Техническая информация
- %WINDIR%\Tasks\ms.job
- <SYSTEM32>\regsvr32.exe /u /s "<SYSTEM32>\1dl3.dll"
- <SYSTEM32>\regsvr32.exe /u /s "<SYSTEM32>\0dde.dll"
- <SYSTEM32>\rundll32.exe ,Always
- <SYSTEM32>\regsvr32.exe /s "<SYSTEM32>\1dl3.dll"
- <SYSTEM32>\regsvr32.exe /u /s "<SYSTEM32>\8ed3.dll"
- <SYSTEM32>\regsvr32.exe /u /s "<SYSTEM32>\63b0.dll"
- <SYSTEM32>\regsvr32.exe /u /s "<SYSTEM32>\36b1.dll"
- <SYSTEM32>\regsvr32.exe /u /s "<SYSTEM32>\6eif.dll"
- %TEMP%\nsn3.tmp\System.dll
- <SYSTEM32>\1dl3.dll
- %WINDIR%\d3e0.exe
- %TEMP%\nsc2.tmp
- %TEMP%\_Inst.dll
- %TEMP%\bho.dll
- %TEMP%\nsn3.tmp\System.dll
- ClassName: 'Shell_TrayWnd' WindowName: ''