Техническая информация
- %TEMP%\Setup3014.exe
- %TEMP%\TheWorld_3.0.exe
- %TEMP%\DFSetup.exe
- <SYSTEM32>\cmd.exe /c ""%TEMP%\DelTemp.bat" "
- <SYSTEM32>\regsvr32.exe /s %PROGRAM_FILES%\QVOD71\QvodEx.dll
- %TEMP%\nsc5.tmp\КАЅзЦ®ґ°a.ini
- %PROGRAM_FILES%\QVOD71\QvodEx.dll
- %TEMP%\nss4.tmp
- %TEMP%\DelTemp.bat
- %TEMP%\version.ini
- %TEMP%\nsc5.tmp\ioSpecial.ini
- %TEMP%\nsc5.tmp\modern-wizard.bmp
- %WINDIR%\ime\SPTIPIMERS.ini
- %TEMP%\Setup3014.exe
- %TEMP%\DFSetup.exe
- %TEMP%\TheWorld_3.0.exe
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Жф¶Ї Internet Explorer дЇААЖч.url
- %HOMEPATH%\Start Menu\Жф¶Ї Internet Explorer дЇААЖч.url
- %HOMEPATH%\Favorites\ѕ«Ж·НшЦ·µјєЅ.url
- %HOMEPATH%\Desktop\Internet Explorer.url
- %TEMP%\DFSetup.exe
- 'co####.ie.sogou.com':80
- co####.ie.sogou.com/version.php?h=################################################
- DNS ASK co####.ie.sogou.com
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''