Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\netsh.lnk
- [<HKLM>\SYSTEM\ControlSet001\Services\NWPS] 'Start' = '00000002'
- '%TEMP%\netsh.exe'
- '%TEMP%\winmine.exe'
- '%TEMP%\address.exe'
- '<SYSTEM32>\ping.exe' /n 15 127.1
- '<SYSTEM32>\reg.exe' query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName
- '<SYSTEM32>\taskkill.exe' /im 201209.exe /f
- '<SYSTEM32>\sc.exe' description NWPS "Portable Network Number Service"
- '<SYSTEM32>\sc.exe' CREATE NWPS binPath= "<SYSTEM32>\address.exe" Start= auto DISPLAYNAME= "Network logon " TYPE= own
- '<SYSTEM32>\reg.exe' query HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\run
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\address-1.bat" "
- '<SYSTEM32>\find.exe' /i "avp.exe"
- '<SYSTEM32>\find.exe' "1060"
- '<SYSTEM32>\sc.exe' getdisplayname "NWPS"
- <SYSTEM32>\address.exe
- %TEMP%\netsh.dll
- %TEMP%\netsh.ini
- %TEMP%\netsh.exe
- %TEMP%\winmine.exe
- %TEMP%\address.exe
- %TEMP%\1.tmp\address-1.bat
- %TEMP%\netsh.ini
- %TEMP%\winmine.exe
- '61.##8.77.96':80
- ClassName: '' WindowName: '(null)'
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'