Technical Information
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'SmartIT Client' = 'C:\SmartIT\ITCurusr.exe'
- [HKLM\SYSTEM\CurrentControlSet\Services\LsProft] 'ImagePath' = 'system32\DRIVERS\LsProft.sys'
- [HKLM\SYSTEM\CurrentControlSet\Services\LsProft] 'Start' = '00000000'
- [HKLM\SYSTEM\CurrentControlSet\Services\ITFF] 'ImagePath' = 'system32\Drivers\itff.sys'
- [HKLM\System\CurrentControlSet\Services\ITClientSvs] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\ITClientSvs] 'ImagePath' = 'C:\SmartIT\ITAgentSvc.exe -DualMode'
- 'ITFF' system32\Drivers\itff.sys
- 'ITClientSvs' C:\SmartIT\ITAgentSvc.exe -DualMode
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\] 'DoNotAllowExceptions' = '00000000'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\] 'DoNotAllowExceptions' = '00000000'
- '%WINDIR%\syswow64\net.exe' stop ITClientSvs
- '%WINDIR%\syswow64\net.exe' stop AlfaFF
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\afpansi.sys
- C:\smartit\webm.ls
- %WINDIR%\syswow64\webdeny.html
- C:\smartit\swmsg.ls
- C:\smartit\itwp.ls
- C:\smartit\itpat.exe
- C:\smartit\wusscan.dll
- C:\smartit\itclient.lng
- C:\smartit\filetrnsf.ls
- C:\smartit\remark.lng
- C:\smartit\lscommc.dll
- C:\smartit\statusstrings.dll
- C:\smartit\iamtagent.dll
- C:\smartit\iamtstoraccess.dll
- C:\smartit\savengui.exe
- C:\smartit\invdev.ls
- C:\smartit\invinfo.ls
- C:\smartit\itagentsvc.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\swmsg.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\uninsaff.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\uninsafm.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\uninsafp.exe
- C:\smartit\itagent.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\statusstrings.dll
- C:\smartit\itclient.ini
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\uninsitff.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\wusscan.dll
- C:\smartit\log\c20230930.log
- C:\smartit\itcurusr.exe
- %WINDIR%\syswow64\stickyapp32.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\webdeny.html
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\webm.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\wuag2.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itprofile.ini
- C:\smartit\fwtool.exe
- C:\smartit\imset.ini
- C:\smartit\immex.ls
- %WINDIR%\syswow64\immex.dll
- C:\smartit\skypemut.lng
- C:\smartit\ecyptm.ls
- C:\smartit\iscypt.exe
- C:\smartit\imm.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\spl2emf.ls
- C:\smartit\emf2jpg.ls
- C:\smartit\aw_sas.dll
- C:\smartit\lsrcshk.dll
- <DRIVERS>\lscdft.sys
- %WINDIR%\temp\udd4e1.tmp
- %WINDIR%\temp\udd14bb.tmp
- C:\smartit\itprofile.ini
- C:\smartit\iscyptext.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\stickyapp32.dll
- C:\smartit\printjob.ls
- <SYSTEM32>\itffx64ctr.ls
- C:\smartit\invnt.ls
- C:\smartit\filelog.ls
- C:\smartit\appm.ls
- C:\smartit\procmang.exe
- <SYSTEM32>\itff.dll
- C:\smartit\spl2emf.ls
- C:\smartit\lscommcex.dll
- C:\smartit\libeay32.dll
- %WINDIR%\syswow64\itffx64ctr.ls
- %WINDIR%\syswow64\institff.exe
- %WINDIR%\syswow64\uninsitff.exe
- C:\smartit\itfflock.ls
- C:\smartit\printm.ls
- C:\smartit\itffx64ctr.ls
- <DRIVERS>\itff.sys
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\smssnt.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\smss9x.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\smss.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\immex.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\imset.ini
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\instafm.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\instafp.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\iamtstoraccess.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\aw_sas32.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\immex.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\install.bat
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\invnt.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\invnt9x.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\iscypt.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\iscyptext.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\institff.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\invdev.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\invinfo.ls
- C:\smartit\itguid.ini
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\iscyptextx64.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\filetrnsf.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\filelog9x.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\filelog.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\emf2jpg.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\ecyptm.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\drvcrypt.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\aw_sas64.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\iamtagent.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\appmnt.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\appm9x.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\alfafm.vxd
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\alfafm.sys
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\afpuni.vxd
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\afpuni.sys
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\afpansi.vxd
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\fwtool.exe
- C:\smartit\itrcs.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itclient.ini
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itff.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\lscommcex9x.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\lsrcshk.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\msvcp80.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\msvcr80.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\multiapp9x.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itclient.lng
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\lscommcex.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\lscommc.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\procmang.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\remark.lng
