Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\main.bat
- %TEMP%\rarsfx0\main.png
- %TEMP%\rarsfx0\main.bat
- %LOCALAPPDATA%\microsoft\windows\explorer\thumbcache_idx.db
- ClassName: 'Edit' WindowName: ''
- ClassName: 'NarratorUIClass' WindowName: ''
- ClassName: 'Progman' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\RarSFX0\main.bat" "
- '<SYSTEM32>\svchost.exe' -k appmodel -p -s camsvc
- '%WINDIR%\explorer.exe'