Техническая информация
- [HKLM\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'EnableFirewall' = '00000000'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- Системный антивирус (Защитник Windows)
- '<SYSTEM32>\netsh.exe' Advfirewall set allprofiles state off
- %TEMP%\fraqbc8wsa1xvpf.exe
- 'localhost':59911
- 'localhost':61310
- '%TEMP%\fraqbc8wsa1xvpf.exe'
- '%TEMP%\fraqbc8wsa1xvpf.exe' ' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c NetSh Advfirewall set allprofiles state off
- '<SYSTEM32>\cmd.exe' /c cls