Техническая информация
- скрытых файлов
- <SYSTEM32>\attrib.exe -h -r "%HOMEPATH%\Desktop\═°╥╫--╙╨╡└╦╤╦ў.lnk"
- <SYSTEM32>\attrib.exe -h -r "%HOMEPATH%\Desktop\╠╘▒ж.lnk"
- <SYSTEM32>\attrib.exe -h -r "%HOMEPATH%\Desktop\░┘╢╚╦╤╦ў.lnk"
- <SYSTEM32>\attrib.exe -h -r "%HOMEPATH%\Desktop\╦╤╣╖╥╗╧┬.lnk"
- <SYSTEM32>\attrib.exe -h -r "%HOMEPATH%\Desktop\╠╘▒ж.url"
- <SYSTEM32>\attrib.exe -h -r "%HOMEPATH%\Desktop\░┘╢╚╦╤╦ў.url"
- <SYSTEM32>\attrib.exe -h -r "%HOMEPATH%\Desktop\╠╘▒ж╚╚┬Ї.lnk"
- <SYSTEM32>\cacls.exe "%APPDATA%\Microsoft\Internet Explorer\Quick Launch" /T /G everyone:F
- <SYSTEM32>\route.exe /p add 59.63.158.214 mask 255.255.255.255 192.168.1.0
- <SYSTEM32>\reg.exe query "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" /v "Desktop"
- <SYSTEM32>\cmd.exe /c """%TEMP%\10CF.CMD"""
- <SYSTEM32>\route.exe /p add 117.40.91.37 mask 255.255.255.255 192.168.1.0
- <SYSTEM32>\cacls.exe "%HOMEPATH%\Desktop" /T /G everyone:F
- <SYSTEM32>\wscript.exe "<Текущая директория>\file.vbs"
- <SYSTEM32>\route.exe /p add 218.65.49.157 mask 255.255.255.255 192.168.1.0
- <Текущая директория>\file.vbs
- %TEMP%\10CF.CMD
- <Текущая директория>\file.vbs