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\savengui.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\sfxparamter.ini
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\skypemut.lng
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\multiappnt.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\printm.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itclient9x.ini
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\printjob.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\imm.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itff.sys
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itfflock.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itffx64.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itffx64.sys
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itffx64ctr.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\lsass.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\lscdftx64.sys
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\lscdft.sys
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itrcs.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itsetup.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itsetup.ini
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itwp.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\libeay32.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itpat.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itprofile9x.ini
- %WINDIR%\syswow64\stickyapp32.ini
- %WINDIR%\temp\udd4e1.tmp
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itfflock.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itffx64.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itffx64.sys
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itpat.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itrcs.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itsetup.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itsetup.ini
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itwp.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\libeay32.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\lsass.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\lscdft.sys
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\lscommc.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\lsrcshk.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\msvcp80.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\printjob.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\wuag2.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\printm.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\procmang.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\remark.lng
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\savengui.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\skypemut.lng
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\smss.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\smss9x.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\smssnt.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\spl2emf.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\swmsg.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\uninsaff.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\uninsafm.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\uninsafp.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\webm.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itff.sys
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\msvcr80.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itff.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\filelog.ls
- %WINDIR%\temp\udd14bb.tmp
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\afpansi.sys
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\afpansi.vxd
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\afpuni.sys
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\afpuni.vxd
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\alfafm.sys
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\alfafm.vxd
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\appm9x.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\appmnt.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\aw_sas32.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\aw_sas64.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\drvcrypt.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\ecyptm.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\emf2jpg.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\filetrnsf.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itclient.ini
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\fwtool.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\imm.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\immex.dll
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\immex.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\imset.ini
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\instafm.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\instafp.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\install.bat
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\institff.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\invdev.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\invinfo.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\invnt.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\invnt9x.ls
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\iscypt.exe
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itclient.lng
- %TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\wusscan.dll
- 'localhost':33510
- '<LOCALNET>.99.40':33500
- '<LOCALNET>.99.40':80
- ClassName: '' WindowName: 'ITClient-SecChk'
- ClassName: '' WindowName: 'ITClient-AppM'
- ClassName: '' WindowName: 'ITClient-WebM'
- ClassName: '' WindowName: 'ITClient-FileTrnsf'
- ClassName: '' WindowName: 'ITClient-FileLog'
- ClassName: '' WindowName: 'ITClient'
- ClassName: '' WindowName: 'ITClient-SmssCheck'
- ClassName: '' WindowName: 'InvInfo'
