Техническая информация
- %WINDIR%\syswow64\svchost.exe
- '<LOCALNET>.1.10':4444
- '%WINDIR%\syswow64\cmd.exe' /c reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v "DisableSmartScreenFilter" /t REG_DWORD /d "0" /f
- '%WINDIR%\syswow64\reg.exe' add "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v "DisableSmartScreenFilter" /t REG_DWORD /d "0" /f
- '%WINDIR%\syswow64\cmd.exe' /c @echo off rem ГђžГ‘‚клÑŽГ‘‡ГђВµГђВЅГђВёГђВµ заÑ‰ГђВёГ‘‚Г‘‹ ГђВІ Г‘€ГђВµГђВ°ГђВ»Г‘ŒГђВЅГђВѕГђВј ГђВІГ‘€ГђВµГђВјГђВµГђВЅГђВё reg delete "HKLM\Software\Policies\Microsoft\Windows ...
- '%WINDIR%\syswow64\cmd.exe' /c cmd.exe /c wevtutil.exe cl System
- '%WINDIR%\syswow64\cmd.exe' /c wevtutil.exe cl System
- '%WINDIR%\syswow64\wevtutil.exe' cl System
- '%WINDIR%\syswow64\cmd.exe' /c cmd.exe /c wevtutil.exe cl Security
- '%WINDIR%\syswow64\cmd.exe' /c wevtutil.exe cl Security
- '%WINDIR%\syswow64\wevtutil.exe' cl Security
- '%WINDIR%\syswow64\svchost.exe'