Техническая информация
- '%WINDIR%\syswow64\net.exe' stop PcaSvc
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyEnable' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyOverride' = '127.0.0.1;*.samsung.net;107.115.*.*;<local>'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'ProxyServer' = '107.115.7.10:8080'
- %TEMP%\start.bat
- %TEMP%\sdbn.crt
- %TEMP%\pac_enable.reg
- %TEMP%\certmgr.exe
- '%TEMP%\certmgr.exe' -add sdbn.crt -c -s -r localMachine root
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\start.bat" "' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\start.bat" "
- '%WINDIR%\syswow64\net1.exe' stop PcaSvc
- '%WINDIR%\syswow64\reg.exe' import pac_enable.reg
- '%WINDIR%\syswow64\net.exe' start PcaSvc
- '%WINDIR%\syswow64\net1.exe' start PcaSvc