Техническая информация
- '<SYSTEM32>\cacls.exe' "%APPDATA%\Tencent\QQPCMgr" /d everyone
- '<SYSTEM32>\attrib.exe' "%APPDATA%\Tencent\QQDoctor"
- '<SYSTEM32>\cacls.exe' "%APPDATA%\Tencent\QQDoctor" /d everyone
- '<SYSTEM32>\attrib.exe' "%APPDATA%\Tencent\QQ\SafeBase"
- '<SYSTEM32>\cacls.exe' "%APPDATA%\Tencent\QQ\SafeBase" /d everyone
- '<SYSTEM32>\attrib.exe' "%APPDATA%\Tencent\QQPCMgr"
- ClassName: 'PROCMON_WINDOW_CLASS' WindowName: ''
- ClassName: 'FileMonClass' WindowName: ''
- ClassName: 'OLLYDBG' WindowName: ''
- %TEMP%\~1.bat
- %TEMP%\~1.bat
- %TEMP%\~1.bat
- ClassName: '18467-41' WindowName: ''