Техническая информация
- <SYSTEM32>\taskkill.exe /f /fi cmd.exe
- <SYSTEM32>\xcopy.exe /y scripts.ini <SYSTEM32>\GroupPolicy\Machine\Scripts\
- <SYSTEM32>\gpupdate.exe /force
- <SYSTEM32>\cmd.exe /c %WINDIR%\360tray.bat
- <SYSTEM32>\rundll32.exe newarea.dll,main
- <SYSTEM32>\attrib.exe <SYSTEM32>\GroupPolicy\*.* -r -s -h /s /d
- <Текущая директория>\scripts.ini
- <SYSTEM32>\GroupPolicy\Machine\Scripts\scripts.ini
- %HOMEPATH%\ntuser.pol
- <SYSTEM32>\newarea.dll
- %WINDIR%\360tray.bat
- %WINDIR%\CHAIN.bat
- <SYSTEM32>\GroupPolicy\gpt.ini
- 'gh###.3322.org':1100
- DNS ASK gh###.3322.org