Техническая информация
- [<HKLM>\SOFTWARE\Classes\odfile\shell\open\command] '' = 'explorer /n,"%PROGRAM_FILES%\T%H"'
- [<HKLM>\SOFTWARE\Classes\omfile\shell\open\command] '' = 'explorer /n,"%PROGRAM_FILES%\%H"'
- %TEMP%\nsk4.tmp\ns6.tmp c:\3528.bat
- %PROGRAM_FILES%\kuaijiejie\KDocks.exe
- %HOMEPATH%\Templates\zxc3520.exe
- %HOMEPATH%\Templates\kkinst.exe
- <SYSTEM32>\wbem\wmic.exe userAccount where "Name='%USERNAME%'" get SID /value
- <SYSTEM32>\cmd.exe /c c:\3528.bat
- [<HKLM>\SOFTWARE\FlashFXP]
- [<HKCU>\Software\FlashFXP]
- %PROGRAM_FILES%\kuaijiejie\icons\јЖЛгЖч.png
- %PROGRAM_FILES%\kuaijiejie\icons\јЗКВ±ѕ.png
- %PROGRAM_FILES%\kuaijiejie\icons\IE2.png
- %TEMP%\nsk4.tmp\ns6.tmp
- %PROGRAM_FILES%\kuaijiejie\icons\їШЦЖГж°е.png
- %PROGRAM_FILES%\kuaijiejie\icons\soft\ACDSee.png
- %PROGRAM_FILES%\kuaijiejie\icons\soft\FXP.png
- %PROGRAM_FILES%\kuaijiejie\icons\ОТµДµзДФ.png
- %PROGRAM_FILES%\kuaijiejie\icons\ОТµДОДµµ.png
- %PROGRAM_FILES%\kuaijiejie\icons\IE1.png
- %HOMEPATH%\Templates\win132035.txt
- %HOMEPATH%\Templates\a.bat
- %TEMP%\nsa2.tmp\System.dll
- %HOMEPATH%\Templates\inst.exe
- %HOMEPATH%\Templates\kkinst.exe
- C:\3528.bat
- %TEMP%\nsk4.tmp\nsExec.dll
- %TEMP%\nsk4.tmp\System.dll
- %PROGRAM_FILES%\kuaijiejie\KDocks.exe
- %TEMP%\nsa2.tmp\System.dll
- ClassName: 'Shell_TrayWnd' WindowName: ''