Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\srvProtectExtension] 'Start' = '00000002'
- '%APPDATA%\BaseFlash\protect\ProtectExtension.exe'
- %APPDATA%\BaseFlash\protect\utilsDll.dll
- %APPDATA%\BaseFlash\protect\Interop.Shell32.dll
- %APPDATA%\BaseFlash\uninstallkit.exe
- %APPDATA%\BaseFlash\protect\config.xml
- %TEMP%\nsl2.tmp\utils.dll
- %TEMP%\nsl2.tmp\registry.dll
- %APPDATA%\BaseFlash\protect\ProtectExtension.exe
- %TEMP%\nsl2.tmp\SimpleSC.dll
- %TEMP%\nsl2.tmp\utils.dll
- %TEMP%\nsl2.tmp\SimpleSC.dll
- %TEMP%\nsl2.tmp\registry.dll
- 'st#.##seflash.com':443
- DNS ASK st#.##seflash.com