Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'EnableFirewall' = '00000000'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- nul
- 'tr###tysteal.me':443
- DNS ASK tr###tysteal.me
- '%WINDIR%\syswow64\cmd.exe' /c netsh advfirewall set allprofiles state off > nul
- '%WINDIR%\syswow64\netsh.exe' advfirewall set allprofiles state off
- '%WINDIR%\syswow64\cmd.exe' /c color b
- '%WINDIR%\syswow64\cmd.exe' /c cls