Техническая информация
- '<SYSTEM32>\taskkill.exe' /f /im explorer.exe
- %WINDIR%\explorer.exe
- %HOMEPATH%\desktop\browse.htm
- %HOMEPATH%\desktop\api-hashmap.html
- %HOMEPATH%\desktop\alert.html
- %HOMEPATH%\desktop\advice_process.htm
- %HOMEPATH%\desktop\dashborder_120.bmp
- %TEMP%\f7e.tmp\wimmount2.bat
- ClassName: '' WindowName: ''
- ClassName: 'Progman' WindowName: ''
- ClassName: 'Proxy Desktop' WindowName: ''
- ClassName: 'SystemTray_Main' WindowName: ''
- ClassName: 'Media Center Tray Applet' WindowName: ''
- ClassName: '' WindowName: 'View Available Networks'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: 'BluetoothNotificationAreaIconWindowClass'
- ClassName: 'BluetoothNotificationAreaIconWindowClass' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\F7E.tmp\wimmount2.bat" <Полный путь к файлу>"' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\F7E.tmp\wimmount2.bat" <Полный путь к файлу>"
- '%WINDIR%\explorer.exe'