Техническая информация
- '<SYSTEM32>\taskkill.exe' /IM AliyunWrapExe.exe /f
- '<SYSTEM32>\taskkill.exe' /IM DRW.exe /f
- '<SYSTEM32>\taskkill.exe' /IM DRWUI.exe /f
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="DRW.exe" dir=out program="%ProgramFiles%\EaseUS\EaseUS Data Recovery Wizard\DRW.exe" action=block
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="DRWUI.exe" dir=out program="%ProgramFiles%\EaseUS\EaseUS Data Recovery Wizard\DRWUI.exe" action=block
- %TEMP%\aut17ea.tmp
- C:\gecici_proje_klasoru\grey.gif
- %TEMP%\aut17fb.tmp
- C:\gecici_proje_klasoru\görünmez.png
- %TEMP%\aut183a.tmp
- C:\gecici_proje_klasoru\e.exe
- %TEMP%\aut186a.tmp
- C:\gecici_proje_klasoru\easeus 13.exe
- %TEMP%\aut189a.tmp
- C:\gecici_proje_klasoru\easeus drw keygen.exe
- %TEMP%\1b45.tmp\easeus 13.bat
- %TEMP%\aut17ea.tmp
- %TEMP%\aut17fb.tmp
- %TEMP%\aut183a.tmp
- %TEMP%\aut186a.tmp
- %TEMP%\aut189a.tmp
- %TEMP%\1b45.tmp\easeus 13.bat
- ClassName: '' WindowName: ''
- 'C:\gecici_proje_klasoru\easeus 13.exe'
- 'C:\gecici_proje_klasoru\easeus drw keygen.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1B45.tmp\EaseUS 13.bat" "C:\gecici_proje_klasoru\EaseUS 13.exe""' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1B45.tmp\EaseUS 13.bat" "C:\gecici_proje_klasoru\EaseUS 13.exe""
- '<SYSTEM32>\attrib.exe' -r <DRIVERS>\etc\hosts
- '<SYSTEM32>\attrib.exe' +r <DRIVERS>\etc\hosts