Technical Information
- [<HKLM>\Software\Wow6432Node\microsoft\windows\currentversion\Explorer\shellexecutehooks] '{A1A6BC2E-C6A1-43C1-8884-A31D772F42B8}' = ''
- %WINDIR%\fonts\jnwybejguvaxbu5d.ttf
- %WINDIR%\syswow64\a1a6bc2e.dll
- '%WINDIR%\syswow64\cmd.exe' /c del <Full path to file> >> NUL' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c del <Full path to file> >> NUL