Technical Information
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'SmartIT Client' = '%WINDIR%\SmartIT\ITCurusr.exe'
- [HKLM\SYSTEM\CurrentControlSet\Services\LsProft] 'ImagePath' = 'system32\DRIVERS\LsProft.sys'
- [HKLM\SYSTEM\CurrentControlSet\Services\LsProft] 'Start' = '00000000'
- [HKLM\SYSTEM\CurrentControlSet\Services\ITFF] 'ImagePath' = 'system32\Drivers\itff.sys'
- [HKLM\System\CurrentControlSet\Services\ITPF] 'ImagePath' = 'system32\Drivers\ITPF.sys'
- [HKLM\System\CurrentControlSet\Services\ITClientSvs] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\ITClientSvs] 'ImagePath' = '%WINDIR%\SmartIT\ITAgentSvc.exe -DualMode'
- 'ITPF' system32\Drivers\ITPF.sys
- 'ITFF' system32\Drivers\itff.sys
- 'ITClientSvs' %WINDIR%\SmartIT\ITAgentSvc.exe -DualMode
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\] 'DoNotAllowExceptions' = '00000000'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\] 'DoNotAllowExceptions' = '00000000'
- '%WINDIR%\syswow64\net.exe' stop itpf
- '%WINDIR%\syswow64\net.exe' stop ITClientSvs
- '%WINDIR%\syswow64\net.exe' stop AlfaFF
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\appm9x.ls
- %WINDIR%\smartit\swmsg.ls
- %WINDIR%\smartit\itwp.ls
- %WINDIR%\smartit\itpat.exe
- %WINDIR%\smartit\wusscan.dll
- %WINDIR%\smartit\itclient.ini
- %WINDIR%\smartit\webmhkx64.ls
- %WINDIR%\smartit\webmhkx64.dll
- %WINDIR%\smartit\itclient.lng
- %WINDIR%\smartit\statusstrings.dll
- %WINDIR%\smartit\iamtagent.dll
- %WINDIR%\smartit\iamtstoraccess.dll
- %WINDIR%\smartit\savengui.exe
- %WINDIR%\smartit\itagent.exe
- %WINDIR%\smartit\remark.lng
- %WINDIR%\smartit\lscommc.dll
- %WINDIR%\smartit\fwtool.exe
- %WINDIR%\smartit\itagentsvc.exe
- %WINDIR%\syswow64\webdeny.html
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\webmhk.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\webmhkx64.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\webmhkx64.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\wuag2.exe
- %WINDIR%\smartit\webmhk.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\webm.ls
- %WINDIR%\smartit\webmhk.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\wusscan.dll
- %WINDIR%\smartit\invinfo.ls
- %WINDIR%\smartit\filetrnsf.ls
- %WINDIR%\smartit\invdev.ls
- %WINDIR%\smartit\webm.ls
- %WINDIR%\smartit\log\c20231108.log
- %WINDIR%\smartit\itcurusr.exe
- %WINDIR%\syswow64\stickyapp32.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itpat.exe
- %WINDIR%\smartit\lscommcex.dll
- %WINDIR%\smartit\imm.ls
- %WINDIR%\smartit\immex.ls
- %WINDIR%\syswow64\immex.dll
- %WINDIR%\smartit\skypemut.lng
- %WINDIR%\smartit\ecyptm.ls
- %WINDIR%\smartit\printm.dll
- %WINDIR%\smartit\iscypt.exe
- %WINDIR%\smartit\imset.ini
- %WINDIR%\smartit\itprofile.ini
- %WINDIR%\smartit\aw_sas.dll
- %WINDIR%\smartit\lsrcshk.dll
- <DRIVERS>\lscdft.sys
- %WINDIR%\temp\udde1b7.tmp
- %WINDIR%\smartit\iscyptext.dll
- %WINDIR%\smartit\printmx64.dll
- %WINDIR%\smartit\itrcs.exe
- %WINDIR%\smartit\printwmx64.ls
- %WINDIR%\smartit\emf2jpg.ls
- %WINDIR%\smartit\invnt.ls
- %WINDIR%\smartit\appm.ls
- %WINDIR%\smartit\procmang.exe
- <SYSTEM32>\itff.dll
- <DRIVERS>\itff.sys
- %WINDIR%\smartit\itffx64ctr.ls
- <SYSTEM32>\itffx64ctr.ls
- %WINDIR%\smartit\filelog.ls
- %WINDIR%\syswow64\itffx64ctr.ls
- %WINDIR%\syswow64\uninsitff.exe
- %WINDIR%\smartit\itfflock.ls
- %WINDIR%\smartit\printm.ls
- %WINDIR%\smartit\printjob.ls
- %WINDIR%\smartit\spl2emf.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\webdeny.html
- %WINDIR%\syswow64\institff.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\webmhk.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\uninsitff.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\uninsafp.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\uninsafm.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\invnt.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\invnt9x.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\iscypt.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\iscyptext.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\institff.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\instafp.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\invinfo.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\iscyptextx64.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itff.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itff.sys
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itfflock.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itffx64.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itclient.ini
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itclient.lng
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itclient9x.ini
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\install.bat
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\instafm.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itffx64.sys
