Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'GmailEnhancer' = '"<SYSTEM32>\AsSysCtrlService\AsSysCtrlSrvcIns.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'GmailEnhancer' = '"<SYSTEM32>\AsSysCtrlService\AsSysCtrlSrvcIns.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'GmailEnhancer' = '<SYSTEM32>\AsSysCtrlService\AsSysCtrlSrvcIns.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\WindowsUpdate.com.url
- '<SYSTEM32>\AsSysCtrlService\AsSysCtrlSrvcIns.exe'
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce" /f /v "GmailEnhancer" /t REG_SZ /d "<SYSTEM32>\AsSysCtrlService\AsSysCtrlSrvcIns.exe"
- <SYSTEM32>\cmd.exe
- <SYSTEM32>\AsSysCtrlService\AsSysCtrlSrvcIns.exe
- <SYSTEM32>\AsSysCtrlService\AsSysCtrlSrvcIns.exe
- 'lt#.###ckenkiller.com':5874
- DNS ASK LT#.###ckenkiller.com
- ClassName: 'Indicator' WindowName: '(null)'