Техническая информация
- %WINDIR%\bitlockerdiscoveryvolumecontents\bitlockertogo.exe
- C:\users\public\libraries\document.pdf
- %LOCALAPPDATA%\adobe\color\profiles\wscrgb.icc
- %LOCALAPPDATA%\adobe\color\profiles\wsrgb.icc
- %LOCALAPPDATA%\adobe\color\acecache11.lst
- '%WINDIR%\syswow64\cmd.exe' /c start C:\Users\Public\Libraries\document.pdf (со скрытым окном)
- '%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrord32.exe' "C:\Users\Public\Libraries\document.pdf"
- '%WINDIR%\bitlockerdiscoveryvolumecontents\bitlockertogo.exe'