Техническая информация
- '<SYSTEM32>\winlogon.exe'
- '%WINDIR%\XXInstall\ps.exe'
- '<SYSTEM32>\netsh.exe' firewall set service type = REMOTEDESKTOP mode = ENABLE
- '<SYSTEM32>\csrss.exe' ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitializat...
- %WINDIR%\Explorer.EXE
- %WINDIR%\XXInstall\ps.exe
- <SYSTEM32>\csrss.exe
- <SYSTEM32>\winlogon.exe
- %TEMP%\1.tmp
- %TEMP%\1.tmp
- 'localhost':3389
- '5.##.242.200':50381
- 'localhost':1038
- '82.##1.104.112':80
- http://82.##1.104.112/dbg.php?e=###################################################################