Техническая информация
- [HKLM\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- '%WINDIR%\syswow64\netsh.exe' advfirewall set privateprofile state off
- '%WINDIR%\syswow64\netsh.exe' advfirewall set publicprofile state off
- %TEMP%\aut8d41.tmp
- C:\config.ini
- %TEMP%\aut8daf.tmp
- %TEMP%\aut8e5c.tmp
- %TEMP%\aut8f27.tmp
- C:\bypass-config.ini
- %TEMP%\aut9003.tmp
- %WINDIR%\cnc380.exe
- %TEMP%\aut9ef2.tmp
- %WINDIR%\adb.exe
- %TEMP%\auta105.tmp
- %WINDIR%\adbwinapi.dll
- %TEMP%\auta193.tmp
- C:\adb.exe
- %TEMP%\auta2cc.tmp
- C:\adbwinapi.dll
- %TEMP%\auta2fb.tmp
- C:\androidemulatorex.exe
- %TEMP%\aut8d41.tmp
- %TEMP%\aut8daf.tmp
- %TEMP%\aut8e5c.tmp
- %TEMP%\aut8f27.tmp
- %TEMP%\aut9003.tmp
- %TEMP%\aut9ef2.tmp
- %TEMP%\auta105.tmp
- %TEMP%\auta193.tmp
- %TEMP%\auta2cc.tmp
- %TEMP%\auta2fb.tmp
- '34.##9.100.209':443
- 'localhost':49402
- 'localhost':51304
- '%WINDIR%\syswow64\cmd.exe' /c netsh advfirewall set publicprofile state off (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c netsh advfirewall set privateprofile state off (со скрытым окном)