Техническая информация
- %TEMP%\1.tmp\safeejectoperation.exe
- %TEMP%\1.tmp\RemoveDrive.exe "USB\VID_0718*" "USB\VID_1A4B*" "USB\VID_124C*"
- <SYSTEM32>\wscript.exe "%TEMP%\1.tmp\closeallusbapps.vbs"
- <SYSTEM32>\taskkill.exe /f /IM "ACCESSAntivirusScanner.exe" /IM "AV_GUARD.exe" /IM "McAfeeEncryptedUSBAntivirus.exe" /IM "SSDESDService.exe"
- <SYSTEM32>\cmd.exe /c ""%TEMP%\1.tmp\EJECT_USB_3.CMD" "
- %TEMP%\1.tmp\RemoveDrive.exe
- %TEMP%\1.tmp\safeejectoperation.exe
- %TEMP%\1.tmp\EJECT_USB_3.CMD
- %TEMP%\1.tmp\closeallusbapps.vbs
- %TEMP%\1.tmp\safeejectoperation.exe
- %TEMP%\1.tmp\EJECT_USB_3.CMD
- %TEMP%\1.tmp\closeallusbapps.vbs
- %TEMP%\1.tmp\RemoveDrive.exe
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''