Техническая информация
- [HKLM\software\Wow6432Node\microsoft\windows\currentversion\run] 'wind' = 'c:\bat\system.bat'
- [HKLM\software\Wow6432Node\microsoft\windows\currentversion\run] 'wind2' = 'c:\bat\1.exe'
- C:\bat\system.bat
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\bat\system.bat" "
- '%WINDIR%\syswow64\reg.exe' add hklm\software\microsoft\windows\currentversion\run /v wind /t reg_sz /d c:\bat\system.bat /f
- '%WINDIR%\syswow64\reg.exe' add hklm\software\microsoft\windows\currentversion\run /v wind2 /t reg_sz /d c:\bat\1.exe /f
- '%WINDIR%\syswow64\cmd.exe'