Техническая информация
- [<HKLM>\SOFTWARE\Classes\CLSID\{32543837-4229-3099-9153-068063565684}\Shell\Open\Command] '' = '%ProgramFiles%\top.exe'
- [<HKLM>\SOFTWARE\Classes\CLSID\{28343837-4229-3099-9153-068063565684}\Shell\Open\Command] '' = '%ProgramFiles%\top.exe'
- %ProgramFiles%\3.ico
- %ProgramFiles%\1.ico
- %ProgramFiles%\5.ico
- %ProgramFiles%\4.ico
- %ProgramFiles%\2.ico
- C:\dr.sys
- C:\ptp.sys
- C:\ЕдЦГПо.ini
- %ProgramFiles%\top.exe
- %ProgramFiles%\3.ico
- %ProgramFiles%\4.ico
- %ProgramFiles%\5.ico
- %ProgramFiles%\1.ico
- C:\dr.sys
- %ProgramFiles%\top.exe
- %ProgramFiles%\2.ico
- '<SYSTEM32>\cacls.exe' "%ALLUSERSPROFILE%\Desktop" /e /c /g everyone:c
- '<SYSTEM32>\cacls.exe' "%ALLUSERSPROFILE%\Desktop/їЄКјЙПНш.lnk" /e /c /d everyone
- '<SYSTEM32>\cacls.exe' "%ALLUSERSPROFILE%\Desktop" /e /c /d everyone
- '<SYSTEM32>\cmd.exe' /c echo y|cacls "%ALLUSERSPROFILE%\Desktop" /e /c /d everyone&echo y|cacls "%ALLUSERSPROFILE%\Desktop" /e /c /g everyone:c&echo y|cacls "%ALLUSERSPROFILE%\Desktop/їЄКјЙПНш.lnk" /e /c /d everyon...
- '<SYSTEM32>\cmd.exe' /S /D /c" echo y"