Техническая информация
- '<SYSTEM32>\cmd.exe' /C takeown /f "%WINDIR%"
- '<SYSTEM32>\dllhost.exe'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\dllhost.exe
- %APPDATA%\Identities\receru.clb
- %APPDATA%\con.79506
- ClassName: 'ConsoleWindowClass' WindowName: ''
- ClassName: 'ProgMan' WindowName: ''