Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Virus' = '%WINDIR%\Update.vbs'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Virus' = '{01,00}'
- '<SYSTEM32>\wscript.exe' "C:\temp\Game.vbs"
- %WINDIR%\Update.vbs
- <SYSTEM32>\Update.vbs
- C:\temp\Game.vbs
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''