Техническая информация
- %TEMP%\res7d78.bat
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\res7D78.bat
- '%WINDIR%\syswow64\cmd.exe' /c vssadmin.exe delete shadows /all /quiet
- '%WINDIR%\syswow64\net.exe' share k0uj9rm62q="C:\Users"
- '%WINDIR%\syswow64\net1.exe' share k0uj9rm62q="C:\Users"
- '%WINDIR%\syswow64\cmd.exe' /c takeown /f "C:\Users" /r /d y
- '%WINDIR%\syswow64\takeown.exe' /f "C:\Users" /r /d y