Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\AmmyyAdmin] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'EnableFirewall' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'DoNotAllowExceptions' = '00000000'
- %TEMP%\wtool\lmhost.exe -install
- %TEMP%\wtool\wintool.exe
- <SYSTEM32>\netsh.exe firewall set opmode mode=disable profile=all
- <SYSTEM32>\sc.exe config SharedAccess start= disabled
- <SYSTEM32>\reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile" /v EnableFirewall /t REG_DWORD /d 0 /f
- <SYSTEM32>\reg.exe ADD "HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile" /v EnableFirewall /t REG_DWORD /d 0 /f
- %ALLUSERSPROFILE%\Application Data\AMMYY\hr
- %ALLUSERSPROFILE%\Application Data\AMMYY\hr3
- %ALLUSERSPROFILE%\Application Data\AMMYY\settings3.bin
- %TEMP%\wtool\wintool.exe
- %TEMP%\wtool\settings3.bin
- %TEMP%\wtool\disfw.cmd
- %TEMP%\wtool\lmhost.exe
- '91.##6.116.160':80