Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Kingsoft Antivirus WebShield Service] 'Start' = '00000002'
- %ALLUSERSPROFILE%\Application Data\wd\KSWebShield.exe -start -install
- %TEMP%\nso2.tmp\ns3.tmp cmd.exe /c "%ALLUSERSPROFILE%\Application Data\wd\u.bat"
- %HOMEPATH%\Favorites\БґЅУ\К®Т»ЅЦµҐ»ъУОП·.url
- %HOMEPATH%\Favorites\БґЅУ\МФ±¦МШВф.url
- %HOMEPATH%\Favorites\БґЅУ\НЕ№є_ГлЙ±Нш.url
- %HOMEPATH%\Favorites\БґЅУ\°¬µПЙо¶ИЛСЛч.url
- %ALLUSERSPROFILE%\Desktop\ФЪПЯ_УОП·.url2
- %ALLUSERSPROFILE%\Desktop\НшЙПМФ±¦.url2
- %HOMEPATH%\Favorites\БґЅУ\88yyФЪПЯРЎУОП·.url
- %HOMEPATH%\Favorites\МФ±¦МШВф.url
- %HOMEPATH%\Favorites\НЕ№є_ГлЙ±Нш.url
- %HOMEPATH%\Favorites\ФЪПЯСФЗйРЎЛµФД¶Б.url
- %HOMEPATH%\Favorites\К®Т»ЅЦµҐ»ъУОП·.url
- %HOMEPATH%\Favorites\БґЅУ\ФЪПЯСФЗйРЎЛµФД¶Б.url
- %HOMEPATH%\Favorites\88yyФЪПЯРЎУОП·.url
- %HOMEPATH%\Favorites\°¬µПЙо¶ИЛСЛч.url
- <SYSTEM32>\i_e.ico
- %ALLUSERSPROFILE%\Application Data\wd\KSWebShield.exe
- %ALLUSERSPROFILE%\Application Data\wd\kswebshield.dll
- %ALLUSERSPROFILE%\Application Data\wd\kswbc.dll
- %ALLUSERSPROFILE%\Application Data\wd\kwssp.dll
- %ALLUSERSPROFILE%\Application Data\kingsoft\kws\kws.ini
- %TEMP%\nso2.tmp\AccessControl.dll
- %ALLUSERSPROFILE%\Application Data\kingsoft\kws\spitesp.dat
- %ALLUSERSPROFILE%\Application Data\wd\KWSSVC.log
- <SYSTEM32>\txb.ico
- <SYSTEM32>\xxyx.ico
- %TEMP%\nso2.tmp\ns3.tmp
- %ALLUSERSPROFILE%\Application Data\wd\kwsui.dll
- %ALLUSERSPROFILE%\Application Data\wd\u.bat
- %TEMP%\nso2.tmp\nsExec.dll
- %TEMP%\nso2.tmp\ns3.tmp
- ClassName: 'kws::OSUCWindowClass' WindowName: ''