Техническая информация
- '%TEMP%\nsn2.tmp\ns3.tmp' "<SYSTEM32>\taskkill.exe" /F /IM iexplore.exe /T
- '<SYSTEM32>\regsvr32.exe' /n /i:"CB7F8E3E-62F8-4E72-BE96-1520352D6391 00000000-0000-0000-0000-000000000000" /s "%PROGRAM_FILES%\CB7F8E3E-62F8-4E72-BE96-1520352D6391\khpyefofvn.dll"
- '<SYSTEM32>\taskkill.exe' /F /IM iexplore.exe /T
- iexplore.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1609' = '0'
- %TEMP%\nsn2.tmp\ns3.tmp
- %TEMP%\nsn2.tmp\nsExec.dll
- %TEMP%\nsn2.tmp\System.dll
- %PROGRAM_FILES%\CB7F8E3E-62F8-4E72-BE96-1520352D6391\khpyefofvn.dll
- %TEMP%\nsn2.tmp\System.dll
- %TEMP%\nsn2.tmp\nsExec.dll
- %TEMP%\nsn2.tmp\ns3.tmp
- ClassName: '' WindowName: ''