Техническая информация
- %PROGRAM_FILES%\Windows\system.exe
- <SYSTEM32>\cacls.exe "%PROGRAM_FILES%\Windows\sys.exe" /P users:R
- <SYSTEM32>\attrib.exe "%PROGRAM_FILES%\Windows\sys.exe" +R
- <SYSTEM32>\cacls.exe "%PROGRAM_FILES%\Windows\system.exe" /P users:R
- <SYSTEM32>\attrib.exe "%PROGRAM_FILES%\Windows\system.exe" +R
- <SYSTEM32>\cacls.exe "C:\sys.exe" /P users:R
- <SYSTEM32>\attrib.exe +h "C:\sys.exe"
- <SYSTEM32>\attrib.exe +h "%PROGRAM_FILES%\Windows"
- <SYSTEM32>\attrib.exe "C:\sys.exe" +R
- <SYSTEM32>\cmd.exe /c ""<SYSTEM32>\qx.bat" "
- %PROGRAM_FILES%\Windows\SDRW.jpg
- %PROGRAM_FILES%\Windows\sys2.exe
- <SYSTEM32>\qx.bat
- C:\sys.jpg
- %PROGRAM_FILES%\Windows\sys.exe
- %PROGRAM_FILES%\Windows\system.jpg
- C:\sys.exe