Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run\] 'WinServices' = '"<SYSTEM32>\WinServices.exe"'
- %WINDIR%\syswow64\winservices.exe
- %WINDIR%\syswow64\winservices.exe
- '%WINDIR%\syswow64\winservices.exe'
- '%WINDIR%\syswow64\cmd.exe' /C attrib +h "<SYSTEM32>\WinServices.exe"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C attrib +s "<SYSTEM32>\WinServices.exe"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C TIMEOUT /T 10 /NOBREAK && "<SYSTEM32>\WinServices.exe"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C attrib +h "<SYSTEM32>\WinServices.exe"
- '%WINDIR%\syswow64\cmd.exe' /C attrib +s "<SYSTEM32>\WinServices.exe"
- '%WINDIR%\syswow64\cmd.exe' /C TIMEOUT /T 10 /NOBREAK && "<SYSTEM32>\WinServices.exe"
- '%WINDIR%\syswow64\attrib.exe' +h "<SYSTEM32>\WinServices.exe"
- '%WINDIR%\syswow64\timeout.exe' /T 10 /NOBREAK
- '%WINDIR%\syswow64\attrib.exe' +s "<SYSTEM32>\WinServices.exe"