Техническая информация
- [HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'Win' = 'rundll32 shell32,ShellExec_RunDLL regsvr32 -s "%TEMP%\sfx.dll"'
- %TEMP%\aut7982.tmp
- %TEMP%\windowsloader.exe
- %TEMP%\aut7dd7.tmp
- %TEMP%\sfx.dll
- %TEMP%\aut7982.tmp
- %TEMP%\aut7dd7.tmp
- ClassName: 'STATIC' WindowName: 'q3TDgcZ4p2up0Z77amQP 000009D0'
- '%TEMP%\windowsloader.exe'
- '%WINDIR%\syswow64\cmd.exe' /c start regsvr32 -s "%TEMP%\sfx.dll"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c start regsvr32 -s "%TEMP%\sfx.dll"
- '%WINDIR%\syswow64\regsvr32.exe' -s "%TEMP%\sfx.dll"