Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DisableNotifications' = '00000001'
- '<SYSTEM32>\netsh.exe' firewall set portopening protocol = TCP port = 123 name = pluss mode = enable scope = all profile = all
- '<SYSTEM32>\netsh.exe' firewall set allowedprogram program = c:\nc.exe name = Port libert mode = enable scope = all profile = all
- '<SYSTEM32>\netsh.exe' firewall set opmode mode = disable
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\linux.bat" "
- '<SYSTEM32>\netsh.exe' firewall set notifications mode = disable
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\fireworks.fretzi[1]
- %TEMP%\linux.bat
- 'www.fi#####ks.fretzi.com':80
- 'localhost':1040
- www.fi#####ks.fretzi.com/
- DNS ASK www.fi#####ks.fretzi.com
- ClassName: 'IEFrame' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '' WindowName: '(null)'