Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\CRMSvc] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\CRMSvc] 'ImagePath' = '"%WINDIR%\CRMSvc.exe"'
- 'CRMSvc' "%WINDIR%\CRMSvc.exe"
- 'CRMSvc' %WINDIR%\CRMSvc.exe
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name="CRMSvc" dir=in action=allow program="%WINDIR%\CRMSvc.exe" enable=yes
- %WINDIR%\crmsvc.exe
- %WINDIR%\crmsvc.installlog
- %WINDIR%\crmsvc.installstate
- %WINDIR%\crmsvc.installlog
- %WINDIR%\crmsvc.installstate
- '17#.9.8.183':2247
- '%WINDIR%\crmsvc.exe' --install
- '%WINDIR%\crmsvc.exe'
- '<SYSTEM32>\cmd.exe' /C netsh advfirewall firewall delete rule name="CRMSvc"' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /C netsh advfirewall firewall add rule name="CRMSvc" dir=in action=allow program="%WINDIR%\CRMSvc.exe" enable=yes' (со скрытым окном)
- '%WINDIR%\crmsvc.exe' --install' (со скрытым окном)
- '<SYSTEM32>\sc.exe' failure "CRMSvc" reset= 2 actions= restart/10000' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /C netsh advfirewall firewall delete rule name="CRMSvc"
- '<SYSTEM32>\netsh.exe' advfirewall firewall delete rule name="CRMSvc"
- '<SYSTEM32>\cmd.exe' /C netsh advfirewall firewall add rule name="CRMSvc" dir=in action=allow program="%WINDIR%\CRMSvc.exe" enable=yes
- '<SYSTEM32>\sc.exe' failure "CRMSvc" reset= 2 actions= restart/10000