Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'USBestCR' = '%PROGRAM_FILES%\USBESTDI\iconcs231765.exe RunFromReg'
- [<HKLM>\SYSTEM\ControlSet001\Services\AfaService] 'Start' = '00000002'
- '%PROGRAM_FILES%\USBESTDI\iconcs231765.exe'
- '<SYSTEM32>\afasrv32.exe'
- %PROGRAM_FILES%\USBESTDI\iconcs231765.exe
- <SYSTEM32>\afasrv32.exe
- ClassName: 'USBestICON' WindowName: '(null)'