Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'zrga' = '<SYSTEM32>\winhelp.exe'
- %WINDIR%\syswow64\windows.bat
- %WINDIR%\syswow64\gole.vbs
- %WINDIR%\syswow64\wintime.exe
- %WINDIR%\syswow64\winhelp.exe
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\syswow64\wintime.exe'
- '%WINDIR%\syswow64\wscript.exe' "<SYSTEM32>\gole.vbs"
- '%WINDIR%\syswow64\cmd.exe' /c ""<SYSTEM32>\windows.bat" " (со скрытым окном)
- '%WINDIR%\syswow64\reg.exe' add "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" /v "zrga" /t reg_sz /d <SYSTEM32>\winhelp.exe /f