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\aw_sas32.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\aw_sas64.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\ecyptm.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\emf2jpg.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\filelog.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\filelog9x.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\appmnt.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\filetrnsf.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\iamtagent.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\iamtstoraccess.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\imm.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\immex.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\immex.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\imset.ini
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe
- %WINDIR%\smartit\itguid.ini
- %WINDIR%\smartit\libeay32.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itffx64ctr.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itprofile9x.ini
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\procmang.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\remark.lng
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\savengui.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\sfxparamter.ini
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\printm.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\skypemut.lng
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\printwmx64.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\smss9x.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\spl2emf.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\statusstrings.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\stickyapp32.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\swmsg.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\smss.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\invdev.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\smssnt.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\printmx64.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\printm.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\printjob.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itrcs.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itsetup.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itsetup.ini
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itwp.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\libeay32.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itprofile.ini
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\lsass.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\lscdftx64.sys
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\lscommc.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\lscommcex.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\lscommcex9x.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\lsrcshk.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\msvcp80.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\lscdft.sys
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\msvcr80.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itpf.sys
- %WINDIR%\syswow64\stickyapp32.ini
- %WINDIR%\temp\udde1b7.tmp
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itsetup.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itsetup.ini
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itwp.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\libeay32.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\lsass.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\lscdft.sys
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\lscommc.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\lsrcshk.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\msvcp80.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\msvcr80.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\printjob.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\printm.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\printm.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\procmang.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\wuag2.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\remark.lng
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\savengui.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\skypemut.lng
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\smss.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\smss9x.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\smssnt.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\spl2emf.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\swmsg.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\uninsafm.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\uninsafp.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\webm.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\webmhk.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\webmhk.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itrcs.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\printwmx64.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itpf.sys
