Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Spooler] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\SYSTEM] 'Start' = '00000002'
- %PROGRAM_FILES%\SYSTEM.exe
- <SYSTEM32>\cmd.exe /c c:\del.bat
- <SYSTEM32>\net1.exe start SYSTEM
- <SYSTEM32>\sc.exe create SYSTEM binpath= "%PROGRAM_FILES%\SYSTEM.exe" type= share start= auto displayname= "SYSTEM" depend= RPCSS/Tcpip/IPSec
- <SYSTEM32>\spoolsv.exe
- C:\del.bat
- %PROGRAM_FILES%\hz_SYSTEM.dll
- <SYSTEM32>\SYSTEM.txt
- <SYSTEM32>\SYSTEM.jpg
- %PROGRAM_FILES%\SYSTEM.exe
- %PROGRAM_FILES%\SYSTEM.ini
- %PROGRAM_FILES%\hz_SYSTEM.dat
- %PROGRAM_FILES%\keyHook.dll
- %PROGRAM_FILES%\SYSTEM.exe
- %PROGRAM_FILES%\SYSTEM.ini
- %PROGRAM_FILES%\hz_SYSTEM.dat
- '<IP-адрес в локальной сети>':1100
- ClassName: 'MS_WINHELP' WindowName: ''