Техническая информация
- [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'explorer.exe'
- \device\harddiskvolume1\boot\bcd.log
- \device\harddiskvolume1\boot\bcd
- '<SYSTEM32>\cmd.exe' /c sc stop BlockAllAccess
- '<SYSTEM32>\sc.exe' stop BlockAllAccess
- '<SYSTEM32>\cmd.exe' /c sc delete BlockAllAccess
- '<SYSTEM32>\sc.exe' delete BlockAllAccess
- '<SYSTEM32>\cmd.exe' /c shutdown /r /f /t 5
- '<SYSTEM32>\shutdown.exe' /r /f /t 5