Техническая информация
- <SYSTEM32>\taskkill.exe /f /im iexplore.exe
- <SYSTEM32>\cacls.exe "C:\Documents and Settings\XPCLIENT\Application Data\Microsoft\Internet Explorer\Quick Launch" /t /p everyone:r
- <SYSTEM32>\cacls.exe "C:\Documents and Settings\shspring\Application Data\Microsoft\Internet Explorer\Quick Launch" /t /p everyone:r
- <SYSTEM32>\ping.exe 127.0.0.1 -n 2
- <SYSTEM32>\ping.exe 127.0.0.1 -n 20
- <SYSTEM32>\cacls.exe g:\mm\??????\??\??\*.* /t /p everyone:f
- <SYSTEM32>\attrib.exe g:\mm\??????\??\??\*.* -s -h -r
- <SYSTEM32>\ping.exe 127.0.0.1 -n 10
- <SYSTEM32>\cmd.exe /c %WINDIR%\temp\tt.bat
- %WINDIR%\regedit.exe /s %WINDIR%\temp\ie.dll
- <SYSTEM32>\cacls.exe "%APPDATA%\Microsoft\Internet Explorer\Quick Launch" /p everyone:f
- <SYSTEM32>\cacls.exe "%APPDATA%\Microsoft\Internet Explorer\Quick Launch" /t /p everyone:r
- <SYSTEM32>\cacls.exe "C:\Documents and Settings\XPCLIENT\Application Data\Microsoft\Internet Explorer\Quick Launch" /p everyone:f
- <SYSTEM32>\cacls.exe "C:\Documents and Settings\shspring\Application Data\Microsoft\Internet Explorer\Quick Launch" /p everyone:f
- iexplore.exe
- %WINDIR%\Temp\tt.bat
- %WINDIR%\Temp\ie.dll
- %WINDIR%\Temp\ie.dll
- ClassName: '' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''