Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Kingsoft Antivirus WebShield Service] 'Start' = '00000002'
- %PROGRAM_FILES%\kingsoft\KSWebShield.exe -start -install
- <SYSTEM32>\ping.exe -n 5 127.0.0.1
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE http://www.66##.net/?uk####
- <SYSTEM32>\cmd.exe /c %TEMP%\lnk.bat
- %HOMEPATH%\Favorites\ТБИЛЕ®РФНш.url
- %PROGRAM_FILES%\ico\Taobao.ico
- %HOMEPATH%\Desktop\ТБИЛЕ®РФНш.url
- %HOMEPATH%\Favorites\ФЪПЯµзУ°.url
- %PROGRAM_FILES%\ico\Beauty.ico
- %HOMEPATH%\Desktop\МФ±¦№єОп.url
- %HOMEPATH%\Desktop\ГАЕ®КУЖµ.url
- %HOMEPATH%\Favorites\ГАЕ®КУЖµ.url
- %PROGRAM_FILES%\ico\Video.ico
- %PROGRAM_FILES%\kingsoft\KWSSVC.log
- %HOMEPATH%\Favorites\МФ±¦№єОп.url
- %PROGRAM_FILES%\kingsoft\kwssp.dll
- %TEMP%\lnk.bat
- %PROGRAM_FILES%\kingsoft\KSWebShield.dll
- %ALLUSERSPROFILE%\Desktopkws\kws.ini
- %PROGRAM_FILES%\kingsoft\KSWebShield.exe
- %PROGRAM_FILES%\ico\Manhua.ico
- %PROGRAM_FILES%\ico\Film.ico
- %HOMEPATH%\Desktop\ФЪПЯµзУ°.url
- %HOMEPATH%\Favorites\ФЪПЯВю».url
- %PROGRAM_FILES%\kingsoft\kwsui.dll
- %HOMEPATH%\Desktop\ФЪПЯВю».url
- DNS ASK tt.#kad.com
- ClassName: 'Shell_TrayWnd' WindowName: ''