Техническая информация
- [<HKLM>\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'EnableFirewall' = '00000000'
- [<HKLM>\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'EnableFirewall' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- <SYSTEM32>\ipconfig.exe
- <SYSTEM32>\net1.exe stop mpssvc
- <SYSTEM32>\net.exe stop mpssvc
- <Текущая директория>\redirect.php
- <Текущая директория>\local.temp.dat
- <Текущая директория>\gate.temp.dat
- <Текущая директория>\redirect.php
- 'eu######u.agilityhoster.com':80
- 'eu####eru.110mb.com':80
- '<IP-адрес в локальной сети>':80
- 'www.fo##yip.com':80
- 'www.wh###smyip.com':80
- 'www.wh###myip.org':80
- <IP-адрес в локальной сети>/InternetGatewayDevice.xml
- eu####eru.110mb.comhttp://eui9hteru.110mb.com/redirect2.php
- <IP-адрес в локальной сети>/dslf/InternetGatewayDevice.xml
- <IP-адрес в локальной сети>/upnp/InternetGatewayDevice.xml
- www.wh###smyip.comhttp://www.whatismyip.com/
- www.fo##yip.comhttp://www.formyip.com/
- eu######u.agilityhoster.comhttp://eui9hteru.agilityhoster.com/redirect2.php
- www.wh###myip.orghttp://www.whatsmyip.org/
- DNS ASK eu######u.agilityhoster.com
- DNS ASK eu####eru.110mb.com
- DNS ASK www.wh###myip.org
- DNS ASK www.fo##yip.com
- DNS ASK www.wh###smyip.com