Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\winmgmt] 'Start' = '00000002'
- '<SYSTEM32>\sc.exe' config Winmgmt start= AUTO
- '<SYSTEM32>\net.exe' START Winmgmt
- '<SYSTEM32>\net1.exe' START Winmgmt
- '<SYSTEM32>\cmd.exe' /c NET START Winmgmt
- '<SYSTEM32>\cmd.exe' /c 注册控件WIN7右键管理员运行.bat
- '<SYSTEM32>\cmd.exe' /c del *.cmd
- '<SYSTEM32>\cmd.exe' /c sc config Winmgmt start= AUTO
- %TEMP%\~DFC10B.tmp
- %TEMP%\~DFC10B.tmp
- 't4.##itsa.com':80
- 'localhost':1037
- http://t4.##itsa.com/login1/openflag.asp?fl####
- DNS ASK t4.##itsa.com