Техническая информация
- <SYSTEM32>\cmd.exe
- %ALLUSERSPROFILE%\eset\delpico.exe
- %ALLUSERSPROFILE%\eset\eset security\license\license.lf
- %TEMP%\4d26.tmp\4d36.tmp\4d37.bat
- nul
- %TEMP%\4d26.tmp\4d36.tmp\4d37.bat
- ClassName: 'EDIT' WindowName: ''
- '%ALLUSERSPROFILE%\eset\delpico.exe'
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\4D26.tmp\4D36.tmp\4D37.bat %ALLUSERSPROFILE%\ESET\DelPico.exe"
- '<SYSTEM32>\find.exe' /i "expire.eset.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\fltmc.exe'