Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\services\RemoteServiceFirewall\Parameters] 'ServiceDll' = '<SYSTEM32>\RemoteServiceFirewall.dll'
- [HKLM\SYSTEM\CurrentControlSet\Services\RemoteServiceFirewall] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\RemoteServiceFirewall] 'ImagePath' = '<SYSTEM32>\svchost.exe -k RemoteServiceFirewall'
- 'RemoteServiceFirewall' <SYSTEM32>\svchost.exe -k RemoteServiceFirewall
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "<SYSTEM32>"
- <SYSTEM32>\remoteservicefirewall.dll
- %WINDIR%\uzfrzp.bin
- DNS ASK gr###fy.link
- '<SYSTEM32>\svchost.exe' -k RemoteServiceFirewall -s RemoteServiceFirewall
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "<SYSTEM32>" (со скрытым окном)