Technical Information
- [<HKLM>\System\CurrentControlSet\Services\LiveLet_2156] 'ImagePath' = '%TEMP%\livecare\LiveLet.exe -unified -runassys -pid 2156'
- 'LiveLet_2156' %TEMP%\livecare\LiveLet.exe -unified -runassys -pid 2156
- %TEMP%\nsw6f37.tmp
- %ALLUSERSPROFILE%\livecare\service\release
- %ALLUSERSPROFILE%\livecare\service\livecareservicelivelet.exe
- %ALLUSERSPROFILE%\livecare\service\livecareelevator.exe
- %TEMP%\nsw7d3b.tmp
- %TEMP%\livecare\lcareview\release
- %TEMP%\livecare\lcareview\ishview.exe
- %TEMP%\nsg7a1f.tmp
- %ALLUSERSPROFILE%\livecare\lcaresrv\release
- %ALLUSERSPROFILE%\livecare\lcaresrv\ishooks64.dll
- %ALLUSERSPROFILE%\livecare\lcaresrv\ishooks64.exe
- %TEMP%\nsb7743.tmp\system.dll
- %ALLUSERSPROFILE%\livecare\lcaresrv\sas.exe
- %ALLUSERSPROFILE%\livecare\lcaresrv\ctlpanel.exe
- %ALLUSERSPROFILE%\livecare\lcaresrv\ishsrvp2p.exe
- %ALLUSERSPROFILE%\livecare\lcaresrv\ishsrv.exe
- %ALLUSERSPROFILE%\livecare\lcaresrv\ishooks.dll
- %TEMP%\nsm74c3.tmp
- %TEMP%\livecare\release
- %TEMP%\livecare\livecare_service.exe
- %TEMP%\livecare\livecare_demo.exe
- %TEMP%\livecare\livecare_assistance.exe
- %TEMP%\livecare\lvcutility.exe
- %TEMP%\livecare\icon.ico
- %TEMP%\livecare\logo.bmp
- %TEMP%\livecare\livelet.ini
- %TEMP%\livecare\livelet.exe
- %TEMP%\nsm6f48.tmp\system.dll
- %TEMP%\livelet.log
- %APPDATA%\livecare\livelet.ini
- %TEMP%\nsb7743.tmp\system.dll
- %TEMP%\nsm6f48.tmp\system.dll
- %TEMP%\livecare\livelet.ini
- from %TEMP%\livecare\icon.ico to %TEMP%\livecare\icon.ico.custom
- from %TEMP%\livecare\logo.bmp to %TEMP%\livecare\logo.bmp.custom
- http://lo###.livecare.net/llogin/index.php/livelet/setup-livelet-ident/
- DNS ASK lo###.livecare.net
- '%TEMP%\livecare\livecare_assistance.exe' -u
- '%TEMP%\livecare\livecare_demo.exe'
- '%TEMP%\livecare\livecare_service.exe' -u
- '%TEMP%\livecare\livelet.exe' -unified
- '%TEMP%\livecare\livelet.exe' -unified -runassys -pid 2156
- '%TEMP%\livecare\livelet.exe' -unified -pid 2156