Техническая информация
- %TEMP%\nsh2.tmp
- %TEMP%\nsm3.tmp\System.dll
- %TEMP%\nsm3.tmp\nsExec.dll
- %TEMP%\nsm3.tmp\ns4.tmp
- %TEMP%\junction.exe
- %HOMEPATH%\My Documents\My Videos\Desktop.ini
- %TEMP%\nsm3.tmp\ns5.tmp
- %TEMP%\nsm3.tmp\ns6.tmp
- %HOMEPATH%\My Documents\My Videos\Desktop.ini
- %TEMP%\nsm3.tmp\ns4.tmp
- %TEMP%\nsm3.tmp\ns5.tmp
- '%TEMP%\nsm3.tmp\ns4.tmp' "<SYSTEM32>\CMD.EXE" /C "<SYSTEM32>\regsvr32 /s "<Текущая директория>\App\PicosmosTools\ShellEx_100.dll"
- '%TEMP%\nsm3.tmp\ns5.tmp' "%TEMP%\junction.exe" "%APPDATA%\Picosmos\Data" "<Текущая директория>\App\DefaultData"
- '%TEMP%\junction.exe' "%APPDATA%\Picosmos\Data" "<Текущая директория>\App\DefaultData"
- '%TEMP%\nsm3.tmp\ns6.tmp' "%TEMP%\junction.exe" "%HOMEPATH%\My Documents\My Pictures\Picosmos Capture" "<Текущая директория>\Data\Pictures"
- '%TEMP%\junction.exe' "%HOMEPATH%\My Documents\My Pictures\Picosmos Capture" "<Текущая директория>\Data\Pictures"
- '<SYSTEM32>\cmd.exe' /C "<SYSTEM32>\regsvr32 /s "<Текущая директория>\App\PicosmosTools\ShellEx_100.dll"
- '<SYSTEM32>\regsvr32.exe' /s "<Текущая директория>\App\PicosmosTools\ShellEx_100.dll