Technical Information
- <SYSTEM32>\tasks\system sll
- [<HKLM>\System\CurrentControlSet\Services\sllPdSrv] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\sllPdSrv] 'ImagePath' = '%CommonProgramFiles(x86)%\System Sll\sllsrv.exe'
- [<HKLM>\System\CurrentControlSet\Services\avflt] 'ImagePath' = '%CommonProgramFiles(x86)%\System Sll\IMHKSDK\avflt64.sys'
- 'sllPdSrv' %CommonProgramFiles(x86)%\System Sll\sllsrv.exe
- 'avflt' %CommonProgramFiles(x86)%\System Sll\IMHKSDK\avflt64.sys
- [<HKLM>\System\CurrentControlSet\Services\avflt] 'Group' = 'FSFilter Activity Monitor'
- C:\_108754.exe
- %CommonProgramFiles(x86)%\system sll\netrcd\is-vjjsp.tmp
- %CommonProgramFiles(x86)%\system sll\netrcd\is-9orbh.tmp
- %CommonProgramFiles(x86)%\system sll\netrcd\is-s1scj.tmp
- %CommonProgramFiles(x86)%\system sll\netrcd\is-rok67.tmp
- %CommonProgramFiles(x86)%\system sll\netrcd\is-qmgbj.tmp
- %CommonProgramFiles(x86)%\system sll\netrcd\is-llv0l.tmp
- %CommonProgramFiles(x86)%\system sll\x64\is-u7pd6.tmp
- %CommonProgramFiles(x86)%\system sll\x64\is-piqs4.tmp
- %CommonProgramFiles(x86)%\system sll\x86\is-6rto4.tmp
- %CommonProgramFiles(x86)%\system sll\x86\is-0rtq9.tmp
- %CommonProgramFiles(x86)%\system sll\is-4mukb.tmp
- %CommonProgramFiles(x86)%\system sll\imhksdk\is-4sd2u.tmp
- %CommonProgramFiles(x86)%\system sll\imhksdk\is-13h93.tmp
- %CommonProgramFiles(x86)%\system sll\imhksdk\is-47pq6.tmp
- %CommonProgramFiles(x86)%\system sll\imhksdk\is-bqear.tmp
- %CommonProgramFiles(x86)%\system sll\ctlexe\drivers\win7_x86\is-f7cpf.tmp
- %CommonProgramFiles(x86)%\system sll\imhksdk\is-2de6c.tmp
- %CommonProgramFiles(x86)%\system sll\ctlexe\drivers\win7_ia64\is-uj9tr.tmp
- %CommonProgramFiles(x86)%\system sll\ctlexe\is-sugot.tmp
- %CommonProgramFiles(x86)%\system sll\domainjump\is-qm90e.tmp
- %CommonProgramFiles(x86)%\system sll\domainjump\drivers\is-llai4.tmp
- %CommonProgramFiles(x86)%\system sll\domainjump\drivers\is-bociq.tmp
- %CommonProgramFiles(x86)%\system sll\domainjump\drivers\is-cv1vg.tmp
- %CommonProgramFiles(x86)%\system sll\domainjump\drivers\is-p6dd7.tmp
- %CommonProgramFiles(x86)%\system sll\drivers\win7_amd64\is-7vgp2.tmp
- %CommonProgramFiles(x86)%\system sll\drivers\win7_x86\is-fhsoh.tmp
- %CommonProgramFiles(x86)%\system sll\fmtm\is-d28b1.tmp
- %CommonProgramFiles(x86)%\system sll\fmtm\is-fnohp.tmp
- %CommonProgramFiles(x86)%\system sll\fmtm\is-d816r.tmp
- %CommonProgramFiles(x86)%\system sll\fmtm\is-gcagb.tmp
- %CommonProgramFiles(x86)%\system sll\fmtm\x64\is-g8n17.tmp
- %CommonProgramFiles(x86)%\system sll\fmtm\x64\is-k2jrr.tmp
- %CommonProgramFiles(x86)%\system sll\fmtm\x86\is-5e306.tmp
