Technical Information
- '<SYSTEM32>\cmd.exe' /c del <Full path to file> > nul
- '<SYSTEM32>\regsvr32.exe' /s "%WINDIR%\fonts\kjsjdvbn.dll"
- Handler for all processes: %WINDIR%\fonts\kjsjdvbn.dll
- ClassName: 'OLLYDBG' WindowName: ''
- %WINDIR%\Fonts\gzgbxiazai.dat
- %WINDIR%\Fonts\kjsjdvbn.tmp
- %WINDIR%\xxxxxx.dll
- from %WINDIR%\Fonts\kjsjdvbn.tmp to %WINDIR%\Fonts\kjsjdvbn.dll