Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] '%ProgramFiles%\infrasecure+\infrasecure+\infraSECURE.exe' = '%ProgramFil...
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%ProgramFiles%\infrasecure+\infrasecure+\infraSECURE.exe' = '%ProgramF...
- C:\Temp\chkisresl.txt
- C:\Temp\chkisserv.bat
- C:\Temp\isuname.txt
- C:\Temp\isuname.txt
- C:\Temp\chkisserv.bat
- '<SYSTEM32>\cmd.exe' /c C:\Temp\chkisserv.bat
- '<SYSTEM32>\sc.exe' query iservice
- '<SYSTEM32>\attrib.exe' -R -S -H -A "C:\Temp\chkisserv.bat"
- '<SYSTEM32>\attrib.exe' -R -S -H -A "C:\Temp\chkisresl.txt"