Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'HKCU' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'HKLM' = ''
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Ad0vetemp92' = '%TEMP%\Ad0vetmp08469.exe'
- '%APPDATA%\InstallDir\Dr1verUpdate00.exe'
- '<SYSTEM32>\lsass.exe'
- '<SYSTEM32>\svchost.exe'
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "Ad0vetemp92" /t REG_SZ /d "%TEMP%\Ad0vetmp08469.exe
- <SYSTEM32>\lsass.exe
- %APPDATA%\Microsoft\Windows\BCLPzets\BCLPzets.dat
- %APPDATA%\Microsoft\Windows\BCLPzets\BCLPzets.svr
- %APPDATA%\InstallDir\Dr1verUpdate00.exe
- %TEMP%\Ad0vetmp08469.exe
- %APPDATA%\Microsoft\Windows\BCLPzets\BCLPzets.nfo
- %APPDATA%\Microsoft\Windows\BCLPzets\BCLPzets.svr
- %APPDATA%\Microsoft\Windows\BCLPzets\BCLPzets.dat
- %APPDATA%\Microsoft\Windows\BCLPzets\BCLPzets.nfo
- %APPDATA%\Microsoft\Windows\BCLPzets\BCLPzets.svr
- %APPDATA%\Microsoft\Windows\BCLPzets\BCLPzets.nfo
- %TEMP%\Ad0vetmp08469.exe
- 'ja######.serveexchange.com':999
- 'is######et.cable-modem.org':999
- DNS ASK ja######.serveexchange.com
- DNS ASK is######et.cable-modem.org
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''