Техническая информация
- %TEMP%\nsl3010.tmp
- %TEMP%\nsr3031.tmp\system.dll
- <DRIVERS>\etc\hosts-backup
- %TEMP%\nsr3031.tmp\nsexec.dll
- %TEMP%\nsr3031.tmp\registry.dll
- <DRIVERS>\etc\hosts-backup
- %TEMP%\nsr3031.tmp\nsexec.dll
- %TEMP%\nsr3031.tmp\registry.dll
- %TEMP%\nsr3031.tmp\system.dll
- '%WINDIR%\syswow64\cmd.exe' /c "echo 127.0.0.1 www.ea###efi.com>> <DRIVERS>\etc\hosts"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c "echo 127.0.0.1 www.ea###efi.com>> <DRIVERS>\etc\hosts"