Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] '8288' = '%CommonProgramFiles%\Microsoft Shared\Microsoft\Office.exe'
- '%PROGRAM_FILES%\ashampoo_burning_studio_11.0.3.exe'
- '%WINDIR%\Regedit.exe' /S "<Имя диска съемного носителя>:\1.reg"
- '<SYSTEM32>\cacls.exe' "%CommonProgramFiles%\Microsoft Shared\Microsoft" /d everyone /e
- %CommonProgramFiles%\microsoft shared\apii.txt
- %CommonProgramFiles%\1.bat
- \Device\HarddiskVolume3\1.reg
- %PROGRAM_FILES%\ashampoo_burning_studio_11.0.3.exe
- %CommonProgramFiles%\microsoft shared\Microsoft\Office.exe
- %CommonProgramFiles%\microsoft shared\Microsoft\api.txt
- \Device\HarddiskVolume3\1.reg
- ClassName: 'RegEdit_RegEdit' WindowName: ''