Техническая информация
- '<SYSTEM32>\regsvr32.exe' /s "<LS_APPDATA>\amk.dll"
- '<SYSTEM32>\regsvr32.exe' /s /u "<LS_APPDATA>\amk.dll"
- firefox.exe
- iexplore.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1609' = '00000000'
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\flashplayer@adobe.com.json
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\extensions\staged\flashplayer@adobe.com.xpi
- <LS_APPDATA>\amk.dll
- ClassName: 'MS_WINHELP' WindowName: ''