Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ntrty' = '%WINDIR%\ntrty.exe'
- %WINDIR%\ntrty.exe
- <SYSTEM32>\reg.exe ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /v ntrty /t REG_SZ /d %WINDIR%\ntrty.exe /f
- %WINDIR%\ntrty.exe
- ClassName: 'Indicator' WindowName: ''