Technical Information
- [HKLM\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'EnableFirewall' = '00000000'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- Windows Firewall
- <SYSTEM32>\winlogon.exe
- <Current directory>\xea10.tmp.dll
- <Current directory>\xea30.tmp.exe
- <Current directory>\xea30.tmp.exe
- <Current directory>\xea10.tmp.dll
- '<LOCALNET>..33.4':19898
- 'localhost':51974
- ClassName: 'Button' WindowName: 'Start'
- ClassName: '' WindowName: ''
- '<Current directory>\xea30.tmp.exe' -G98040699 -p448 -r -l<Current directory>\xEA10.tmp.dll
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "<Full path to file>"