Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Kiosk' = '%ProgramFiles%\Kiosk\kiosk.exe'
- '<SYSTEM32>\net1.exe' localgroup "HiRISAdmin" /add
- '<SYSTEM32>\net.exe' localgroup "HiRISAdmin" /add
- '<SYSTEM32>\net1.exe' user "OperatorLevel1" "0p3rat0rL3v3l1" /add
- '<SYSTEM32>\net.exe' user "OperatorLevel1" "0p3rat0rL3v3l1" /add
- '<SYSTEM32>\net1.exe' localgroup "HiRISLevel2" /add
- '<SYSTEM32>\net.exe' localgroup "HiRISLevel1" /add
- '<SYSTEM32>\cmd.exe' /c CreateUsersAndGroups.cmd
- '<SYSTEM32>\net.exe' localgroup "HiRISLevel2" /add
- '<SYSTEM32>\net1.exe' localgroup "HiRISLevel1" /add
- %ProgramFiles%\Kiosk\NLog.dll
- %ProgramFiles%\Kiosk\Microsoft.Practices.Prism.SharedInterfaces.dll
- %WINDIR%\lockscreen.jpg
- %TEMP%\nsz2.tmp\CreateUsersAndGroups.cmd
- %ALLUSERSPROFILE%\Desktop\Restore Kiosk Mode.lnk
- %ProgramFiles%\Kiosk\Kiosk.exe
- %TEMP%\nsz2.tmp\UserInfo.dll
- %ProgramFiles%\Kiosk\HiRis.Utility.dll
- %ProgramFiles%\Kiosk\Microsoft.Practices.Prism.Mvvm.dll
- %ProgramFiles%\Kiosk\MathNet.Numerics.dll
- ClassName: 'Shell_TrayWnd' WindowName: ''