Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'GoogleSvchostCrashHandler' = '%WINDIR%\�'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'GoogleSvchostCrashHandler' = '%WINDIR%\�'
- <SYSTEM32>\tasks\test
- %WINDIR%\svchost.exe
- %WINDIR%\svchost.exe
- '%WINDIR%\svchost.exe'
- '%WINDIR%\svchost.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /Create /RU SYSTEM /SC MINUTE /MO 1 /TN TEST /TR %WINDIR%\\svchost.exe
- '%WINDIR%\syswow64\schtasks.exe' /Create /RU SYSTEM /SC MINUTE /MO 1 /TN TEST /TR %WINDIR%\\svchost.exe