Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'wextract_cleanup0' = 'rundll32.exe <SYSTEM32>\advpack.dll,DelNodeRunDLL32 "%TEMP%\IXP000.TMP\"'
- %TEMP%\is-L7UG7.tmp\is-O1LO0.tmp /SL4 $300DC "%TEMP%\IXP000.TMP\ЧФ¶ЇІй~1.EXE" 64000 64000
- %TEMP%\IXP000.TMP\ЧФ¶ЇІй~1.EXE
- %TEMP%\IXP000.TMP\10010.EXE
- %WINDIR%\regedit.exe /s 1.reg
- <SYSTEM32>\cmd.exe /c ""%TEMP%\E291.CMD""
- %TEMP%\is-L7UG7.tmp\is-O1LO0.tmp
- %TEMP%\is-LA70L.tmp\_isetup\_RegDLL.tmp
- %TEMP%\is-LA70L.tmp\_isetup\_shfoldr.dll
- %TEMP%\IXP000.TMP\1.reg
- %TEMP%\IXP000.TMP\10010.EXE
- %TEMP%\IXP000.TMP\ЧФ¶ЇІй~1.EXE
- %TEMP%\E291.CMD
- %TEMP%\IXP000.TMP\1.reg
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''