Техническая информация
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\Services\wscsvc" /v Start /t REG_DWORD /d 0x4 /f
- '<SYSTEM32>\net1.exe' stop SharedAccess
- '<SYSTEM32>\net1.exe' stop "Security Center"
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\Services\wuauserv" /v Start /t REG_DWORD /d 0x4 /f
- '<SYSTEM32>\reg.exe' add "HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess" /v Start /t REG_DWORD /d 0x4 /f
- '<SYSTEM32>\net.exe' stop "Security Center"
- '<SYSTEM32>\net.exe' stop SharedAccess
- [<HKCU>\Software\Microsoft\MSNMessenger]
- [<HKCU>\Software\Microsoft\MessengerService]
- %WINDIR%\CRNJEUFU.txt
- 'ft#.##eewebtown.com':21
- 'localhost':1036
- DNS ASK ft#.##eewebtown.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'