Technical Information
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\3FB824C44CC7ED623B66C8.lnk
- %TEMP%\_ir_sf7_temp_0\irsetup.exe "__IRAFN:<Full path to virus>"
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_1.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_0.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_3.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_2.bmp
- %PROGRAM_FILES%\ilovetb\TheWorld.ini
- %PROGRAM_FILES%\ilovetb\dailytips.ini
- %PROGRAM_FILES%\ilovetb\ImgCache\www.ioage.com_favicon.ico
- %PROGRAM_FILES%\ilovetb\theworld.ac
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_9.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_8.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_11.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_10.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_5.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_4.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_7.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_6.bmp
- %WINDIR%\onlyyou\Fav\ВМЙ«ИнјюХѕ.url
- %WINDIR%\onlyyou\Fav\МФ°ЎМФ - МФЈЎОТПІ»¶.url
- %WINDIR%\onlyyou\icons\2345.ico
- %WINDIR%\onlyyou\Fav\ѕ©¶«ЙМіЗ.url
- %WINDIR%\onlyyou\Fav\·ІїНіПЖ·.url
- %WINDIR%\onlyyou\Fav\2345НшХѕЦ®јТ.url
- %WINDIR%\onlyyou\Fav\µ±µ±НшЎЄНшЙП№єОпЦРРД.url
- %WINDIR%\onlyyou\Fav\ЧїФЅСЗВнС·.url
- %WINDIR%\onlyyou\icons\Thumbs.db
- %WINDIR%\onlyyou\icons\xtzj.ico
- %PROGRAM_FILES%\ilovetb\TheWorld.exe
- %PROGRAM_FILES%\ilovetb\xihuan.ico
- %WINDIR%\onlyyou\icons\Internet.ico
- %WINDIR%\onlyyou\icons\dang.ico
- %WINDIR%\onlyyou\icons\xihuan.ico
- %WINDIR%\onlyyou\icons\joyo.ico
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_12.bmp
- %WINDIR%\onlyyou\se.vbs
- %WINDIR%\onlyyou\ggnew.bat
- %WINDIR%\onlyyou\cpa.vbs
- %PROGRAM_FILES%\bigsoft\CPAX_Tbqszd.exe
- %PROGRAM_FILES%\iloveu\iloveu.ico
- %PROGRAM_FILES%\iloveu\theworld.ac
- %WINDIR%\onlyyou\ntao.bat
- %WINDIR%\onlyyou\se.reg
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\дЇААЖчЙПНш.lnk
- %ALLUSERSPROFILE%\Desktop\дЇААЖчЙПНш.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\дЇААЖчЙПНш.lnk
- %ALLUSERSPROFILE%\Start Menu\дЇААЖчЙПНш.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\МФПІ»¶.lnk
- %ALLUSERSPROFILE%\Desktop\МФПІ»¶.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\МФПІ»¶.lnk
- %ALLUSERSPROFILE%\Start Menu\МФПІ»¶.lnk
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_18.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_17.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\m445.mail.qq.com_favicon.ico
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_19.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_14.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_13.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_16.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_15.bmp
- %PROGRAM_FILES%\iloveu\dailytips.ini
- %PROGRAM_FILES%\ilovetb\ImgCache\union.dangdang.com_favicon.ico
- %PROGRAM_FILES%\iloveu\TheWorld.ini
- %PROGRAM_FILES%\iloveu\TheWorld.exe
- %PROGRAM_FILES%\ilovetb\ImgCache\taoke.alimama.com_favicon.ico
- %PROGRAM_FILES%\ilovetb\ImgCache\download.cnet.com_favicon.ico
- %PROGRAM_FILES%\ilovetb\ImgCache\www.taobao.com_favicon.ico
