Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'system' = '<SYSTEM32>\drives\hosts\taskmgr.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- <SYSTEM32>\reg.exe add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /V system /t REG_SZ /d "<SYSTEM32>\drives\hosts\taskmgr.exe" /f
- <SYSTEM32>\attrib.exe -h -s win
- <SYSTEM32>\netsh.exe firewall set opmode mode = DISABLE
- <SYSTEM32>\net.exe stop "Centro de Seguridad"
- <SYSTEM32>\net1.exe stop "Centro de Seguridad"
- %TEMP%\~1.bat
- %TEMP%\~1.bat
- %TEMP%\~1.bat