Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'nieguideplus' = '"%PROGRAM_FILES%\nieguideplus\nieguideup.exe" -o'
- <SYSTEM32>\cmd.exe /c \DelUS.bat
- C:\nieguideup.exe
- %TEMP%\nsy2.tmp\SelfDelete.dll
- C:\DelUS.bat
- %TEMP%\nsy2.tmp\registry.dll
- %TEMP%\nsy2.tmp\KillProcDLL.dll
- %TEMP%\nsy2.tmp\DLLWaitForKillProgram.dll
- %TEMP%\nsy2.tmp\registry.dll
- %TEMP%\nsy2.tmp\SelfDelete.dll
- %TEMP%\nsy2.tmp\DLLWaitForKillProgram.dll
- %TEMP%\nsy2.tmp\KillProcDLL.dll
- ClassName: 'Indicator' WindowName: ''