Техническая информация
- '<SYSTEM32>\attrib.exe' -R -a -S -H <DRIVERS>\Etc\HOstS.iCs
- '<SYSTEM32>\attrib.exe' +r +s <DRIVERS>\etc\hosts
- '<SYSTEM32>\attrib.exe' +r +s <DRIVERS>\etc\hosts.ics
- '<SYSTEM32>\attrib.exe' -R -a -S -H <DRIVERS>\Etc\HOStS
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\bat.bat" "
- '<SYSTEM32>\reg.exe' add "HkEY_cURRENt_USER\SOFtWaRE\MIcROSOFt\WINdOWS\cuRRENtVERSION\INtERNEt SEttINgS" /v "DNScacHEtIMEOut" /t "REG_DWORD" /d "0" /F
- '<SYSTEM32>\reg.exe' add "HkEY_cURRENt_USER\SOFtWaRE\MIcROSOFt\WINdOWS\cuRRENtVERSION\INtERNEt SEttINgS" /v "SERvERINFOtIMEOut" /t "REG_DWORD" /d "0" /F
- ClassName: 'OLLYDBG' WindowName: ''
- ClassName: 'FileMonClass' WindowName: ''
- %TEMP%\1.tmp\bat.bat
- <DRIVERS>\etc\hosts
- %TEMP%\1.tmp\bat.bat
- %WINDIR%\Temp\Perflib_Perfdata_7e8.dat
- <DRIVERS>\etc\HoSts.ics
- ClassName: '18467-41' WindowName: ''