Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\ys33ISZM.lnk
- '<Полный путь к файлу>'
- '<SYSTEM32>\cacls.exe' "%HOMEPATH%\NTUSER.DAT" /E /G %USERNAME%:F /C
- '<SYSTEM32>\attrib.exe' -R -A -H "%HOMEPATH%\NTUSER.DAT"
- '<SYSTEM32>\cmd.exe' /C CACLS "%HOMEPATH%\NTUSER.DAT" /E /G %USERNAME%:F /C & ATTRIB -R -A -H "%HOMEPATH%\NTUSER.DAT"
- '<SYSTEM32>\cmd.exe' /C attrib +H "%HOMEPATH%\Start Menu\Programs\Startup\ys33ISZM.lnk"
- '<SYSTEM32>\attrib.exe' +H "%HOMEPATH%\Start Menu\Programs\Startup\ys33ISZM.lnk"
- %HOMEPATH%\Favorites\Links\!Inf0_H0w_T0_Unl0ck_Files!.inf
- %HOMEPATH%\Favorites\!ReadMe_T0_ResT0re_Files!.rtf
- %HOMEPATH%\Favorites\!Inf0_H0w_T0_Unl0ck_Files!.inf
- %HOMEPATH%\Favorites\Links\!ReadMe_T0_ResT0re_Files!.rtf
- %TEMP%\5OCL48lO.exe
- %HOMEPATH%\Templates\!ReadMe_T0_ResT0re_Files!.rtf
- %HOMEPATH%\Templates\!Inf0_H0w_T0_Unl0ck_Files!.inf
- %HOMEPATH%\Start Menu\Programs\Startup\ys33ISZM.lnk