Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'EnableFirewall' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'DoNotAllowExceptions' = '00000000'
- %TEMP%\toolbar.exe banner.html
- <SYSTEM32>\netsh.exe firewall set opmode mode=disable
- <SYSTEM32>\netsh.exe firewall set opmode mode=disable profile=ALL
- <SYSTEM32>\cmd.exe /c %TEMP%\disable.bat
- %TEMP%\disable.bat
- %TEMP%\aut3.tmp
- <Текущая директория>\banner.html
- %TEMP%\aut1.tmp
- %TEMP%\toolbar.exe
- %TEMP%\aut2.tmp
- %TEMP%\aut3.tmp
- <Текущая директория>\banner.html
- %TEMP%\aut1.tmp
- %TEMP%\aut2.tmp
- 'ft####b.funpic.de':21
- DNS ASK ft####b.funpic.de
- ClassName: 'Shell_TrayWnd' WindowName: ''