Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Explorer Controler' = '%HOMEPATH%\NortonWindowsLiveUSpA.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\nortonwindowsliveuspa.exe
- [HKLM\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- '%WINDIR%\syswow64\netsh.exe' firewall set opmode mode=disable
- DNS ASK pi##ght.com
- 'localhost':57008
- 'localhost':50783
- '%WINDIR%\syswow64\netsh.exe' firewall set opmode mode=disable (со скрытым окном)