Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'DfrgCommonext' = 'rundll32.exe "<LS_APPDATA>\lanAuthenticationPort\DfrgCommonext.dll",DirectPathWan BthMaplog'
- <SYSTEM32>\rundll32.exe "<LS_APPDATA>\lanAuthenticationPort\DfrgCommonext.dll",DirectPathWan BthMaplog
- <SYSTEM32>\rundll32.exe ""%TEMP%\BthWIxx.dll"", DirectPathWan i18Padclass
- <LS_APPDATA>\lanAuthenticationPort\DfrgCommonext.dll
- %TEMP%\BthWIxx.dll
- %TEMP%\BthWIxx.dll
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'DfrgWICmds' WindowName: ''