Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'mciNetdll32' = 'rundll32.exe "<LS_APPDATA>\userAuthenticationcdrom\mciNetdll32.dll",AsyncHelpMusic smiWIMgmt'
- %TEMP%\is-P21NP.tmp\setup.tmp /SL5="$50036,702221,54272,%TEMP%\setup.exe"
- %TEMP%\setup.exe
- <SYSTEM32>\rundll32.exe "<LS_APPDATA>\userAuthenticationcdrom\mciNetdll32.dll",AsyncHelpMusic smiWIMgmt
- <SYSTEM32>\rundll32.exe "%TEMP%\SyncNetSupport.dll", AsyncHelpMusic DRMCommonPath
- %TEMP%\is-P21NP.tmp\setup.tmp
- %TEMP%\is-B1N4D.tmp\_isetup\_RegDLL.tmp
- %TEMP%\is-B1N4D.tmp\_isetup\_shfoldr.dll
- %TEMP%\SyncNetSupport.dll
- %TEMP%\setup.exe
- <LS_APPDATA>\userAuthenticationcdrom\mciNetdll32.dll
- %TEMP%\SyncNetSupport.dll
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'userPadhid' WindowName: ''