Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] '{FFBA5A4F-CDD2-439E-902B-81AAAFDAD3EC}' = ''
- %WINDIR%\regedit.exe /s %TEMP%\reg.reg
- <SYSTEM32>\cmd.exe /c %TEMP%\reg.bat
- %TEMP%\reg.bat
- %WINDIR%\system\group32.dll
- <SYSTEM32>\group.exe
- %TEMP%\reg.reg
- %TEMP%\reg.reg
- ClassName: 'RegEdit_RegEdit' WindowName: ''