Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Kingsoft Antivirus WebShield Service] 'Start' = '00000002'
- %ALLUSERSPROFILE%\Application Data\WD\KSWebShield.exe -start -install
- %WINDIR%\sleep.exe 500
- <SYSTEM32>\cmd.exe /c """%TEMP%\temg_tmp.bat"" "
- <SYSTEM32>\cmd.exe /c ""%ALLUSERSPROFILE%\Application Data\wd\u.bat" "
- %ALLUSERSPROFILE%\Desktop\Internat Exlporer.url2
- %ALLUSERSPROFILE%\Desktop\МФ±¦№єОп.url2
- %WINDIR%\tbgw.ico
- %TEMP%\nse3.tmp\AccessControl.dll
- %ALLUSERSPROFILE%\Application Data\kingsoft\kws\kws.ini
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0J2LM5OP\wpad[1].dat
- %TEMP%\temg_tmp.bat
- %ALLUSERSPROFILE%\Application Data\WD\KWSSVC.log
- %ALLUSERSPROFILE%\Application Data\WD\KSWebShield.exe
- %ALLUSERSPROFILE%\Application Data\WD\kswbc.dll
- %TEMP%\nsk2.tmp
- %TEMP%\nse3.tmp\FindProcDLL.dll
- %ALLUSERSPROFILE%\Application Data\WD\kwsui.dll
- %ALLUSERSPROFILE%\Application Data\WD\u.bat
- %ALLUSERSPROFILE%\Application Data\WD\kswebshield.dll
- %ALLUSERSPROFILE%\Application Data\WD\kwssp.dll
- %TEMP%\nse3.tmp\FindProcDLL.dll
- %TEMP%\nse3.tmp\AccessControl.dll
- 'wpad.localdomain':80
- 'if#.#uba.net':80
- wpad.localdomain/wpad.dat
- if#.#uba.net/urlrcv.php?mc#####################################################
- DNS ASK wpad.localdomain
- DNS ASK if#.#uba.net
- ClassName: 'kws::OSUCWindowClass' WindowName: ''