Техническая информация
- [<HKLM>\SOFTWARE\Classes\Wow6432Node\CLSID\{00D34A52-5617-1D04-E5C5-BDB42573D472}\Shell\Open\Command] '' = '%ProgramFiles%\Internet Explorer\SIGNUP\iexplore.exe %1 h%t%t%p:%//%w%w%w.%18%15%16%1...
- %WINDIR%\syswow64\cmd.exe
- %ProgramFiles%\internet explorer\signup\iexplore.exe
- %WINDIR%\{00d34a52-5617-1d04-e5c5-bdb42573d472}.reg
- %WINDIR%\{00d34a52-5617-1d04-e5c5-bdb42573d472}.bat
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\{00D34A52-5617-1D04-E5C5-BDB42573D472}.bat' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\{00D34A52-5617-1D04-E5C5-BDB42573D472}.bat
- '%WINDIR%\syswow64\regedit.exe' /s {00D34A52-5617-1D04-E5C5-BDB42573D472}.reg