Техническая информация
- <SYSTEM32>\cacls.exe "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk" /t /e /c /g everyone:f
- <SYSTEM32>\cacls.exe "%HOMEPATH%\Desktop\Internet Explorer.lnk" /t /e /c /g everyone:f
- <SYSTEM32>\cacls.exe "%HOMEPATH%\Desktop\Internet Explorer.lnk" /t /e /c /r %USERNAME%
- <SYSTEM32>\regini.exe bak.ini
- %WINDIR%\regedit.exe /s CHS.reg
- <SYSTEM32>\regini.exe regini.ini
- %TEMP%\nsa3.tmp\ns7.tmp
- %TEMP%\nsa3.tmp\ns6.tmp
- %TEMP%\nsa3.tmp\ns5.tmp
- %TEMP%\nsa3.tmp\ns8.tmp
- %TEMP%\nsa3.tmp\ns9.tmp
- %HOMEPATH%\Desktop\Internet Explorer.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk
- <SYSTEM32>\regini.ini
- %TEMP%\nsa3.tmp\System.dll
- %TEMP%\nsf2.tmp
- <SYSTEM32>\CHS.reg
- %TEMP%\nsa3.tmp\ns4.tmp
- %TEMP%\nsa3.tmp\nsExec.dll
- <SYSTEM32>\bak.ini
- <SYSTEM32>\regini.ini
- %TEMP%\nsa3.tmp\ns7.tmp
- %TEMP%\nsa3.tmp\ns8.tmp
- %TEMP%\nsa3.tmp\ns6.tmp
- %TEMP%\nsa3.tmp\ns4.tmp
- <SYSTEM32>\bak.ini
- %TEMP%\nsa3.tmp\ns5.tmp
- ClassName: 'RegEdit_RegEdit' WindowName: ''