Техническая информация
- [HKLM\System\CurrentControlSet\Services\EFS] 'Start' = '00000002'
- %TEMP%\enc2cab.tmp
- %APPDATA%\microsoft\crypto\rsa\s-1-5-21-3150914307-1777937420-491476919-1000\a5619586e73a9867e859be67a0034adc_d99ef00b-ccd3-4f1d-9980-90ac453b0b47
- %APPDATA%\microsoft\systemcertificates\my\certificates\254667314aa1b6bacc98ba426ee12b15c4d6fe08
- C:\system volume information\efs0.log
- %TEMP%\efs0.tmp
- %TEMP%\efs0.tmp
- C:\system volume information\efs0.log
- %TEMP%\enc2cab.tmp
- '%WINDIR%\syswow64\cipher.exe' /e "%TEMP%\enc2CAB.tmp"' (со скрытым окном)
- '%WINDIR%\syswow64\cipher.exe' /e "/s:%HOMEPATH%\cpsi" /a' (со скрытым окном)
- '%WINDIR%\syswow64\cipher.exe' /e "%TEMP%\enc2CAB.tmp"
- '<SYSTEM32>\efsui.exe' /efs /keybackup
- '%WINDIR%\syswow64\cipher.exe' /e "/s:%HOMEPATH%\cpsi" /a