Техническая информация
- '<SYSTEM32>\netsh.exe' firewall set opmode enable
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="Malwarebytes" dir=out action=block program="%ProgramFiles%\Malwarebytes\Anti-Malware\MBAMService.exe"
- %TEMP%\aut70fa.tmp
- C:\gecici_proje_klasoru\grey.gif
- %TEMP%\aut713a.tmp
- C:\gecici_proje_klasoru\görünmez.png
- %TEMP%\aut713b.tmp
- C:\gecici_proje_klasoru\e.link.exe
- %TEMP%\aut7255.tmp
- C:\gecici_proje_klasoru\lk.exe
- %TEMP%\aut7294.tmp
- C:\gecici_proje_klasoru\t2.vbs
- %TEMP%\7780.tmp\lk.bat
- nul
- %TEMP%\aut70fa.tmp
- %TEMP%\aut713a.tmp
- %TEMP%\aut713b.tmp
- %TEMP%\aut7255.tmp
- %TEMP%\aut7294.tmp
- %TEMP%\7780.tmp\lk.bat
- 'C:\gecici_proje_klasoru\lk.exe'
- '%WINDIR%\syswow64\wscript.exe' "C:\gecici_proje_klasoru\T2.vbs"
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\7780.tmp\LK.bat C:\gecici_proje_klasoru\LK.exe"' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\7780.tmp\LK.bat C:\gecici_proje_klasoru\LK.exe"
- '<SYSTEM32>\netsh.exe' advfirewall reset
- '<SYSTEM32>\attrib.exe' -r <DRIVERS>\etc\hosts
- '<SYSTEM32>\find.exe' /C /I "keystone.mwbsys.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\attrib.exe' +r "%ALLUSERSPROFILE%\Malwarebytes\MBAMService\config\LicenseConfig.json"
- '<SYSTEM32>\attrib.exe' +r "%ALLUSERSPROFILE%\Malwarebytes\MBAMService\config\LicenseConfig.json.bak"