Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] 'AppInit_DLLs' = ''
- <SYSTEM32>\reg.exe Delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows" /v LoadAppInit_DLLs /f
- <SYSTEM32>\reg.exe Delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows" /v RequireSignedAppInit_DLLs /f
- <SYSTEM32>\cmd.exe /c %TEMP%\\sdel.bat
- <SYSTEM32>\reg.exe Add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows" /v AppInit_DLLs /d "" /f
- %TEMP%\sdel.bat