Техническая информация
- %TEMP%\RarSFX0\Bloc.drivereasy.cmd
- %TEMP%\RarSFX0\Bloc.drivereasy.cmd
- ClassName: 'EDIT' WindowName: ''
- '<SYSTEM32>\find.exe' /C /I "app.drivereasy.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\attrib.exe' +r <DRIVERS>\etc\hosts
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\RarSFX0\Bloc.drivereasy.cmd" "
- '<SYSTEM32>\attrib.exe' -r <DRIVERS>\etc\hosts