Техническая информация
- [HKLM\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'EnableFirewall' = '00000000'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Set-MpPreference -DisableRealtimeMonitoring $true
- '<SYSTEM32>\taskkill.exe' /f /im MBAMService.exe
- '<SYSTEM32>\taskkill.exe' /f /im "Malwarebytes Service"
- '<SYSTEM32>\netsh.exe' advfirewall set allprofiles state off
- %TEMP%\4ce7.tmp\4ce8.tmp\4ce9.bat
- 'localhost':54415
- 'localhost':51122
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\4CE7.tmp\4CE8.tmp\4CE9.bat <Полный путь к файлу>" (со скрытым окном)
- '<SYSTEM32>\timeout.exe' /t 15