- %CommonProgramFiles(x86)%\system sll\fmtm\x86\is-60hi3.tmp
- %CommonProgramFiles(x86)%\system sll\ctlexe\drivers\win7_amd64\is-bi4t6.tmp
- %CommonProgramFiles(x86)%\system sll\imhksdk\is-c9jp9.tmp
- %CommonProgramFiles(x86)%\system sll\imhksdk\is-tpn63.tmp
- %CommonProgramFiles(x86)%\system sll\imhksdk\is-fgldd.tmp
- %CommonProgramFiles(x86)%\system sll\id.rdb
- %CommonProgramFiles(x86)%\system sll\logs\log.txt
- %CommonProgramFiles(x86)%\system sll\cfg.txt
- %WINDIR%\temp\udd83cf.tmp
- %WINDIR%\temp\cab90aa.tmp
- %WINDIR%\temp\tar90ab.tmp
- %WINDIR%\temp\cabf787.tmp
- %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %CommonProgramFiles(x86)%\system sll\fcode.rdb
- %CommonProgramFiles(x86)%\system sll\uptime.rdb
- %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\metadata\8890a77645b73478f5b1ded18acbf795_b95a585585762f8b2d72e152f328449a
- %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\content\8890a77645b73478f5b1ded18acbf795_b95a585585762f8b2d72e152f328449a
- %CommonProgramFiles(x86)%\system sll\update\abc.html
- %CommonProgramFiles(x86)%\system sll\logs\update.log
- %CommonProgramFiles(x86)%\system sll\is-q7mll.tmp
- %CommonProgramFiles(x86)%\system sll\unins000.dat
- %CommonProgramFiles(x86)%\system sll\wx\is-j29n5.tmp
- %CommonProgramFiles(x86)%\system sll\wx\is-207ug.tmp
- %CommonProgramFiles(x86)%\system sll\mail\sys\is-9svod.tmp
- %CommonProgramFiles(x86)%\system sll\is-jlnnd.tmp
- %CommonProgramFiles(x86)%\system sll\is-iua7p.tmp
- %CommonProgramFiles(x86)%\system sll\is-4qhcp.tmp
- %CommonProgramFiles(x86)%\system sll\mail\is-rpi65.tmp
- %CommonProgramFiles(x86)%\system sll\mail\sys\is-3mf68.tmp
- %CommonProgramFiles(x86)%\system sll\mail\sys\is-2p5cv.tmp
- %CommonProgramFiles(x86)%\system sll\keyboard\is-qp6ru.tmp
- %CommonProgramFiles(x86)%\system sll\mail\sys\is-mkte1.tmp
- %CommonProgramFiles(x86)%\system sll\mail\sys\is-3fmdp.tmp
- %CommonProgramFiles(x86)%\system sll\mail\sys\is-s077e.tmp
- %CommonProgramFiles(x86)%\system sll\mail\sys\is-17l92.tmp
- %CommonProgramFiles(x86)%\system sll\mail\sys\is-6b49h.tmp
- %CommonProgramFiles(x86)%\system sll\mail\sys\is-rk351.tmp
- %CommonProgramFiles(x86)%\system sll\mail\sys\is-ho8ct.tmp
- %CommonProgramFiles(x86)%\system sll\mail\sys\is-881be.tmp
- %CommonProgramFiles(x86)%\system sll\is-jimm6.tmp
- %CommonProgramFiles(x86)%\system sll\mail\sys\is-mq1si.tmp
- %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %CommonProgramFiles(x86)%\system sll\keyboard\is-m0vbg.tmp
- %CommonProgramFiles(x86)%\system sll\is-h2d2p.tmp
- %CommonProgramFiles(x86)%\system sll\is-dtqfd.tmp
