Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'wextract_cleanup0' = 'rundll32.exe <SYSTEM32>\advpack.dll,DelNodeRunDLL32 "%TEMP%\IXP000.TMP\"'
- [<HKLM>\SOFTWARE\Classes\MSProgramGroup\Shell\Open\Command] '' = '<SYSTEM32>\grpconv.exe %1'
- '%TEMP%\IXP000.TMP\findnds.exe'
- '<SYSTEM32>\grpconv.exe' -o
- <SYSTEM32>\SET3.tmp
- %TEMP%\IXP000.TMP\ADVPACK.DLL
- %TEMP%\IXP000.TMP\nw_unin.inf
- <SYSTEM32>\SET4.tmp
- %WINDIR%\Help\SET7.tmp
- %WINDIR%\SET6.tmp
- %WINDIR%\inf\QFE\SET5.tmp
- %TEMP%\IXP000.TMP\W95inf32.dll
- %TEMP%\IXP000.TMP\nwnp32.nw4
- %TEMP%\IXP000.TMP\nwnp32.nw3
- %TEMP%\IXP000.TMP\findnds.exe
- %TEMP%\IXP000.TMP\nwnpupd.inf
- %TEMP%\IXP000.TMP\W95inf16.dll
- %TEMP%\IXP000.TMP\Qfecheck.hlp
- %TEMP%\IXP000.TMP\Qfecheck.exe
- %TEMP%\IXP000.TMP\nwnpupd.inf
- %TEMP%\IXP000.TMP\Qfecheck.exe
- %TEMP%\IXP000.TMP\nwnp32.nw4
- %TEMP%\IXP000.TMP\findnds.exe
- %TEMP%\IXP000.TMP\nwnp32.nw3
- %TEMP%\IXP000.TMP\nw_unin.inf
- %TEMP%\IXP000.TMP\ADVPACK.DLL
- %TEMP%\IXP000.TMP\W95inf32.dll
- %TEMP%\IXP000.TMP\Qfecheck.hlp
- %TEMP%\IXP000.TMP\W95inf16.dll
- %WINDIR%\SET6.tmp в %WINDIR%\qfecheck.exe
- %WINDIR%\Help\SET7.tmp в %WINDIR%\Help\qfecheck.hlp
- %WINDIR%\inf\QFE\SET5.tmp в %WINDIR%\inf\QFE\NW_unin.inf
- <SYSTEM32>\SET3.tmp в <SYSTEM32>\NWNP32.nw3
- <SYSTEM32>\SET4.tmp в <SYSTEM32>\nwnp32.nw4