- %PROGRAM_FILES%\ilovetb\ImgCache\comment5.news.qq.com_favicon.ico
- %WINDIR%\onlyyou\config.xml
- %PROGRAM_FILES%\mychers\icons\Finder.png
- %PROGRAM_FILES%\mychers\icons\default.png
- %PROGRAM_FILES%\mychers\icons\iChat.png
- %PROGRAM_FILES%\mychers\icons\iCal.png
- %PROGRAM_FILES%\mychers\docklets\RecycleBin\icons\trash_full.ico
- %PROGRAM_FILES%\mychers\docklets\RecycleBin\icons\trash_empty.ico
- %PROGRAM_FILES%\mychers\icons\Dashboard.png
- %PROGRAM_FILES%\mychers\icons\Address Book.png
- %PROGRAM_FILES%\mychers\icons\QuickTime.png
- %PROGRAM_FILES%\mychers\icons\Mail.png
- %PROGRAM_FILES%\mychers\icons\Safari.png
- %PROGRAM_FILES%\mychers\icons\RKLauncher.png
- %PROGRAM_FILES%\mychers\icons\iPhoto.png
- %PROGRAM_FILES%\mychers\icons\iMovie.png
- %PROGRAM_FILES%\mychers\icons\LinkURL.png
- %PROGRAM_FILES%\mychers\icons\iTunes.png
- %PROGRAM_FILES%\mychers\RKLauncher.conf
- %PROGRAM_FILES%\mychers\RKLauncher.dll
- %PROGRAM_FILES%\mychers\icons.conf
- %PROGRAM_FILES%\mychers\RKDocklet.dll
- %TEMP%\_ir_sf7_temp_0\irsetup.dat
- %TEMP%\_ir_sf7_temp_0\irsetup.exe
- %PROGRAM_FILES%\mychers\YzDocklet.dll
- %TEMP%\_ir_sf7_temp_0\IRIMG1.JPG
- %PROGRAM_FILES%\mychers\docklets\RecycleBin\RecycleBin.ini
- %PROGRAM_FILES%\mychers\docklets\RecycleBin\RecycleBin.dll
- %PROGRAM_FILES%\mychers\docklets\RecycleBin\icons\SLATE_READ_ME.txt
- %PROGRAM_FILES%\mychers\docklets\RecycleBin\RecycleBin_readme.txt
- %PROGRAM_FILES%\mychers\dockletstemp.ini
- %PROGRAM_FILES%\mychers\excluded.conf
- %PROGRAM_FILES%\mychers\itemlist.conf
- %PROGRAM_FILES%\mychers\RKLauncher.exe
- %PROGRAM_FILES%\mychers\icons\SystemPrefs.png
- %WINDIR%\onlyyou\zhuyao.reg
- %WINDIR%\onlyyou\gongju.reg
- %WINDIR%\onlyyou\5e643138f47194aa.bat
- %WINDIR%\onlyyou\3FB824C44CC7ED623B609D702462D6C8.vbs
- %PROGRAM_FILES%\mychers\themes\Default\poof.png
- %PROGRAM_FILES%\mychers\themes\Default\mark.png
- %PROGRAM_FILES%\mychers\themes\Default\theme.conf
- %PROGRAM_FILES%\mychers\themes\Default\sep.png
- %WINDIR%\onlyyou\navinfo.db
- %WINDIR%\onlyyou\360sefav.db
- %WINDIR%\onlyyou\del.bat
- %WINDIR%\onlyyou\TtConf.dat
- %WINDIR%\onlyyou\4acfa28ff1b446ee645bdba8bb7081c5.vbs
- %WINDIR%\onlyyou\4CC7ED623B609D70.bat
- %WINDIR%\onlyyou\zhu.reg
- %WINDIR%\onlyyou\A60f3C.vbs
- %PROGRAM_FILES%\mychers\icons\main.ico
- %PROGRAM_FILES%\mychers\icons\shopcartadd.png
- %PROGRAM_FILES%\mychers\icons\chonglang.ico
- %PROGRAM_FILES%\mychers\icons\dang.ico
- %PROGRAM_FILES%\mychers\icons\TrashFull.png
- %PROGRAM_FILES%\mychers\icons\TrashEmpty.png
- %PROGRAM_FILES%\mychers\icons\shopcart.png
- %PROGRAM_FILES%\mychers\icons\chonglang Shortcut.png
- %PROGRAM_FILES%\mychers\lang\rkl_SimplifiedChinese.lang
- %PROGRAM_FILES%\mychers\icons\icon_tao.png
- %PROGRAM_FILES%\mychers\themes\Default\bg.png
- %PROGRAM_FILES%\mychers\plugins\RKScaleEffect\RKScaleEffect.dll
- %PROGRAM_FILES%\mychers\icons\xihuan.ico
- %PROGRAM_FILES%\mychers\icons\joyo.ico
- %PROGRAM_FILES%\mychers\icons\buy.png
- %PROGRAM_FILES%\mychers\icons\xtzj.ico
- %PROGRAM_FILES%\iloveu\theworld.ac
- %PROGRAM_FILES%\ilovetb\theworld.ac
- %WINDIR%\onlyyou\icons\Thumbs.db
- %TEMP%\_ir_sf7_temp_0\irsetup.dat
- ClassName: 'Shell_TrayWnd' WindowName: ''