Техническая информация
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'Regmonclass', WindowName: ''
- %TEMP%\996cf9d.bat
- %TEMP%\996cf9d.bat
- %TEMP%\996cf9d.bat
- ClassName: '18467-41' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\996CF9D.bat" "<Полный путь к файлу>" "' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\996CF9D.bat" "<Полный путь к файлу>" "
- '%WINDIR%\syswow64\takeown.exe' /f "<DRIVERS>\etc\hosts"
- '%WINDIR%\syswow64\attrib.exe' -h -s "<DRIVERS>\etc\hosts"
- '%WINDIR%\syswow64\attrib.exe' +h +s "<DRIVERS>\etc\hosts"