Техническая информация
- %TEMP%\7ZipSfx.000\a.cmd
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\7ZipSfx.000\a.cmd" "
- '<SYSTEM32>\find.exe' /C /I "bandicam.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "ssl.bandisoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "ssl.bandicam.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "cert.bandicam.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "52.79.86.85" <DRIVERS>\etc\hosts