- ClassName: '' WindowName: 'ITClient-PrintM'
- ClassName: '' WindowName: 'ITClient-RunAsUser9'
- ClassName: '' WindowName: 'ITClient-PrintJob'
- ClassName: '' WindowName: 'ITClient-ImM'
- ClassName: '' WindowName: 'ITClient-ImMEx'
- ClassName: '' WindowName: 'ITClient-ITRCS'
- ClassName: '' WindowName: 'ITClient-SavEnergy'
- ClassName: '' WindowName: 'ITClient-EcypM'
- ClassName: '' WindowName: 'ITClient-AgtM'
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: '' WindowName: 'DccMan'
- ClassName: '' WindowName: 'ITClient-MainSvc'
- ClassName: '' WindowName: 'ITClient-SvcCheck'
- ClassName: '' WindowName: 'ITClient-MainApp'
- ClassName: '' WindowName: 'ITClient-Main'
- ClassName: '' WindowName: 'ITClient-RunAsUser19'
- ClassName: '' WindowName: 'ITClient-RunAsUser0'
- ClassName: '' WindowName: 'ITClient-RunAsUser1'
- ClassName: '' WindowName: 'ITClient-RunAsUser2'
- ClassName: '' WindowName: 'ITClient-RunAsUser3'
- ClassName: '' WindowName: 'ITClient-RunAsUser4'
- ClassName: '' WindowName: 'ITClient-RunAsUser5'
- ClassName: '' WindowName: 'ITClient-RunAsUser6'
- ClassName: '' WindowName: 'ITClient-RunAsUser7'
- ClassName: '' WindowName: 'ITClient-InvNT'
- ClassName: '' WindowName: 'ITClient-FileTransfer'
- ClassName: '' WindowName: 'ITClient-RunAsUser8'
- ClassName: '' WindowName: 'ITClient-RunAsUser11'
- ClassName: '' WindowName: 'ITClient-RunAsUser12'
- ClassName: '' WindowName: 'ITClient-RunAsUser13'
- ClassName: '' WindowName: 'ITClient-RunAsUser14'
- ClassName: '' WindowName: 'ITClient-RunAsUser15'
- ClassName: '' WindowName: 'ITClient-RunAsUser16'
- ClassName: '' WindowName: 'ITClient-RunAsUser17'
- ClassName: '' WindowName: 'ITClient-RunAsUser18'
- ClassName: '' WindowName: 'ITClient-CurrentUser'
- ClassName: '' WindowName: 'ITClient-RunAsUser10'
- ClassName: '' WindowName: 'ITClient-WebMHK'
- '%TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itsetup.exe' -resetitguid -resetprofile -deletedeployfile
- '%TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\fwtool.exe' ADD -n "SmartIT File Transfer" -e "C:\SmartIT\filetrnsf.ls" -p 33511 -a *
- 'C:\smartit\itagent.exe'
- '%TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\fwtool.exe' ADD -n "SmartIT RCS" -e "C:\SmartIT\itrcs.exe" -p 33520 -a *
- '%TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\fwtool.exe' ADD -n "SmartIT Client" -e "C:\SmartIT\ITAgent.exe" -p 33510 -a *
- 'C:\smartit\itffx64ctr.ls' CDRWCltControl "-2147475436"
- '%TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\fwtool.exe' DELETE -n "SmartIT RCS"
- '%TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\fwtool.exe' DELETE -n "SmartIT Client"
- 'C:\smartit\invdev.ls' keepout
- '%TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\uninsafp.exe' keepout
- '%TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\fwtool.exe' DELETE -n "SmartIT File Transfer"
- '%WINDIR%\syswow64\itffx64ctr.ls' LsSetExulcdeFilesystems "\Device\LanmanRedirector|\Device\Mup|\Ntfs|\Fat|\Cdfs|\UdfsCdRom|\FileSystem\UdfsDiskRecognizer" "N"
- '%WINDIR%\syswow64\institff.exe' keepout
- '%TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\uninsaff.exe' keepout
- '%TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\uninsafm.exe' keepout
- 'C:\smartit\itffx64ctr.ls' LsDeleteRuleEntryEx "InvNT" "NULL"
- 'C:\smartit\itcurusr.exe'
- 'C:\smartit\invnt.ls' keepout
- 'C:\smartit\itagentsvc.exe' -DualMode
- '%WINDIR%\syswow64\itffx64ctr.ls' InstallDriverService "system32\Drivers\itff.sys" "ITFF" "ITFF" "3"
- '%TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\fwtool.exe' DELETE -n "SmartIT File Transfer"' (with hidden window)
- 'C:\smartit\itcurusr.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cacls.exe' C:\SmartIT\Queue /T /E /P Everyone:F' (with hidden window)
- 'C:\smartit\itffx64ctr.ls' LsDeleteRuleEntryEx "InvNT" "NULL"' (with hidden window)
- '%TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\fwtool.exe' ADD -n "SmartIT File Transfer" -e "C:\SmartIT\filetrnsf.ls" -p 33511 -a *' (with hidden window)
- '%WINDIR%\syswow64\cacls.exe' C:\SmartIT\Temp /T /E /P Everyone:F' (with hidden window)
- '%WINDIR%\syswow64\cacls.exe' C:\SmartIT\Log\c20230930.log /T /E /P Everyone:F' (with hidden window)
- '%TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\fwtool.exe' ADD -n "SmartIT RCS" -e "C:\SmartIT\itrcs.exe" -p 33520 -a *' (with hidden window)
- 'C:\smartit\invnt.ls' keepout' (with hidden window)
- 'C:\smartit\invdev.ls' keepout' (with hidden window)
- '%WINDIR%\syswow64\itffx64ctr.ls' LsSetExulcdeFilesystems "\Device\LanmanRedirector|\Device\Mup|\Ntfs|\Fat|\Cdfs|\UdfsCdRom|\FileSystem\UdfsDiskRecognizer" "N"' (with hidden window)
- '%WINDIR%\syswow64\fltmc.exe' unload AFPAnsi' (with hidden window)
- '%TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\fwtool.exe' DELETE -n "SmartIT Client"' (with hidden window)
- '%WINDIR%\syswow64\net.exe' stop ITClientSvs' (with hidden window)
- '%WINDIR%\syswow64\fltmc.exe' unload AlfaFM' (with hidden window)
- '%TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\itsetup.exe' -resetitguid -resetprofile -deletedeployfile' (with hidden window)
- '%WINDIR%\syswow64\net.exe' stop AlfaFF' (with hidden window)
- '%WINDIR%\syswow64\institff.exe' keepout' (with hidden window)
- '%WINDIR%\syswow64\itffx64ctr.ls' InstallDriverService "system32\Drivers\itff.sys" "ITFF" "ITFF" "3"' (with hidden window)
- '%TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\fwtool.exe' ADD -n "SmartIT Client" -e "C:\SmartIT\ITAgent.exe" -p 33510 -a *' (with hidden window)
- '%TEMP%\39a0bbab-8472-4dce-a92d-ca8bbc23698a\fwtool.exe' DELETE -n "SmartIT RCS"' (with hidden window)
- 'C:\smartit\itffx64ctr.ls' CDRWCltControl "-2147475436"' (with hidden window)
- '%WINDIR%\syswow64\net1.exe' stop ITClientSvs
- '%WINDIR%\syswow64\fltmc.exe' unload AlfaFM
- '%WINDIR%\syswow64\fltmc.exe' unload AFPAnsi
- '%WINDIR%\syswow64\net1.exe' stop AlfaFF
- '%WINDIR%\syswow64\cacls.exe' C:\SmartIT\Queue /T /E /P Everyone:F
- '%WINDIR%\syswow64\cacls.exe' C:\SmartIT\Temp /T /E /P Everyone:F
- '%WINDIR%\syswow64\cacls.exe' C:\SmartIT\Log\c20230930.log /T /E /P Everyone:F