Technical Information
- %WINDIR%\winhlp32.exe
- %TEMP%\dynwrapx.dll
- '%WINDIR%\syswow64\regsvr32.exe' /I /S "%TEMP%\dynwrapx.dll"' (with hidden window)
- '%WINDIR%\syswow64\wscript.exe' //b //e:vbscript "<PATH_SAMPLE>.vbs"
- '%WINDIR%\syswow64\regsvr32.exe' /I /S "%TEMP%\dynwrapx.dll"
- '%WINDIR%\winhlp32.exe'