Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\r_server] 'Start' = '00000002'
- '<SYSTEM32>\lsas.exe' /service
- '<SYSTEM32>\lsas.exe' /install /silence
- '<SYSTEM32>\attrib.exe' +r +h +s <SYSTEM32>\lsas.exe
- '<SYSTEM32>\netsh.exe' firewall add portopening TCP 3389 RemoteDesktop
- '<SYSTEM32>\attrib.exe' +r +h +s <SYSTEM32>\Admdll.dll
- '<SYSTEM32>\sc.exe' config r_server displayname= "Network DDE Management"
- '<SYSTEM32>\attrib.exe' +r +h +s <SYSTEM32>\raddrv.dll
- '%WINDIR%\regedit.exe' -s <SYSTEM32>\lsas.reg
- '<SYSTEM32>\cmd.exe' /c ""<SYSTEM32>\setup.bat" "
- '<SYSTEM32>\net1.exe' start r_server
- '<SYSTEM32>\netsh.exe' firewall add portopening TCP 4899 Thunder4
- '<SYSTEM32>\netsh.exe' firewall add portopening TCP 4898 Thunder5
- <SYSTEM32>\lsas.exe
- <SYSTEM32>\zcm.txt
- <SYSTEM32>\lsas.reg
- <SYSTEM32>\setup.bat
- <SYSTEM32>\raddrv.dll
- <SYSTEM32>\AdmDll.dll
- <SYSTEM32>\radmin.exe
- <SYSTEM32>\2052.lng
- <SYSTEM32>\Visedll.dll
- <SYSTEM32>\raddrv.dll
- <SYSTEM32>\AdmDll.dll
- <SYSTEM32>\lsas.exe
- <SYSTEM32>\radmin.exe
- <SYSTEM32>\lsas.reg
- <SYSTEM32>\zcm.txt
- ClassName: 'RegEdit_RegEdit' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'