Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'shell' = 'explorer.exe <DRIVERS>\lsass.exe'
- '<SYSTEM32>\reg.exe' ADD "hklm\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /v shell /t REG_SZ /d "explorer.exe <DRIVERS>\lsass.exe" /f
- '<SYSTEM32>\cmd.exe' /c <DRIVERS>\winn.bat
- <SYSTEM32>\1.txt
- <SYSTEM32>\2.txt
- <DRIVERS>\winn.bat
- <SYSTEM32>\win.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\ip[1].php
- <DRIVERS>\lsass.exe
- %WINDIR%\Media\Windows XP Start.wav
- 'pc###plive.com':80
- 'localhost':1036
- pc###plive.com/ip.php
- DNS ASK pc###plive.com