Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'wextract_cleanup0' = 'rundll32.exe <SYSTEM32>\advpack.dll,DelNodeRunDLL32 "%TEMP%\IXP000.TMP\"'
- '%TEMP%\IXP000.TMP\dpinst.exe' /LM /EL /F /D
- '%TEMP%\IXP000.TMP\install.exe'
- %TEMP%\IXP000.TMP\dpinst.xml
- %TEMP%\IXP000.TMP\32.in
- %TEMP%\IXP000.TMP\vista_64.sy
- %TEMP%\IXP000.TMP\install.exe
- %WINDIR%\DPINST.LOG
- %TEMP%\IXP000.TMP\64.ca
- %TEMP%\IXP000.TMP\32.ca
- %TEMP%\IXP000.TMP\2003_x64.sy
- %TEMP%\IXP000.TMP\xp.sy
- %TEMP%\IXP000.TMP\dp_x64.exe
- %TEMP%\IXP000.TMP\dp_x86.exe
- %TEMP%\IXP000.TMP\vista_32.sy
- %TEMP%\IXP000.TMP\2003.sy
- %TEMP%\IXP000.TMP\64.in
- %TEMP%\IXP000.TMP\2k.sy
- %TEMP%\IXP000.TMP\32.in в %TEMP%\IXP000.TMP\netnnusb.inf
- %TEMP%\IXP000.TMP\32.ca в %TEMP%\IXP000.TMP\netnnusb.cat
- %TEMP%\IXP000.TMP\xp.sy в %TEMP%\IXP000.TMP\netnnusb.sys
- %TEMP%\IXP000.TMP\dp_x86.exe в %TEMP%\IXP000.TMP\dpinst.exe
- ClassName: 'Shell_TrayWnd' WindowName: ''