Техническая информация
- %HOMEPATH%\start menu\programs\startup\bcastdvrbroker.url
- %WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe
- <LS_APPDATA>\google\chrome\user data\default\login data
- <LS_APPDATA>\chromium\user data\default\web data
- %APPDATA%\opera software\opera stable\login data
- %HOMEPATH%\bcastdvrbroker\bcastdvrbroker.vbs
- %HOMEPATH%\bcastdvrbroker\appidcertstorecheck.exe
- %TEMP%\543edaeb-1c1c-6760-ddfe-0ee326962d93
- %TEMP%\tmp1.tmp
- %TEMP%\tmp1.tmp
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /stext "%TEMP%\tmp1.tmp"' (со скрытым окном)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\regasm.exe'
- '%WINDIR%\microsoft.net\framework\v2.0.50727\vbc.exe' /stext "%TEMP%\tmp1.tmp"