Техническая информация
- [<HKLM>\SYSTEM\ControlSet002\Control\Session Manager] 'BootExecute' = ''
- [<HKLM>\SYSTEM\ControlSet001\Control\Session Manager] 'BootExecute' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WinService32' = '%WINDIR%\system\winsvc32.exe'
- <SYSTEM32>\reg.exe add "HKLM\SYSTEM\ControlSet002\Control\Session manager" /v BootExecute /t REG_MULTI_SZ /d "autocheck autochk *" /f
- <SYSTEM32>\reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Session manager" /v BootExecute /t REG_MULTI_SZ /d "autocheck autochk *" /f
- <SYSTEM32>\reg.exe add "HKLM\SYSTEM\ControlSet001\Control\Session manager" /v BootExecute /t REG_MULTI_SZ /d "autocheck autochk *" /f
- <SYSTEM32>\schtasks.exe /delete /TN startt /f
- <SYSTEM32>\sc.exe delete GbpSv
- 'si#####onitao.t35.com':80
- si#####onitao.t35.com/inf.php
- DNS ASK si#####onitao.t35.com