Техническая информация
- <SYSTEM32>\cmd.exe /c ""<SYSTEM32>\system.bat" "
- <SYSTEM32>\net1.exe stop SharedAccess
- %WINDIR%\regedit.exe /S %HOMEPATH%\Local Settings\Temp.\kill.reg
- <SYSTEM32>\ftp.exe -n -i -s:<DRIVERS>\config.sys
- <SYSTEM32>\net.exe stop Security Center
- <SYSTEM32>\cmd.exe /c ""<SYSTEM32>\update.bat" "
- <SYSTEM32>\net.exe stop SharedAccess
- <SYSTEM32>\net1.exe stop Security Center
- <SYSTEM32>\system.bat
- %TEMP%\kill.reg
- <DRIVERS>\config.sys
- <SYSTEM32>\borg.exe
- <SYSTEM32>\update.bat
- %TEMP%\kill.reg
- 'localhost':1048
- 'localhost':1046
- 'localhost':1052
- 'localhost':1050
- 'localhost':1044
- 'ft#.#ripod.com':21
- 'localhost':1037
- 'localhost':1042
- 'localhost':1040
- DNS ASK ft#.#ripod.com
- ClassName: 'RegEdit_RegEdit' WindowName: ''