Technical Information
- %TEMP%\~nsu.tmp\au_.exe
- %TEMP%\nsk7511.tmp\nsexec.dll
- %TEMP%\nsk7511.tmp\processwork.dll
- ClassName: '#32770' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- '%TEMP%\~nsu.tmp\au_.exe' _?=<Current directory>\
- '%WINDIR%\syswow64\regsvr32.exe' /u /s "%WINDIR%\client-detect.ocx"' (with hidden window)
- '%WINDIR%\syswow64\regsvr32.exe' /u /s "%WINDIR%\client-detect.ocx"