Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe netcmd.exe s'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{223801KEY0-YUS5OK-D1KOW-F49T8-TVUI81RWM141}] 'StubPath' = 'netconfig.exe'
- <SYSTEM32>\netcmd.exe s
- %WINDIR%\netconfig.exe s
- %WINDIR%\netconfig.exe
- %TEMP%\TMP301.tmp
- <SYSTEM32>\netcmd.exe
- %TEMP%\TMP011.tmp
- %WINDIR%\netconfig.exe
- <SYSTEM32>\netcmd.exe
- %TEMP%\TMP301.tmp
- %TEMP%\TMP011.tmp