Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\osppsvc] 'Start' = '00000002'
- <SYSTEM32>\net1.exe stop osppsvc
- <SYSTEM32>\net1.exe start osppsvc
- <SYSTEM32>\net.exe stop osppsvc
- <SYSTEM32>\reg.exe ADD "HKLM\SYSTEM\CurrentControlSet\services\osppsvc" /v "Start" /t "REG_DWORD" /d "2" /f
- <SYSTEM32>\reg.exe ADD "HKCU\SOFTWARE\Microsoft\Office\Common\UserInfo" /v "UserName" /d "Office 2010 Hack" /f
- %TEMP%\~1.bat
- %TEMP%\~1.bat
- %TEMP%\~1.bat