Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'antivirusFalsePositiveTest4' = '<SYSTEM32>\antivirusfalsepositivetest4.exe'
- nul
- <SYSTEM32>\startdefender.bat
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v antivirusFalsePositiveTest4 /t REG_SZ /d "<SYSTEM32>\antivirusfalsepositivetest4.exe" /f
- '<SYSTEM32>\timeout.exe' /t 5 /nobreak