Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- '%WINDIR%\syswow64\netsh.exe' advfirewall set publicprofile state off
- '%WINDIR%\syswow64\netsh.exe' advfirewall set privateprofile state off
- <SYSTEM32>\runtimebroker.exe
- %TEMP%\autd05b.tmp
- C:\dsound.dll
- %TEMP%\autd4f0.tmp
- C:\androidemulatorex.exe
- %TEMP%\autdaec.tmp
- C:\config.ini
- %TEMP%\autdafd.tmp
- %TEMP%\autdb0e.tmp
- %TEMP%\autd05b.tmp
- %TEMP%\autd4f0.tmp
- %TEMP%\autdaec.tmp
- %TEMP%\autdafd.tmp
- %TEMP%\autdb0e.tmp
- '15#.#01.65.91':443
- DNS ASK fi#####.###tings.services.mozilla.com
- 'C:\androidemulatorex.exe' -vm 100
- '%WINDIR%\syswow64\cmd.exe' /c netsh advfirewall set privateprofile state off (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c netsh advfirewall set publicprofile state off (со скрытым окном)