Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'Crypthtml' = '{E9196AA2-7FE6-498B-83A5-728FC6D5EBD0}'
- <SYSTEM32>\htmdoc.dll
- <SYSTEM32>\styledos.dll
- %TEMP%\_is154671.ini
- %TEMP%\_is154312.ini
- <SYSTEM32>\webodbc.dll
- %TEMP%\UUU2.tmp
- %TEMP%\UUU1.tmp
- %TEMP%\UUU3.tmp
- <SYSTEM32>\progcat32.dll
- %TEMP%\_is154312.ini
- %TEMP%\_is154671.ini
- %TEMP%\UUU3.tmp
- %TEMP%\UUU1.tmp
- %TEMP%\UUU2.tmp