Technical Information
- '%WINDIR%\syswow64\netsh.exe' adv firewall set opmode mode disable
- <Current directory>\ruby.log
- <Current directory>\remotec.ps1
- DNS ASK on##n.net
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -executionpolicy bypass -command .\remotec.ps1