- %CommonProgramFiles(x86)%\system sll\is-ii7o5.tmp
- %CommonProgramFiles(x86)%\system sll\is-103p7.tmp
- %CommonProgramFiles(x86)%\system sll\is-09o8p.tmp
- %CommonProgramFiles(x86)%\system sll\is-71g9t.tmp
- %CommonProgramFiles(x86)%\system sll\is-kp8fo.tmp
- %CommonProgramFiles(x86)%\system sll\is-pt9e6.tmp
- %CommonProgramFiles(x86)%\system sll\is-isuck.tmp
- %CommonProgramFiles(x86)%\system sll\is-73040.tmp
- %CommonProgramFiles(x86)%\system sll\is-cfdl7.tmp
- %CommonProgramFiles(x86)%\system sll\is-eohoj.tmp
- %CommonProgramFiles(x86)%\system sll\is-0igbm.tmp
- %CommonProgramFiles(x86)%\system sll\is-9s3me.tmp
- %CommonProgramFiles(x86)%\system sll\is-36g4b.tmp
- %CommonProgramFiles(x86)%\system sll\is-vuh37.tmp
- %CommonProgramFiles(x86)%\system sll\is-3faeg.tmp
- %CommonProgramFiles(x86)%\system sll\is-mcbrq.tmp
- %CommonProgramFiles(x86)%\system sll\is-rl82v.tmp
- %CommonProgramFiles(x86)%\system sll\is-c5hfn.tmp
- %TEMP%\is-iu932.tmp\_108754.tmp
- %TEMP%\is-shve3.tmp\_isetup\_setup64.tmp
- %TEMP%\is-shve3.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-shve3.tmp\hzzinstaller.exe
- %CommonProgramFiles(x86)%\system sll\is-qmb5m.tmp
- %CommonProgramFiles(x86)%\system sll\is-35a0t.tmp
- %CommonProgramFiles(x86)%\system sll\is-3r136.tmp
- %CommonProgramFiles(x86)%\system sll\is-i0chq.tmp
- %CommonProgramFiles(x86)%\system sll\is-u26b7.tmp
- %CommonProgramFiles(x86)%\system sll\is-96hri.tmp
- %CommonProgramFiles(x86)%\system sll\is-qu83e.tmp
- %CommonProgramFiles(x86)%\system sll\is-cseq3.tmp
- %CommonProgramFiles(x86)%\system sll\is-vhdnl.tmp
- %CommonProgramFiles(x86)%\system sll\is-7438l.tmp
- %CommonProgramFiles(x86)%\system sll\is-cntfv.tmp
- %CommonProgramFiles(x86)%\system sll\is-q1hmn.tmp
- %CommonProgramFiles(x86)%\system sll\is-047du.tmp
- %CommonProgramFiles(x86)%\system sll\is-ho5ss.tmp
- %CommonProgramFiles(x86)%\system sll\is-r7dcp.tmp
- %CommonProgramFiles(x86)%\system sll\is-s6av5.tmp
- %CommonProgramFiles(x86)%\system sll\is-3eq28.tmp
- %CommonProgramFiles(x86)%\system sll\is-kc6ju.tmp
- %CommonProgramFiles(x86)%\system sll\is-f8inl.tmp
- %CommonProgramFiles(x86)%\system sll\is-1oq2d.tmp
- %CommonProgramFiles(x86)%\system sll\is-1lshg.tmp
- %CommonProgramFiles(x86)%\system sll\is-ieg1l.tmp
- %CommonProgramFiles(x86)%\system sll\is-t45r5.tmp
- %CommonProgramFiles(x86)%\system sll\is-eakt2.tmp
- %CommonProgramFiles(x86)%\system sll\is-s5m5m.tmp
- %CommonProgramFiles(x86)%\system sll\is-uj7b5.tmp
- %CommonProgramFiles(x86)%\system sll\is-5or9n.tmp
- %CommonProgramFiles(x86)%\system sll\is-69tir.tmp
- %CommonProgramFiles(x86)%\system sll\is-b09hj.tmp
