Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'update' = '%WINDIR%\system\update.scr'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- '<SYSTEM32>\sc.exe' stop SharedAccess
- '<SYSTEM32>\sc.exe' config SharedAccess start= disabled
- '<SYSTEM32>\sc.exe' stop wuauserv
- '<SYSTEM32>\sc.exe' config wuauserv start= disabled
- '<SYSTEM32>\sc.exe' config wscsvc start= disabled
- '<SYSTEM32>\reg.exe' add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v update /t reg_sz /d %WINDIR%\system\update.scr /f
- '<SYSTEM32>\netsh.exe' firewall set opmode disable
- '<SYSTEM32>\sc.exe' stop wscsvc
- %WINDIR%\system\update
- %WINDIR%\system\update в %WINDIR%\system\update.scr
- 'dr####a11.no-ip.biz':1234
- 'any':1234
- DNS ASK dr####a11.no-ip.biz
- ClassName: 'Tapplication' WindowName: 'ULTIMOS DIAS'