Техническая информация
- <SYSTEM32>\ntvdm.exe
- C:\zv\Param.dll
- C:\zv\QRGM.BAT
- %WINDIR%\Temp\scs1.tmp
- %WINDIR%\Temp\scs2.tmp
- C:\zv\MSVC.DLL
- %WINDIR%\Temp\scs1.tmp
- %WINDIR%\Temp\scs2.tmp
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-b5c.b60.380001'
- '<SYSTEM32>\cmd.exe' /c C:\zv\QRGM.BAT c:\zv\PARAM.DLL c:\zv\MSVC.DLL
- '<SYSTEM32>\ntvdm.exe' -f