- %CommonProgramFiles(x86)%\system sll\is-0hqrn.tmp
- %CommonProgramFiles(x86)%\system sll\is-8qa7j.tmp
- %CommonProgramFiles(x86)%\system sll\is-533p7.tmp
- %CommonProgramFiles(x86)%\system sll\is-l8gji.tmp
- %CommonProgramFiles(x86)%\system sll\is-isq5s.tmp
- %CommonProgramFiles(x86)%\system sll\is-0rgb9.tmp
- %CommonProgramFiles(x86)%\system sll\is-su02h.tmp
- %CommonProgramFiles(x86)%\system sll\is-9ek82.tmp
- %CommonProgramFiles(x86)%\system sll\is-jfsq2.tmp
- %CommonProgramFiles(x86)%\system sll\is-sr236.tmp
- %CommonProgramFiles(x86)%\system sll\is-t28t2.tmp
- %CommonProgramFiles(x86)%\system sll\keyboard\is-cbe18.tmp
- %CommonProgramFiles(x86)%\system sll\is-ncu7m.tmp
- %CommonProgramFiles(x86)%\system sll\is-i7grq.tmp
- %CommonProgramFiles(x86)%\system sll\is-qv22n.tmp
- %CommonProgramFiles(x86)%\system sll\is-m4t5b.tmp
- %CommonProgramFiles(x86)%\system sll\is-2obpn.tmp
- %CommonProgramFiles(x86)%\system sll\is-ro13r.tmp
- %CommonProgramFiles(x86)%\system sll\is-eqgbk.tmp
- %CommonProgramFiles(x86)%\system sll\is-aorsp.tmp
- %CommonProgramFiles(x86)%\system sll\is-9q6ml.tmp
- %CommonProgramFiles(x86)%\system sll\is-nq1o8.tmp
- %WINDIR%\temp\tarf788.tmp
- %CommonProgramFiles(x86)%\system sll\unins000.dat
- %CommonProgramFiles(x86)%\system sll\unins000.exe
- %TEMP%\is-iu932.tmp\_108754.tmp
- %WINDIR%\temp\udd83cf.tmp
- %WINDIR%\temp\cab90aa.tmp
- %WINDIR%\temp\tar90ab.tmp
- %CommonProgramFiles(x86)%\system sll\abc.html
- %CommonProgramFiles(x86)%\system sll\update\abc.html
- %WINDIR%\temp\cabf787.tmp
- %WINDIR%\temp\tarf788.tmp
- from %CommonProgramFiles(x86)%\system sll\is-qmb5m.tmp to %CommonProgramFiles(x86)%\system sll\unins000.exe
- from %CommonProgramFiles(x86)%\system sll\netrcd\is-rok67.tmp to %CommonProgramFiles(x86)%\system sll\netrcd\libesedb.dll
- from %CommonProgramFiles(x86)%\system sll\netrcd\is-s1scj.tmp to %CommonProgramFiles(x86)%\system sll\netrcd\histrcd.exe
- from %CommonProgramFiles(x86)%\system sll\netrcd\is-9orbh.tmp to %CommonProgramFiles(x86)%\system sll\netrcd\getesedbinfo.exe
- from %CommonProgramFiles(x86)%\system sll\netrcd\is-vjjsp.tmp to %CommonProgramFiles(x86)%\system sll\netrcd\getdbcache_x64.exe
- from %CommonProgramFiles(x86)%\system sll\ctlexe\drivers\win7_x86\is-f7cpf.tmp to %CommonProgramFiles(x86)%\system sll\ctlexe\drivers\win7_x86\tmctldrv.sys
- from %CommonProgramFiles(x86)%\system sll\ctlexe\drivers\win7_ia64\is-uj9tr.tmp to %CommonProgramFiles(x86)%\system sll\ctlexe\drivers\win7_ia64\tmctldrv.sys
- from %CommonProgramFiles(x86)%\system sll\ctlexe\drivers\win7_amd64\is-bi4t6.tmp to %CommonProgramFiles(x86)%\system sll\ctlexe\drivers\win7_amd64\tmctldrv.sys
