Техническая информация
- <SYSTEM32>\attrib.exe -h -s "<DRIVERS>\etc\hosts"
- <SYSTEM32>\attrib.exe +h +s "<DRIVERS>\etc\hosts"
- <SYSTEM32>\cmd.exe /c ""%TEMP%\1.tmp\troy_mcclur.bat""
- %WINDIR%\NOTEPAD.EXE
- <DRIVERS>\etc\hюsts
- %TEMP%\1.tmp\troy_mcclur.bat
- %TEMP%\1.tmp\troy_mcclur.bat
- ClassName: 'Shell_TrayWnd' WindowName: ''