Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\r_server] 'Start' = '00000002'
- %WINDIR%\r_server.exe /service
- %WINDIR%\r_server.exe /start
- %WINDIR%\r_server.exe /install /silence
- <SYSTEM32>\net1.exe stop sharedaccess
- %WINDIR%\regedit.exe /s radmin.reg
- %WINDIR%\regedit.exe /s shardaccess.reg
- <SYSTEM32>\wscript.exe "%WINDIR%\520hack.vbs"
- <SYSTEM32>\net.exe stop sharedaccess
- %WINDIR%\sharedaccess.reg
- %WINDIR%\admin.reg
- %WINDIR%\r_server.exe
- %WINDIR%\520hack.vbs
- %WINDIR%\AdmDll.dll
- %WINDIR%\raddrv.dll
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'EDIT' WindowName: ''