Техническая информация
- [HKLM\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'EnableFirewall' = '00000000'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- '<SYSTEM32>\netsh.exe' advfirewall set allprofiles state off
- <SYSTEM32>\cmd.exe
- %TEMP%\f9ca.tmp\f9cb.tmp\f9db.bat
- %TEMP%\12097__hosts
- %TEMP%\f9ca.tmp\f9cb.tmp\f9db.bat
- 'localhost':52884
- 'localhost':55235
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\F9CA.tmp\F9CB.tmp\F9DB.bat <Полный путь к файлу>"
- '<SYSTEM32>\attrib.exe' -h -r -s /s /d <DRIVERS>\etc\hosts.*
- '<SYSTEM32>\findstr.exe' /V "fin-game.com" "<DRIVERS>\etc\hosts"