Техническая информация
- '%TEMP%\nsw3.tmp\ns5.tmp' cmd.exe /c cacls "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk" /E /R %username% %USERNAME%s SYSTEM Users "power users"
- '%TEMP%\nsw3.tmp\ns6.tmp' cmd.exe /c cacls "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk" /E /P everyone:r
- '%TEMP%\~nsu.tmp\Au_.exe' _?=<Текущая директория>\
- '%TEMP%\nsw3.tmp\ns4.tmp' cacls "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk" /E /G everyone:f
- '<SYSTEM32>\regini.exe' %TEMP%\$~LOGU.TMP
- '<SYSTEM32>\regini.exe' %TEMP%\$~LOGI.TMP
- '<SYSTEM32>\cacls.exe' "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk" /E /P everyone:r
- '<SYSTEM32>\cacls.exe' "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk" /E /G everyone:f
- '<SYSTEM32>\cacls.exe' "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk" /E /R %USERNAME% %USERNAME%s SYSTEM Users "power users"
- %TEMP%\nsw3.tmp\ns6.tmp
- %TEMP%\nsw3.tmp\ns5.tmp
- %TEMP%\$~LOGI.TMP
- %TEMP%\$~LOGU.TMP
- %TEMP%\nsw3.tmp\ns4.tmp
- %TEMP%\nsw3.tmp\System.dll
- %TEMP%\~nsu.tmp\Au_.exe
- %TEMP%\nsw3.tmp\nsExec.dll
- %TEMP%\nsw3.tmp\ShellLink.dll
- %TEMP%\nsw3.tmp\nsExec.dll
- %TEMP%\nsw3.tmp\ShellLink.dll
- %TEMP%\nsw3.tmp\System.dll
- %TEMP%\nsw3.tmp\ns4.tmp
- %TEMP%\nsw3.tmp\ns5.tmp
- %TEMP%\nsw3.tmp\ns6.tmp