Техническая информация
- '%WINDIR%\adcnk.exe'
- '<SYSTEM32>\cmd.exe' /c ""%WINDIR%\rich.bat" "
- '<SYSTEM32>\wscript.exe' "%WINDIR%\rich.vbs"
- %WINDIR%\adcnk.exe
- %WINDIR%\rich.vbs
- %ALLUSERSPROFILE%\桌面\网 吧 首 页.lnk
- C:\Tools\iesogou\iesogou.vbs
- %WINDIR%\rich.bat
- %APPDATA%\SogouExplorer\MCPattern.db
- %APPDATA%\SogouExplorer\config.xml
- <DRIVERS>\richdisk.sys
- <DRIVERS>\richboot.sys
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'