Техническая информация
- '<SYSTEM32>\taskkill.exe' /IM DRW.exe /f
- '<SYSTEM32>\taskkill.exe' /IM DRWUI.exe /f
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="DRW.exe" dir=out program="%ProgramFiles%\EaseUS\EaseUS Data Recovery Wizard\DRW.exe" action=block
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="DRWUI.exe" dir=out program="%ProgramFiles%\EaseUS\EaseUS Data Recovery Wizard\DRWUI.exe" action=block
- %TEMP%\e017.tmp\block in host+firewall.cmd
- nul
- %TEMP%\e017.tmp\block in host+firewall.cmd
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\E017.tmp\Block in Host+Firewall.cmd" <Полный путь к файлу>"' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\E017.tmp\Block in Host+Firewall.cmd" <Полный путь к файлу>"
- '<SYSTEM32>\fltmc.exe'
- '<SYSTEM32>\attrib.exe' -r <DRIVERS>\etc\hosts
- '<SYSTEM32>\attrib.exe' +r <DRIVERS>\etc\hosts