- April 19, 2007 2:15:04 AM
- Windows 98, Windows 95, Windows XP, Windows Me, Windows NT, Windows Server 2003, Windows 2000
When Adware.BeSys is executed, it creates the following registry entry so that it runs every time Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"BeSys" = "[PATH TO THE ADWARE PROGRAM]"
The risk then attempts to download the file bead.ini in the same directory as the adware program from the following location:
Note: The file contains the URL list of pop-up ads.
It then displays the pop-up ads.