Техническая информация
- [HKLM\System\CurrentControlSet\Services\EFS] 'Start' = '00000002'
- %APPDATA%\microsoft\crypto\rsa\s-1-5-21-3691498038-2086406363-2140527554-1000\b432e34da57adbf7eee229651954ddbf_0cb67e2f-dc95-45ca-8fb8-69bde8e3f814
- %APPDATA%\microsoft\systemcertificates\my\certificates\c73d362513062f7bcce7b3d56371394cee9a396d
- C:\system volume information\efs0.log
- %LOCALAPPDATA%\microsoft\efs0.tmp
- %LOCALAPPDATA%\microsoft\spoolsvc.exe
- %LOCALAPPDATA%\microsoft\efs0.tmp
- C:\system volume information\efs0.log
- DNS ASK pp##e.bit
- '%LOCALAPPDATA%\microsoft\spoolsvc.exe'
- '<SYSTEM32>\efsui.exe' /efs /keybackup