Техническая информация
- [HKLM\System\CurrentControlSet\Services\EFS] 'Start' = '00000002'
- %APPDATA%\microsoft\crypto\rsa\s-1-5-21-3691498038-2086406363-2140527554-1000\ba08e0ea4f209984540fe9c74f1b9125_0cb67e2f-dc95-45ca-8fb8-69bde8e3f814
- %APPDATA%\microsoft\systemcertificates\my\certificates\dd6feaf564759c00a329d91be3752cc196b5a39e
- C:\system volume information\efs0.log
- %LOCALAPPDATA%\microsoft\efs0.tmp
- %LOCALAPPDATA%\microsoft\spoolsvc.exe
- %LOCALAPPDATA%\microsoft\efs0.tmp
- C:\system volume information\efs0.log
- '%LOCALAPPDATA%\microsoft\spoolsvc.exe'
- '<SYSTEM32>\efsui.exe' /efs /keybackup