Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'EnableFirewall' = '00000000'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- <SYSTEM32>\cmd.exe
- %TEMP%\d39.tmp\d4a.tmp\d5a.bat
- nul
- %TEMP%\d39.tmp\d4a.tmp\d5a.bat
- 'localhost':58106
- 'localhost':65393
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\D39.tmp\D4A.tmp\D5A.bat <Полный путь к файлу>"
- '<SYSTEM32>\cacls.exe' "<SYSTEM32>\config\system"
- '<SYSTEM32>\netsh.exe' advfirewall set allprofiles state off