Техническая информация
- %TEMP%\48n77bhe.cmd
- nul
- %TEMP%\48n77bhe.cmd
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\48N77BHE.cmd" "<Полный путь к файлу>" "' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\48N77BHE.cmd" "<Полный путь к файлу>" "
- '%WINDIR%\syswow64\takeown.exe' /f "<DRIVERS>\etc\hosts" /a
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" echo y"
- '%WINDIR%\syswow64\icacls.exe' <DRIVERS>\etc\hosts /c /grant "administrators:F"
- '%WINDIR%\syswow64\attrib.exe' -h -r -s <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "CyberMania CCleaner Block" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "0.0.0.0 license-api.ccleaner.com" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\find.exe' /C /I "CCleaner Block End" <DRIVERS>\etc\hosts
- '%WINDIR%\syswow64\ipconfig.exe' -flushdns