Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ccsvchst' = '%WINDIR%\ccsvchst.exe'
- %WINDIR%\ccsvchst.exe
- <SYSTEM32>\reg.exe ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v ccsvchst /t REG_SZ /d %WINDIR%\ccsvchst.exe
- <SYSTEM32>\ftp.exe -s:script
- <SYSTEM32>\findstr.exe /C:"span class='ip'" IP
- <SYSTEM32>\netsh.exe firewall add portopening TCP 21 ftp enable
- <SYSTEM32>\netsh.exe firewall add portopening TCP 80 wget enable
- <SYSTEM32>\reg.exe Query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v ccsvchst
- %WINDIR%\script
- %WINDIR%\-bt.txt
- %WINDIR%\ccsvchst.exe
- %TEMP%\bt2862.bat
- %TEMP%\bt2862.bat
- %WINDIR%\-bt.txt
- %WINDIR%\script
- 'nk##.ucoz.com':21
- 'localhost':1044
- 'localhost':1041
- 'localhost':1039
- '92.#3.96.49':21
- DNS ASK nk##.ucoz.com
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''