Техническая информация
- Системный антивирус (Защитник Windows)
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{5ACC6BBA-648E-4D8E-AAD7-E3D42ECB094C}Machine\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Extensions] 'exe' = ''
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Extensions] 'exe' = ''
- <SYSTEM32>\grouppolicy\gpt.ini
- <SYSTEM32>\grouppolicy\machine\registry.pol
- %ALLUSERSPROFILE%\ntuser.pol
- '10#.#20.176.203':80
- '14#.#5.47.169':80
- http://10#.#20.176.203/api/crazyfish.php
- '<SYSTEM32>\svchost.exe' -k secsvcs
- '<SYSTEM32>\raserver.exe' /offerraupdate