>\SYSTEM\ControlSet001\Control\Session Manager] 'BootExecute' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'smss' = '<SYSTEM32>\sys\smss.exe'
- <SYSTEM32>\reg.exe add "HKLM\SYSTEM\ControlSet002\Control\Session manager" /v BootExecute /t REG_MULTI_SZ /d "autocheck autochk *" /f
- <SYSTEM32>\reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Session manager" /v BootExecute /t REG_MULTI_SZ /d "autocheck autochk *" /f
- <SYSTEM32>\sc.exe delete GbpSv
- <SYSTEM32>\reg.exe add "HKLM\SYSTEM\ControlSet001\Control\Session manager" /v BootExecute /t REG_MULTI_SZ /d "autocheck autochk *" /f
- '68.##7.88.113':80
- '76.#.67.178':80
- 68.##7.88.113/images/logos/recebe.asp?
- 76.#.67.178/images/resource/recebe.asp?