- from %CommonProgramFiles(x86)%\system sll\ctlexe\is-sugot.tmp to %CommonProgramFiles(x86)%\system sll\ctlexe\tmctlcom.dll
- from %CommonProgramFiles(x86)%\system sll\fmtm\x86\is-60hi3.tmp to %CommonProgramFiles(x86)%\system sll\fmtm\x86\fmtmodule.dll
- from %CommonProgramFiles(x86)%\system sll\fmtm\x86\is-5e306.tmp to %CommonProgramFiles(x86)%\system sll\fmtm\x86\fmtm.exe
- from %CommonProgramFiles(x86)%\system sll\fmtm\x64\is-k2jrr.tmp to %CommonProgramFiles(x86)%\system sll\fmtm\x64\fmtmodule.dll
- from %CommonProgramFiles(x86)%\system sll\fmtm\x64\is-g8n17.tmp to %CommonProgramFiles(x86)%\system sll\fmtm\x64\fmtm.exe
- from %CommonProgramFiles(x86)%\system sll\fmtm\is-gcagb.tmp to %CommonProgramFiles(x86)%\system sll\fmtm\stop.bat
- from %CommonProgramFiles(x86)%\system sll\fmtm\is-d816r.tmp to %CommonProgramFiles(x86)%\system sll\fmtm\start.exe
- from %CommonProgramFiles(x86)%\system sll\fmtm\is-fnohp.tmp to %CommonProgramFiles(x86)%\system sll\fmtm\pipmd.dll
- from %CommonProgramFiles(x86)%\system sll\fmtm\is-d28b1.tmp to %CommonProgramFiles(x86)%\system sll\fmtm\ctldll.dll
- from %CommonProgramFiles(x86)%\system sll\drivers\win7_x86\is-fhsoh.tmp to %CommonProgramFiles(x86)%\system sll\drivers\win7_x86\ptprc.sys
- from %CommonProgramFiles(x86)%\system sll\drivers\win7_amd64\is-7vgp2.tmp to %CommonProgramFiles(x86)%\system sll\drivers\win7_amd64\ptprc.sys
- from %CommonProgramFiles(x86)%\system sll\domainjump\drivers\is-p6dd7.tmp to %CommonProgramFiles(x86)%\system sll\domainjump\drivers\sys864.sys
- from %CommonProgramFiles(x86)%\system sll\domainjump\drivers\is-cv1vg.tmp to %CommonProgramFiles(x86)%\system sll\domainjump\drivers\sys8.sys
- from %CommonProgramFiles(x86)%\system sll\domainjump\drivers\is-bociq.tmp to %CommonProgramFiles(x86)%\system sll\domainjump\drivers\sys764.sys
- from %CommonProgramFiles(x86)%\system sll\domainjump\drivers\is-llai4.tmp to %CommonProgramFiles(x86)%\system sll\domainjump\drivers\sys7.sys
- from %CommonProgramFiles(x86)%\system sll\domainjump\is-qm90e.tmp to %CommonProgramFiles(x86)%\system sll\domainjump\domainjumpdll.dll
- from %CommonProgramFiles(x86)%\system sll\keyboard\is-qp6ru.tmp to %CommonProgramFiles(x86)%\system sll\keyboard\sysoft40.exe
- from %CommonProgramFiles(x86)%\system sll\keyboard\is-m0vbg.tmp to %CommonProgramFiles(x86)%\system sll\keyboard\sysoft.exe
- from %CommonProgramFiles(x86)%\system sll\keyboard\is-cbe18.tmp to %CommonProgramFiles(x86)%\system sll\keyboard\msconfig.ini
- from %CommonProgramFiles(x86)%\system sll\is-ieg1l.tmp to %CommonProgramFiles(x86)%\system sll\shomectl.dll
