Техническая информация
- [HKLM\System\CurrentControlSet\Services\svcLanSerfer] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\svcLanSerfer] 'ImagePath' = '%WINDIR%\SysWOW64\LanClient.exe'
- 'svcLanSerfer' %WINDIR%\SysWOW64\LanClient.exe
- Библиотека-обработчик для всех процессов: %WINDIR%\SysWOW64\hlibstaex.dll
- %WINDIR%\syswow64\clientsetup.exe
- %WINDIR%\syswow64\zclientoptions.lco
- %WINDIR%\syswow64\zlib.dll
- %WINDIR%\syswow64\zoptions.lco
- %TEMP%\gert0.dll
- %TEMP%\ci0-temp\clientlan25.set
- %TEMP%\lanclient.exe
- %TEMP%\hlibstaex.dll
- %TEMP%\setup.exe
- %TEMP%\ci0-temp\clientlan25.set
- %TEMP%\gert0.dll
- %TEMP%\lanclient.exe в %WINDIR%\syswow64\lanclient.exe
- %TEMP%\hlibstaex.dll в %WINDIR%\syswow64\hlibstaex.dll
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- '%WINDIR%\syswow64\clientsetup.exe'
- '%TEMP%\setup.exe'
- '%WINDIR%\syswow64\lanclient.exe' /LANSERSETUP /SILENT
- '%WINDIR%\syswow64\lanclient.exe'
- '%WINDIR%\syswow64\net.exe' start svcLanSerfer (со скрытым окном)
- '%WINDIR%\syswow64\net1.exe' start svcLanSerfer
- '%WINDIR%\syswow64\lanclient.exe' /LANSERSETUP /SILENT (со скрытым окном)