Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'wextract_cleanup0' = 'rundll32.exe <SYSTEM32>\advpack.dll,DelNodeRunDLL32 "%TEMP%\IXP000.TMP\"'
- %TEMP%\IXP000.TMP\msinfhlp.exe ;install; ;msvs.dat;
- %TEMP%\IXP000.TMP\Diar1.___
- %TEMP%\IXP000.TMP\RICHTX32.___
- %TEMP%\IXP000.TMP\comdlg32.___
- %TEMP%\IXP000.TMP\msvs.dat
- %TEMP%\IXP000.TMP\SexUnifo.___
- %TEMP%\IXP000.TMP\msinfhlp.exe
- <SYSTEM32>\wbem\Performance\WmiApRpl_new.ini
- %TEMP%\IXP000.TMP\vjreg.exe
- %TEMP%\IXP000.TMP\MSCOMCT2.___
- %TEMP%\IXP000.TMP\Diary.___
- ClassName: '{42895C58-5A32-4556-BE77-A9F0666291B9}' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''