Техническая информация
- [HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions\{1D901067-2529-4A9B-9B6B-7A1DB3A44CB5}] 'ClsidExtension' = '{D1BB7CF4-4463-4e91-88D7-ECC3CE0A13B7}'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Update' = '%CommonProgramFiles(x86)%\UPDAT\Update.exe'
- [HKLM\System\CurrentControlSet\Services\BUZOR] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\BUZOR] 'ImagePath' = '<SYSTEM32>\RUNDLL32.EXE <SYSTEM32>\WBEM\IRJIT.DLL,Export 1087'
- [HKLM\System\CurrentControlSet\Services\Indtry] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Indtry] 'ImagePath' = '<SYSTEM32>\svchost.exe -k netsvcs'
- [HKLM\SYSTEM\CurrentControlSet\Services\Indtry\Parameters] 'ServiceDll' = '<SYSTEM32>\spted.dll'
- 'BUZOR' <SYSTEM32>\RUNDLL32.EXE <SYSTEM32>\WBEM\IRJIT.DLL,Export 1087
- 'Indtry' <SYSTEM32>\svchost.exe -k netsvcs
- %WINDIR%\syswow64\nt.sys
- %WINDIR%\syswow64\spted.dll
- %ProgramFiles(x86)%\coolwebsite\quicklink.dll
- %WINDIR%\syswow64\wbem\ocmor.dat
- %WINDIR%\syswow64\wbem\irjit.dll
- %CommonProgramFiles(x86)%\updat\update.exe
- %CommonProgramFiles(x86)%\updat\update.dat
- %ProgramFiles(x86)%\coolwebsite\uninst.exe
- '%WINDIR%\syswow64\rundll32.exe' "<SYSTEM32>\spted.dll",ExportFunc 1001
- '%WINDIR%\syswow64\rundll32.exe' "<SYSTEM32>\wbem\IRJIT.dll",Export @install