Техническая информация
- firefox.exe
- %TEMP%\nsm536d.tmp\uac.dll
- %TEMP%\nsm536d.tmp\version.dll
- %ProgramFiles(x86)%\wow search\icons\install.ico
- %ProgramFiles(x86)%\wow search\icons\wow_ico.ico
- %TEMP%\nsm536d.tmp\nsprocess.dll
- %TEMP%\sqlite3.exe
- %TEMP%\prefjsoncpp.exe
- %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\searchplugins\search_engine.xml
- %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\searchplugins\wow_search_ff.ps1
- %TEMP%\nsm536d.tmp\nsexec.dll
- %APPDATA%\mozilla\firefox\profiles\m15ucxjx.default\search-metadata.json
- %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\search-metadata.json
- %TEMP%\nsm536d.tmp\system.dll
- %TEMP%\nsm536d.tmp\nsexec.dll
- %TEMP%\nsm536d.tmp\nsprocess.dll
- %TEMP%\nsm536d.tmp\system.dll
- %TEMP%\nsm536d.tmp\uac.dll
- %TEMP%\nsm536d.tmp\version.dll
- %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\prefs.js
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -inputformat none -ExecutionPolicy RemoteSigned -File "wow_search_ff.ps1"' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -inputformat none -ExecutionPolicy RemoteSigned -File "wow_search_ff.ps1"