Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath 'C:\Addon\'"
- C:\addon\private-user.cmd
- C:\addon\default.bat
- C:\addon\suporte.exe
- nul
- %HOMEPATH%\desktop\contato direto (suporte).png
- C:\addon\private-user.cmd
- C:\addon\default.bat
- C:\addon\suporte.exe
- ClassName: 'EDIT' WindowName: ''
- 'C:\addon\suporte.exe'
- '<SYSTEM32>\cmd.exe' /c ""C:\Addon\DEFAULT.bat" "
- '<SYSTEM32>\cacls.exe' "<SYSTEM32>\config\system"
- '<SYSTEM32>\cmd.exe' /c ""C:\Addon\PRIVATE-USER.cmd" "
- '<SYSTEM32>\attrib.exe' -r <DRIVERS>\etc\hosts
- '<SYSTEM32>\attrib.exe' +r <DRIVERS>\etc\hosts