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\instafm.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\appm9x.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\appmnt.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\aw_sas32.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\aw_sas64.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\ecyptm.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\emf2jpg.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\filelog.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\filetrnsf.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\imm.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\immex.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\immex.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\imset.ini
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\instafp.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itffx64.sys
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\install.bat
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\institff.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\invdev.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\invinfo.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\invnt.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\invnt9x.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\iscypt.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itclient.ini
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itclient.lng
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itff.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itff.sys
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itfflock.ls
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itffx64.dll
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itpat.exe
- %TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\wusscan.dll
- 'localhost':33510
- '<LOCALNET>.3.220':33500
- '<LOCALNET>.3.220':80
- ClassName: '' WindowName: 'ITClient-SecChk'
- ClassName: '' WindowName: 'ITClient-AppM'
- ClassName: '' WindowName: 'ITClient-WebM'
- ClassName: '' WindowName: 'ITClient-WebMHK'
- ClassName: '' WindowName: 'ITClient-WebMHKx64'
- ClassName: '' WindowName: 'ITClient-FileTrnsf'
- ClassName: '' WindowName: 'ITClient-FileLog'
- ClassName: '' WindowName: 'ITClient'
- ClassName: '' WindowName: 'ITClient-SmssCheck'
- ClassName: '' WindowName: 'ITClient-RunAsUser9'
- ClassName: '' WindowName: 'InvInfo'
- ClassName: '' WindowName: 'ITClient-PrintJob'
- ClassName: '' WindowName: 'ITClient-FileTransfer'
- ClassName: '' WindowName: 'ITClient-ImM'
- ClassName: '' WindowName: 'ITClient-ImMEx'
- ClassName: '' WindowName: 'ITClient-ITRCS'
- ClassName: '' WindowName: 'ITClient-SavEnergy'
- ClassName: '' WindowName: 'ITClient-EcypM'
- ClassName: '' WindowName: 'ITClient-AgtM'
- ClassName: '' WindowName: 'ITClient-MainSvc'
- ClassName: '' WindowName: 'ITClient-SvcCheck'
- ClassName: '' WindowName: 'ITClient-MainApp'
- ClassName: '' WindowName: 'ITClient-Main'
- ClassName: '' WindowName: 'ITClient-RunAsUser19'
- ClassName: '' WindowName: 'ITClient-RunAsUser0'
- ClassName: '' WindowName: 'ITClient-RunAsUser1'
- ClassName: '' WindowName: 'ITClient-RunAsUser2'
- ClassName: '' WindowName: 'ITClient-RunAsUser3'
- ClassName: '' WindowName: 'ITClient-RunAsUser4'
- ClassName: '' WindowName: 'ITClient-RunAsUser5'
- ClassName: '' WindowName: 'ITClient-RunAsUser6'
- ClassName: '' WindowName: 'ITClient-RunAsUser7'
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: '' WindowName: 'ITClient-PrintM'
- ClassName: '' WindowName: 'ITClient-RunAsUser8'
- ClassName: '' WindowName: 'ITClient-RunAsUser11'
- ClassName: '' WindowName: 'ITClient-RunAsUser12'
- ClassName: '' WindowName: 'ITClient-RunAsUser13'
- ClassName: '' WindowName: 'ITClient-RunAsUser14'
- ClassName: '' WindowName: 'ITClient-RunAsUser15'
- ClassName: '' WindowName: 'ITClient-RunAsUser16'
- ClassName: '' WindowName: 'ITClient-RunAsUser17'
- ClassName: '' WindowName: 'ITClient-RunAsUser18'
- ClassName: '' WindowName: 'ITClient-CurrentUser'
- ClassName: '' WindowName: 'ITClient-RunAsUser10'
- ClassName: '' WindowName: 'ITClient-InvNT'
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itsetup.exe' -resetitguid -destination %WINDIR%\SmartIT -deletedeployfile
- '%WINDIR%\smartit\itffx64ctr.ls' CDRWCltControl "-2147475436"
- '%WINDIR%\smartit\itffx64ctr.ls' LsDeleteRuleEntryEx "InvNT" "NULL"
- '%WINDIR%\smartit\invnt.ls' keepout
- '%WINDIR%\smartit\invdev.ls' keepout
- '%WINDIR%\smartit\itcurusr.exe' -CallFromITSetup
- '%WINDIR%\smartit\itagentsvc.exe' -DualMode
