Техническая информация
- <SYSTEM32>\reg.exe delete "HKEY_LOCAL_MACHINE\SYSTEM\RAdmin" /f
- <SYSTEM32>\reg.exe import 111.reg
- %WINDIR%\regedit.exe /s 111.reg
- <SYSTEM32>\cmd.exe /c ""%TEMP%\RarSFX0\111.bat" "
- <SYSTEM32>\netsh.exe firewall add allowedprogram "%WINDIR%\help\svchost.exe" "Remote %USERNAME% Server" ENABLE
- <SYSTEM32>\reg.exe export "HKEY_LOCAL_MACHINE\SYSTEM\RAdmin" 123.reg
- %TEMP%\RarSFX0\svchost.exe
- %WINDIR%\Help\admdll.dll
- %WINDIR%\Help\svchost.exe
- %TEMP%\RarSFX0\111.reg
- %TEMP%\RarSFX0\111.bat
- %TEMP%\RarSFX0\AdmDll.dll
- %TEMP%\RarSFX0\123.reg
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''