Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '%WINDIR%\pl\services.exe,<SYSTEM32>\userinit.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%WINDIR%\pl\services.exe' = '%WINDIR%\pl\services.exe:*:Enabled:%USERNAME%500.txt'
- %WINDIR%\pl\services.exe
- <SYSTEM32>\attrib.exe %WINDIR%\pl\services.exe +h
- <SYSTEM32>\reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Userinit /t REG_SZ /d "%WINDIR%\pl\services.exe,<SYSTEM32>\userinit.exe" /f
- <SYSTEM32>\reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List" /v "%WINDIR%\pl\services.exe" /t REG_SZ /d "%WINDIR%\pl\services.exe:*:Enabled:%USERNAME%500.txt" /f
- <SYSTEM32>\attrib.exe <SYSTEM32>\config\qnlogger.ini -h
- <SYSTEM32>\attrib.exe %WINDIR%\pl\services.exe -h
- <SYSTEM32>\attrib.exe <SYSTEM32>\config\qnlogger.ini +h
- %WINDIR%\pl\%USERNAME%500.txt
- %WINDIR%\pl\services.exe
- <SYSTEM32>\config\qnlogger.ini
- %WINDIR%\pl\services.exe
- <SYSTEM32>\config\qnlogger.ini
- 'qn###ger.cba.pl':21
- 'qn####er66.cba.pl':21
- DNS ASK qn###ger.cba.pl
- DNS ASK qn####er66.cba.pl
- ClassName: 'ConsoleWindowClass' WindowName: ''