Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'dbfMicrosoft' = '%WINDIR%\ccswatch.exe'
- <SYSTEM32>\cmd.exe /c %WINDIR%\regC.bat
- <SYSTEM32>\reg.exe ADD HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run /v dbfMicrosoft /t REG_SZ /d "%WINDIR%\ccswatch.exe"
- <SYSTEM32>\cmd.exe /c %WINDIR%\regB.bat
- <SYSTEM32>\reg.exe DELETE HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run /v dbfMicrosoft /f
- %WINDIR%\regEXT.bat
- %WINDIR%\regC.bat
- %WINDIR%\regB.bat
- ClassName: 'Shell_TrayWnd' WindowName: ''