Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Windows Service Host!' = '%WINDIR%\explorer.exe "%PROGRAM_FILES%\FireFox\svcchost.exe"'
- %PROGRAM_FILES%\FireFox\svcchost.exe
- <SYSTEM32>\reg.exe add HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /v ConsentPromptBehaviorAdmin /t REG_DWORD /d 0x00000000 /f
- %WINDIR%\regedit.exe /s "%TEMP%\tmpreg.reg"
- <SYSTEM32>\taskkill.exe /IM svcchost.exe /F /T
- <SYSTEM32>\cmd.exe /c %TEMP%\TMPCOPY.bat
- %TEMP%\tmpreg.reg
- %PROGRAM_FILES%\FireFox\svcchost.exe
- %TEMP%\TMPCOPY.bat
- %PROGRAM_FILES%\FireFox\svcchost.exe
- %TEMP%\tmpreg.reg
- %TEMP%\TMPCOPY.bat
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: '' WindowName: ''