Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{10006650-A707-22d2-9CBD-0000F87A469H}] 'StubPath' = '%CommonProgramFiles%\Microsoft Shared\ies\ies\ies.exe'
- '%WINDIR%\regedit.exe' /S "<Имя диска съемного носителя>:\1.reg"
- '<SYSTEM32>\cacls.exe' "%CommonProgramFiles%\Microsoft Shared\ies" /d everyone /e
- '<SYSTEM32>\cmd.exe' /c "%CommonProgramFiles%\Microsoft Shared\MSInfo\ntfs.bat"
- '<SYSTEM32>\cacls.exe' "%CommonProgramFiles%\Microsoft Shared\ies\ies" /d everyone /e
- %CommonProgramFiles%\Microsoft Shared\MSInfo\kkk.txt
- %CommonProgramFiles%\Microsoft Shared\MSInfo\IEFILES5.INI
- %CommonProgramFiles%\Microsoft Shared\MSInfo\ntfs.bat
- %CommonProgramFiles%\a2.txt
- %CommonProgramFiles%\Microsoft Shared\ies\ies\ies.exe
- %CommonProgramFiles%\Microsoft Shared\MSInfo\xinzhu.txt
- ClassName: 'RegEdit_RegEdit' WindowName: ''