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' ADD -n "SmartIT File Transfer DataPort" -e "%WINDIR%\SmartIT\filetrnsf.ls" -p 20 -a *
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' ADD -n "SmartIT File Transfer" -e "%WINDIR%\SmartIT\filetrnsf.ls" -p 33511 -a *
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' ADD -n "SmartIT RCS" -e "%WINDIR%\SmartIT\itrcs.exe" -p 33520 -a *
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' ADD -n "SmartIT Client" -e "%WINDIR%\SmartIT\ITAgent.exe" -p 33510 -a *
- '%WINDIR%\smartit\itagent.exe'
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' DELETE -n "SmartIT File Transfer"
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' DELETE -n "SmartIT RO"
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' DELETE -n "SmartIT RCS"
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' DELETE -n "SmartIT Client"
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' DELETE -n "SmartIT File Transfer DataPort"
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\uninsafp.exe' keepout
- '%WINDIR%\syswow64\institff.exe' keepout
- '%WINDIR%\syswow64\itffx64ctr.ls' InstallDriverService "system32\Drivers\ITPF.sys" "ITPF" "ITPF" "3"
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\uninsafm.exe' keepout
- '%WINDIR%\syswow64\itffx64ctr.ls' InstallDriverService "system32\Drivers\itff.sys" "ITFF" "ITFF" "3"
- '%WINDIR%\syswow64\itffx64ctr.ls' LsSetExulcdeFilesystems "\Device\LanmanRedirector|\Ntfs|\Fat|\exFat|\Cdfs|\UdfsCdRom|\FileSystem\UdfsDiskRecognizer" "N"
- '%WINDIR%\smartit\itcurusr.exe' -CallFromITSetup' (with hidden window)
- '%WINDIR%\syswow64\cacls.exe' "%WINDIR%\SmartIT\Queue" /T /E /P Everyone:F' (with hidden window)
- '%WINDIR%\syswow64\cacls.exe' "%WINDIR%\SmartIT\Temp" /T /E /P Everyone:F' (with hidden window)
- '%WINDIR%\syswow64\cacls.exe' "%WINDIR%\SmartIT\Log\c20231108.log" /T /E /P Everyone:F' (with hidden window)
- '%WINDIR%\syswow64\net.exe' stop ITClientSvs' (with hidden window)
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' DELETE -n "SmartIT RO"' (with hidden window)
- '%WINDIR%\syswow64\net.exe' stop itpf' (with hidden window)
- '%WINDIR%\smartit\invnt.ls' keepout' (with hidden window)
- '%WINDIR%\syswow64\net.exe' stop AlfaFF' (with hidden window)
- '%WINDIR%\smartit\itffx64ctr.ls' LsDeleteRuleEntryEx "InvNT" "NULL"' (with hidden window)
- '%WINDIR%\syswow64\fltmc.exe' unload AlfaFM' (with hidden window)
- '%WINDIR%\smartit\invdev.ls' keepout' (with hidden window)
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\itsetup.exe' -resetitguid -destination %WINDIR%\SmartIT -deletedeployfile' (with hidden window)
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' DELETE -n "SmartIT Client"' (with hidden window)
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' ADD -n "SmartIT Client" -e "%WINDIR%\SmartIT\ITAgent.exe" -p 33510 -a *' (with hidden window)
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' ADD -n "SmartIT File Transfer DataPort" -e "%WINDIR%\SmartIT\filetrnsf.ls" -p 20 -a *' (with hidden window)
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' DELETE -n "SmartIT File Transfer"' (with hidden window)
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' DELETE -n "SmartIT RCS"' (with hidden window)
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' DELETE -n "SmartIT File Transfer DataPort"' (with hidden window)
- '%WINDIR%\syswow64\institff.exe' keepout' (with hidden window)
- '%WINDIR%\syswow64\itffx64ctr.ls' InstallDriverService "system32\Drivers\ITPF.sys" "ITPF" "ITPF" "3"' (with hidden window)
- '%WINDIR%\syswow64\itffx64ctr.ls' InstallDriverService "system32\Drivers\itff.sys" "ITFF" "ITFF" "3"' (with hidden window)
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' ADD -n "SmartIT RCS" -e "%WINDIR%\SmartIT\itrcs.exe" -p 33520 -a *' (with hidden window)
- '%WINDIR%\syswow64\fltmc.exe' unload AFPAnsi' (with hidden window)
- '%TEMP%\b2f3b20f-463f-4514-941e-edf2eea5820d\fwtool.exe' ADD -n "SmartIT File Transfer" -e "%WINDIR%\SmartIT\filetrnsf.ls" -p 33511 -a *' (with hidden window)
- '%WINDIR%\syswow64\itffx64ctr.ls' LsSetExulcdeFilesystems "\Device\LanmanRedirector|\Ntfs|\Fat|\exFat|\Cdfs|\UdfsCdRom|\FileSystem\UdfsDiskRecognizer" "N"' (with hidden window)
- '%WINDIR%\syswow64\net.exe' start itpf' (with hidden window)
- '%WINDIR%\smartit\itffx64ctr.ls' CDRWCltControl "-2147475436"' (with hidden window)
- '%WINDIR%\syswow64\net1.exe' stop itpf
- '%WINDIR%\syswow64\net1.exe' stop ITClientSvs
- '%WINDIR%\syswow64\fltmc.exe' unload AlfaFM
- '%WINDIR%\syswow64\fltmc.exe' unload AFPAnsi
- '%WINDIR%\syswow64\net1.exe' stop AlfaFF
- '%WINDIR%\syswow64\net.exe' start itpf
- '%WINDIR%\syswow64\net1.exe' start itpf
- '%WINDIR%\syswow64\cacls.exe' "%WINDIR%\SmartIT\Queue" /T /E /P Everyone:F
- '%WINDIR%\syswow64\cacls.exe' "%WINDIR%\SmartIT\Temp" /T /E /P Everyone:F
- '%WINDIR%\syswow64\cacls.exe' "%WINDIR%\SmartIT\Log\c20231108.log" /T /E /P Everyone:F