Техническая информация
- '<SYSTEM32>\taskkill.exe' /im ekrn.exe /f
- '<SYSTEM32>\taskkill.exe' /im ScanFrm.exe /f
- '<SYSTEM32>\conhost.exe' func.dll, droqp
- '<SYSTEM32>\taskkill.exe' /im egui.exe /f
- '<SYSTEM32>\cacls.exe' %WINDIR% /e /p everyone:f
- '<SYSTEM32>\cacls.exe' "%TEMP%\" /e /p everyone:f
- '<SYSTEM32>\sc.exe' config ekrn start= disabled
- <DRIVERS>\acpiec.sys
- <SYSTEM32>\func.dll
- DNS ASK dn#.##ftncsi.com
- DNS ASK www.qv##678.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''