Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\UPAS adlog] 'ImagePath' = '%ProgramFiles%\Sofnet\UPAS adlog\adlog.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\UPAS adlog] 'Start' = '00000002'
- %ProgramFiles%\Sofnet\UPAS adlog\logo_upas.ico
- %ProgramFiles%\Sofnet\UPAS adlog\UPAS.bmp
- %WINDIR%\Temp\ADLOG-2017-12-18.txt
- %ProgramFiles%\Sofnet\UPAS adlog\WindowsAgentUI.exe
- %TEMP%\nsk2.tmp
- %ProgramFiles%\Sofnet\UPAS adlog\adlog.exe
- %ProgramFiles%\Sofnet\UPAS adlog\sqlite3.dll
- %TEMP%\nsu3.tmp\SimpleSC.dll
- %TEMP%\nsu3.tmp\registry.dll
- '<LOCALNET>.1.70':49000
- '%ProgramFiles%\Sofnet\UPAS adlog\adlog.exe'