Техническая информация
- '<SYSTEM32>\taskkill.exe' /IM DRW.exe /f
- '<SYSTEM32>\taskkill.exe' /IM DRWUI.exe /f
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="DRW.exe" dir=out program="%ProgramFiles%\EaseUS\EaseUS Data Recovery Wizard\DRW.exe" action=block
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="DRWUI.exe" dir=out program="%ProgramFiles%\EaseUS\EaseUS Data Recovery Wizard\DRWUI.exe" action=block
- %TEMP%\aut598d.tmp
- %PROGRAMDATA%\setup.exe
- %TEMP%\aut599e.tmp
- %PROGRAMDATA%\setup2.exe
- %TEMP%\80fb.tmp\block in host+firewall.cmd
- nul
- %TEMP%\aut598d.tmp
- %TEMP%\aut599e.tmp
- %TEMP%\80fb.tmp\block in host+firewall.cmd
- ClassName: '' WindowName: ''
- '%PROGRAMDATA%\setup.exe'
- '%PROGRAMDATA%\setup2.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\80FB.tmp\Block in Host+Firewall.cmd" %PROGRAMDATA%\Setup.exe"' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\80FB.tmp\Block in Host+Firewall.cmd" %PROGRAMDATA%\Setup.exe"
- '<SYSTEM32>\fltmc.exe'
- '<SYSTEM32>\attrib.exe' -r <DRIVERS>\etc\hosts
- '<SYSTEM32>\attrib.exe' +r <DRIVERS>\etc\hosts