Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\AcrobatUpdateService] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\AcrobatUpdateService] 'ImagePath' = '%ALLUSERSPROFILE%\AdobeUpdater.exe'
- 'AcrobatUpdateService' %ALLUSERSPROFILE%\AdobeUpdater.exe
- Журнал событий Windows (Windows Event Logging)
- <SYSTEM32>\conhost.exe
- %WINDIR%\explorer.exe
- %ALLUSERSPROFILE%\adobeupdater.exe
- %WINDIR%\temp\ydfbriffrgyc.sys
- DNS ASK po##.#ashvault.pro
- '%ALLUSERSPROFILE%\adobeupdater.exe'
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-dc 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-dc 0
- '<SYSTEM32>\sc.exe' delete "AcrobatUpdateService"
- '<SYSTEM32>\sc.exe' create "AcrobatUpdateService" binpath= "%ALLUSERSPROFILE%\AdobeUpdater.exe" start= "auto"
- '<SYSTEM32>\sc.exe' stop eventlog
- '<SYSTEM32>\sc.exe' start "AcrobatUpdateService"
- '%WINDIR%\explorer.exe'