Техническая информация
- %TEMP%\1.tmp\disable_activation.cmd
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\disable_activation.cmd" <Полный путь к файлу>"
- '<SYSTEM32>\find.exe' /C /I "tonec.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "www.to##c.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "registeridm.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "www.re####eridm.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "secure.registeridm.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "internetdownloadmanager.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "www.in#######ownloadmanager.com" <DRIVERS>\etc\hosts