Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WinMe' = 'C:/Windows/Kernel.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- Диспетчера задач (Taskmgr)
- Редактора реестра (RegEdit)
- <SYSTEM32>\taskkill.exe /F /IM server.pif
- <SYSTEM32>\taskkill.exe /F /IM server.bat
- <SYSTEM32>\taskkill.exe /F /IM server.com
- <SYSTEM32>\taskkill.exe /F /IM server.scr
- <SYSTEM32>\taskkill.exe /F /IM server.exe
- <SYSTEM32>\cmd.exe /c C:/windows/system32/Login.bat
- <SYSTEM32>\reg.exe add HKCU\software\microsoft\windows\currentversion\policies\system /v disableregistrytools /t reg_dword /d "1" /f
- <SYSTEM32>\reg.exe add HKCU\software\microsoft\windows\currentversion\policies\system /v disabletaskmgr /t reg_dword /d "1" /f
- %WINDIR%\Kernel.exe
- <SYSTEM32>\Login.bat
- 'localhost':8560
- ClassName: '' WindowName: ''