Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '' = '%WINDIR%\1.vbs'
- <SYSTEM32>\123\1.exe
- <SYSTEM32>\cacls.exe <DRIVERS>\etc\hosts /g everyone:r
- <SYSTEM32>\attrib.exe +r +a +s +h <DRIVERS>\etc\hosts
- <SYSTEM32>\wscript.exe "%WINDIR%\1.vbs"
- <SYSTEM32>\reg.exe add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /ve /d "%WINDIR%\1.vbs" /f
- <SYSTEM32>\cacls.exe <DRIVERS>\etc\hosts /g everyone:f
- <SYSTEM32>\cmd.exe /c ""%TEMP%\1.tmp\ёДHOSTSОДјю.bat" "
- <SYSTEM32>\ping.exe 127.0.0.1
- <SYSTEM32>\attrib.exe -r -a -s -h <DRIVERS>\etc\hosts
- %TEMP%\1.tmp\ёДHOSTSОДјю.bat
- %WINDIR%\1.vbs
- <SYSTEM32>\123\hosts
- <SYSTEM32>\123\1.exe
- <DRIVERS>\etc\hosts
- '20#.#26.136.158':8080
- 'localhost':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''