Техническая информация
- %TEMP%\TheWorld_OEM_6.exe
- %TEMP%\hahayx.exe
- %TEMP%\AHSetup.exe
- <SYSTEM32>\cmd.exe /c ""%TEMP%\DelTemp.bat" "
- <SYSTEM32>\wbem\wmiadap.exe /R /T
- <SYSTEM32>\regsvr32.exe /s %PROGRAM_FILES%\fx678Toolbar\fx678Toolbar.dll
- %PROGRAM_FILES%\fx678Toolbar\fx678Toolbar.dll
- %TEMP%\nse5.tmp
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\№єОпЙМіЗ.url
- %PROGRAM_FILES%\Baidu\Toolbar\BaiduBarX_Tmp\BaiduBarX.dll
- %HOMEPATH%\Desktop\№єОпЙМіЗ.url
- <SYSTEM32>\wbem\Performance\WmiApRpl_new.ini
- %TEMP%\DelTemp.bat
- %PROGRAM_FILES%\Baidu\Toolbar\BaiduBarX.dll
- %TEMP%\nsh6.tmp\ioSpecial.ini
- %TEMP%\nsh6.tmp\modern-wizard.bmp
- %TEMP%\TheWorld_OEM_6.exe
- %WINDIR%\ime\SPTIPIMERS.ini
- %TEMP%\hahayx.exe
- %TEMP%\nsk2.tmp\System.dll
- %TEMP%\AHSetup.exe
- %HOMEPATH%\Start Menu\Жф¶Ї Internet Explorer дЇААЖч.url
- %APPDATA%\Baidu\Toolbar\Custom Buttons\custom.xml
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Жф¶Ї Internet Explorer дЇААЖч.url
- %HOMEPATH%\Favorites\ѕ«Ж·НшЦ·µјєЅ.url
- %HOMEPATH%\Desktop\Internet Explorer.url
- %TEMP%\AHSetup.exe
- %PROGRAM_FILES%\Baidu\Toolbar\BaiduBarX_Tmp\BaiduBarX.dll
- %TEMP%\nsk2.tmp\System.dll
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: '#32770' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''