Техническая информация
- <SYSTEM32>\net1.exe stop Alerter
- <SYSTEM32>\net.exe stop wscsvc
- <SYSTEM32>\net.exe stop Alerter
- <SYSTEM32>\net1.exe stop SharedAccess
- <SYSTEM32>\net1.exe stop wscsvc
- <SYSTEM32>\net.exe stop SharedAccess
- <SYSTEM32>\sc.exe config SharedAccess start=disabled
- <SYSTEM32>\sc.exe config Alerter start=disabled
- <SYSTEM32>\sc.exe stop Alerter
- <SYSTEM32>\netsh.exe firewall add allowedprogram "<Полный путь к вирусу>" Bradesco Seguro
- <SYSTEM32>\sc.exe stop SharedAccess
- <SYSTEM32>\sc.exe config wscsvc start=disabled
- <SYSTEM32>\sc.exe stop wscsvc
- 'av###ria.org':80
- av###ria.org/add.php
- DNS ASK av###ria.org
- ClassName: 'Shell_TrayWnd' WindowName: ''