Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'WGNP Windows W32 Generic Host Process System' = '<SYSTEM32>\svshost.exe'
- %WINDIR%\sup.reg
- %WINDIR%\svshost.exe
- %WINDIR%\sup.bat
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%WINDIR%\svshost.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%WINDIR%\sup.bat" "
- '%WINDIR%\syswow64\regedit.exe' /s %WINDIR%\sup.reg