Техническая информация
- %TEMP%\rarsfx0\ehs_nt64.msi
- %TEMP%\rarsfx0\cfg.xml
- %TEMP%\rarsfx0\btacs.txt
- %TEMP%\rarsfx0\host.cmd
- nul
- ClassName: 'EDIT' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\RarSFX0\HOST.CMD" "
- '<SYSTEM32>\cacls.exe' "<SYSTEM32>\config\system"
- '<SYSTEM32>\attrib.exe' -r <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "BTACS Host Block" <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "expire.eset.com " <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "edf.eset.com " <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "BTACS Host Block Finish" <DRIVERS>\etc\hosts