Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Kingsoft Antivirus WebShield Service] 'Start' = '00000002'
- %APPDATA%\kwsafe\KSAFE.exe -start
- %APPDATA%\kwsafe\KSAFE.exe
- %TEMP%\nsk3.tmp\ns4.tmp %APPDATA%\kwsafe\a.bat
- %APPDATA%\kwsafe\KSAFE.exe -install
- <SYSTEM32>\cmd.exe /c "%APPDATA%\kwsafe\a.bat"
- %APPDATA%\kwsafe\kwsui.dll
- %APPDATA%\kwsafe\kwstray.exe
- %APPDATA%\kwsafe\kwssp.dll
- %APPDATA%\kwsafe\KWSSVC.log
- %TEMP%\nsk3.tmp\ns4.tmp
- %TEMP%\nsk3.tmp\nsExec.dll
- %APPDATA%\kwsafe\kswebshield.dll
- %ALLUSERSPROFILE%\Application Data\kingsoft\kws\spitesp.dat
- %ALLUSERSPROFILE%\Application Data\kingsoft\kws\kws.ini
- %TEMP%\nsb2.tmp
- %APPDATA%\kwsafe\kswbc.dll
- %APPDATA%\kwsafe\a.bat
- %APPDATA%\kwsafe\KSAFE.exe
- %TEMP%\nsk3.tmp\nsExec.dll
- %TEMP%\nsk3.tmp\ns4.tmp
- ClassName: 'kws::OSUCWindowClass' WindowName: ''