Техническая информация
- %TEMP%\2447_1.exe
- %TEMP%\TheWorld_OEM_5.exe
- %TEMP%\AISetup.exe
- <SYSTEM32>\cmd.exe /c ""%TEMP%\DelTemp.bat" "
- <SYSTEM32>\regsvr32.exe /s %PROGRAM_FILES%\QVOD5\QvodEx.dll
- %TEMP%\nsn5.tmp\ioSpecial.ini
- %PROGRAM_FILES%\QVOD5\QvodEx.dll
- %TEMP%\nsc4.tmp
- %HOMEPATH%\Start Menu\Жф¶Ї Internet Explorer дЇААЖч.url
- %TEMP%\DelTemp.bat
- %TEMP%\version.ini
- %TEMP%\nsn5.tmp\modern-wizard.bmp
- %TEMP%\TheWorld_OEM_5.exe
- %TEMP%\2447_1.exe
- %TEMP%\nsl2.tmp\System.dll
- %TEMP%\AISetup.exe
- %HOMEPATH%\Desktop\Internet Explorer.url
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Жф¶Ї Internet Explorer дЇААЖч.url
- %WINDIR%\ime\SPTIPIMERS.ini
- %HOMEPATH%\Favorites\ѕ«Ж·НшЦ·µјєЅ.url
- %TEMP%\AISetup.exe
- %TEMP%\nsl2.tmp\System.dll
- 'co####.ie.sogou.com':80
- co####.ie.sogou.com/version.php?h=################################################
- DNS ASK co####.ie.sogou.com
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '#32770' WindowName: ''