Техническая информация
- '<SYSTEM32>\find.exe' /C /I "kingsoftstore.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\notepad.exe' %TEMP%\1.tmp\Serial.txt
- '<SYSTEM32>\find.exe' /C /I "kingsoft.com" <DRIVERS>\etc\hosts
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\activation.cmd" "
- '<SYSTEM32>\find.exe' /C /I "ksosoft.com" <DRIVERS>\etc\hosts
- %TEMP%\1.tmp\Serial.txt
- %TEMP%\1.tmp\activation.cmd
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'