Техническая информация
- %TEMP%\flashremove$\crack.cmd
- %TEMP%\flashremove$\removereg.reg
- %TEMP%\flashremove$\uninstall_flash_player.exe
- %WINDIR%\syswow64\macromed\temp\{00d69c84-797e-4762-89a7-5f80a29dee1e}\fpb.tmp
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- '%TEMP%\flashremove$\uninstall_flash_player.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\flashremove$\crack.cmd" "
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" type <DRIVERS>\etc\hosts "
- '%WINDIR%\syswow64\find.exe' "geo2.adobe.com"
- '%WINDIR%\syswow64\regedit.exe' /s .\removereg.reg
- '%WINDIR%\syswow64\cmd.exe' /c dir pep*.* /b/ad