Техническая информация
- %TEMP%\nso3.tmp\ns6.tmp regini.exe regini.ini
- %TEMP%\nso3.tmp\ns7.tmp cacls.exe "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk" /t /e /c /g everyone:f
- %TEMP%\nso3.tmp\ns4.tmp regini.exe bak.ini
- %TEMP%\nso3.tmp\ns5.tmp regedit.exe /s CHS.reg
- <SYSTEM32>\regini.exe regini.ini
- <SYSTEM32>\cacls.exe "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk" /t /e /c /g everyone:f
- <SYSTEM32>\regini.exe bak.ini
- %WINDIR%\regedit.exe /s CHS.reg
- %TEMP%\nso3.tmp\ns4.tmp
- %TEMP%\nso3.tmp\nsExec.dll
- %TEMP%\nso3.tmp\ns5.tmp
- %TEMP%\nso3.tmp\ns7.tmp
- %TEMP%\nso3.tmp\ns6.tmp
- %TEMP%\nso3.tmp\System.dll
- %TEMP%\nsy2.tmp
- <SYSTEM32>\regini.ini
- <SYSTEM32>\bak.ini
- <SYSTEM32>\CHS.reg
- %TEMP%\nso3.tmp\ns6.tmp
- <SYSTEM32>\regini.ini
- %TEMP%\nso3.tmp\ns5.tmp
- %TEMP%\nso3.tmp\ns4.tmp
- <SYSTEM32>\bak.ini
- ClassName: 'RegEdit_RegEdit' WindowName: ''