Техническая информация
- '<SYSTEM32>\net.exe' START spooler
- '<SYSTEM32>\net1.exe' START spooler
- '<SYSTEM32>\spoolsv.exe'
- '<SYSTEM32>\net1.exe' STOP spooler
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\batchfile.bat" "
- '<SYSTEM32>\reg.exe' add HKLM\Software\Classes\cmdfile\shell /ve /t REG_SZ /d "runas" /f
- '<SYSTEM32>\net.exe' STOP spooler
- %TEMP%\1.tmp\batchfile.bat