Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'msconfig' = '%WINDIR%\Prefetch\msconfig.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Remote Access] 'Start' = '00000002'
- <SYSTEM32>\msvcr71.dll
- <SYSTEM32>\msvcp71.dll
- <SYSTEM32>\msvcr71.dll
- <SYSTEM32>\msvcp71.dll
- '<SYSTEM32>\runassrv.exe' add /cmdline:"<SYSTEM32>\wupdmg.exe" /name:"Remote Access" /desc:"存储本地用户帐户的安全信息。"
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 1
- <SYSTEM32>\wupdmg.exe
- %TEMP%\aut4.tmp
- %WINDIR%\Prefetch\msconfig.exe
- %TEMP%\aut5.tmp
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- <SYSTEM32>\runassrv.exe
- %TEMP%\aut3.tmp
- %TEMP%\aut4.tmp
- %TEMP%\aut5.tmp
- %TEMP%\aut3.tmp
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp