Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- <SYSTEM32>\netsh.exe firewall set opmode disable
- <SYSTEM32>\cmd.exe /c """%TEMP%\1.tmp\start bat.bat"" "
- %TEMP%\1.tmp\binaries.txt
- %TEMP%\1.tmp\start bat.bat
- %TEMP%\1.tmp\b2e
- %TEMP%\1.tmp\b2e.dll
- %TEMP%\1.tmp\start bat.bat
- %TEMP%\1.tmp\b2e.dll
- %TEMP%\1.tmp\binaries.txt
- %TEMP%\1.tmp\b2e