Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Kingsoft Antivirus WebShield Service] 'Start' = '00000002'
- %PROGRAM_FILES%\ymLevel2_Taste\info.exe
- %PROGRAM_FILES%\ymLevel2_Taste\svchost.exe -start -install
- %PROGRAM_FILES%\ymLevel2_Taste\setup_24756.exe
- %PROGRAM_FILES%\їмЅЭАё\KDocks.exe
- <SYSTEM32>\cmd.exe /c ""%PROGRAM_FILES%\ymLevel2_Taste\u.bat" "
- <SYSTEM32>\wscript.exe "%PROGRAM_FILES%\ymLevel2_Taste\u.vbs"
- [<HKLM>\SOFTWARE\FlashFXP]
- [<HKCU>\Software\FlashFXP]
- %PROGRAM_FILES%\ymLevel2_Taste\kwsui.dll
- %PROGRAM_FILES%\ymLevel2_Taste\svchost.exe
- %PROGRAM_FILES%\ymLevel2_Taste\kswebshield.dll
- %PROGRAM_FILES%\ymLevel2_Taste\kwssp.dll
- %PROGRAM_FILES%\їмЅЭАё\kkjDock.cfg
- %PROGRAM_FILES%\ymLevel2_Taste\KWSSVC.log
- %PROGRAM_FILES%\ymLevel2_Taste\u.bat
- %PROGRAM_FILES%\ymLevel2_Taste\u.vbs
- %PROGRAM_FILES%\ymLevel2_Taste\kswbc.dll
- %TEMP%\nst3.tmp\System.dll
- %PROGRAM_FILES%\їмЅЭАё\KDocks.exe
- %PROGRAM_FILES%\ymLevel2_Taste\info.exe
- %PROGRAM_FILES%\ymLevel2_Taste\setup_24756.exe
- %ALLUSERSPROFILE%\Application Data\kingsoft\kws\spitesp.dat
- %ALLUSERSPROFILE%\Application Data\kingsoft\kws\kws.ini
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\nst3.tmp\System.dll
- ClassName: 'kws::OSUCWindowClass' WindowName: ''
- ClassName: 'Progman' WindowName: 'Program Manager'
- ClassName: 'Shell_TrayWnd' WindowName: ''