Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoSMHelp' = '00000001'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1601' = '00000000'
- %WINDIR%\system\reg.reg
- %TEMP%\7zsfx000.cmd
- %TEMP%\7zsfx000.cmd
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%WINDIR%\syswow64\regedit.exe' /s "%WINDIR%\system\reg.reg"
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\7ZSfx000.cmd" " (со скрытым окном)