Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\risimg] 'Start' = '00000002'
- %WINDIR%\lsas.exe
- <SYSTEM32>\cmd.exe /c c:\ip.bat
- <SYSTEM32>\sc.exe delete risimg
- <SYSTEM32>\sc.exe config rfwservice start= disabled
- <SYSTEM32>\regsvr32.exe <SYSTEM32>\AlxRes.dll /s
- <SYSTEM32>\net.exe stop rfwservice
- <SYSTEM32>\regsvr32.exe <SYSTEM32>\AlxTB1.dll /s
- <SYSTEM32>\net1.exe stop rfwservice
- <SYSTEM32>\regsvr32.exe <SYSTEM32>\AlxTB2.dll /s
- <SYSTEM32>\spoolsv.exe
- <SYSTEM32>\alg.exe
- <SYSTEM32>\cscript.exe
- C:\ip.bat
- %WINDIR%\lsas.exe