Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Kingsoft Antivirus WebShield Service] 'Start' = '00000002'
- '%WINDIR%\Resources\KSWebShield.exe'
- '%TEMP%\uninst.exe'
- '%TEMP%\~nsu.tmp\Au_.exe' _?=%TEMP%\
- '%WINDIR%\Resources\KSWebShield.exe' -start
- '%TEMP%\nst3.tmp\ns4.tmp' cmd.exe /c KSWebShield -install
- '%WINDIR%\Resources\KSWebShield.exe' -install
- '%TEMP%\nst3.tmp\ns5.tmp' cmd.exe /c KSWebShield -start
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://ie.#h-cn.cc/
- '%PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE' http://tj.#####code.meibu.com:8080/jsie/tj.html?ye#
- %TEMP%\nst3.tmp\System.dll
- %TEMP%\temp.ini
- %TEMP%\nst3.tmp\ns5.tmp
- %ALLUSERSPROFILE%\Application Data\kingsoft\kws\kws.ini
- %TEMP%\~nsu.tmp\Au_.exe
- %TEMP%\nsa9.tmp
- %TEMP%\uninst.exe
- %TEMP%\nse7.tmp
- <SYSTEM32>\kwssp.dll
- <SYSTEM32>\kswebshield.dll
- %TEMP%\nss2.tmp
- <SYSTEM32>\kwsui.dll
- %TEMP%\nst3.tmp\ns4.tmp
- %WINDIR%\Resources\KWSSVC.log
- %WINDIR%\Resources\KSWebShield.exe
- %TEMP%\nst3.tmp\nsExec.dll
- %WINDIR%\Resources\KSWebShield.exe
- %ALLUSERSPROFILE%\Application Data\kingsoft\kws\kws.ini
- <SYSTEM32>\kswebshield.dll
- <SYSTEM32>\kwsui.dll
- <SYSTEM32>\kwssp.dll
- %TEMP%\nst3.tmp\System.dll
- %TEMP%\uninst.exe
- %TEMP%\temp.ini
- %TEMP%\nst3.tmp\ns4.tmp
- %TEMP%\nst3.tmp\ns5.tmp
- %TEMP%\nst3.tmp\nsExec.dll
- ClassName: '' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'kws::OSUCWindowClass' WindowName: ''