Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] '{DF12F8AB-9A00-469C-B9D4-425C1BE3E1E6}' = ''
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] '%WINDIR%\Fonts\ysagpbof.dll' = '{DF12F8AB-9A00-469C-B9D4-425C1BE3E1E6}'
- <SYSTEM32>\regsvr32.exe /s "%WINDIR%\Fonts\ysagpbof.dll"
- Библиотека-обработчик для всех процессов: %WINDIR%\Fonts\ysagpbof.dll
- %WINDIR%\Fonts\d091015.dat
- %WINDIR%\Fonts\ysagpbof.tmp