- from %CommonProgramFiles(x86)%\system sll\is-b09hj.tmp to %CommonProgramFiles(x86)%\system sll\shomefilectl.dll
- from %CommonProgramFiles(x86)%\system sll\is-69tir.tmp to %CommonProgramFiles(x86)%\system sll\stopfp.exe
- from %CommonProgramFiles(x86)%\system sll\netrcd\is-qmgbj.tmp to %CommonProgramFiles(x86)%\system sll\netrcd\msvcr100.dll
- from %CommonProgramFiles(x86)%\system sll\x64\is-u7pd6.tmp to %CommonProgramFiles(x86)%\system sll\x64\glbdll.dll
- from %CommonProgramFiles(x86)%\system sll\wx\is-j29n5.tmp to %CommonProgramFiles(x86)%\system sll\wx\wxmsdk.dll
- from %CommonProgramFiles(x86)%\system sll\x64\is-piqs4.tmp to %CommonProgramFiles(x86)%\system sll\x64\nvsc.exe
- from %CommonProgramFiles(x86)%\system sll\wx\is-207ug.tmp to %CommonProgramFiles(x86)%\system sll\wx\wxmonitor.dll
- from %CommonProgramFiles(x86)%\system sll\mail\sys\is-9svod.tmp to %CommonProgramFiles(x86)%\system sll\mail\sys\mailmon_wfp_win81.sys
- from %CommonProgramFiles(x86)%\system sll\mail\sys\is-881be.tmp to %CommonProgramFiles(x86)%\system sll\mail\sys\mailmon_wfp_win8.sys
- from %CommonProgramFiles(x86)%\system sll\mail\sys\is-ho8ct.tmp to %CommonProgramFiles(x86)%\system sll\mail\sys\mailmon_wfp_win7.sys
- from %CommonProgramFiles(x86)%\system sll\mail\sys\is-rk351.tmp to %CommonProgramFiles(x86)%\system sll\mail\sys\mailmon_wfp_win10.sys
- from %CommonProgramFiles(x86)%\system sll\mail\sys\is-6b49h.tmp to %CommonProgramFiles(x86)%\system sll\mail\sys\mailmon_wfp_win10.inf
- from %CommonProgramFiles(x86)%\system sll\mail\sys\is-17l92.tmp to %CommonProgramFiles(x86)%\system sll\mail\sys\mailmon_wfp_win10.cat
- from %CommonProgramFiles(x86)%\system sll\mail\sys\is-s077e.tmp to %CommonProgramFiles(x86)%\system sll\mail\sys\mailmon64_wfp_win81.sys
- from %CommonProgramFiles(x86)%\system sll\mail\sys\is-mq1si.tmp to %CommonProgramFiles(x86)%\system sll\mail\sys\mailmon64_wfp_win8.sys
- from %CommonProgramFiles(x86)%\system sll\mail\sys\is-mkte1.tmp to %CommonProgramFiles(x86)%\system sll\mail\sys\mailmon64_wfp_win7.sys
- from %CommonProgramFiles(x86)%\system sll\mail\sys\is-3fmdp.tmp to %CommonProgramFiles(x86)%\system sll\mail\sys\mailmon64_wfp_win10.sys
- from %CommonProgramFiles(x86)%\system sll\mail\sys\is-2p5cv.tmp to %CommonProgramFiles(x86)%\system sll\mail\sys\mailmon64_wfp_win10.inf
- from %CommonProgramFiles(x86)%\system sll\mail\sys\is-3mf68.tmp to %CommonProgramFiles(x86)%\system sll\mail\sys\mailmon64_wfp_win10.cat
- from %CommonProgramFiles(x86)%\system sll\mail\is-rpi65.tmp to %CommonProgramFiles(x86)%\system sll\mail\mailmonitor.dll
- from %CommonProgramFiles(x86)%\system sll\is-4qhcp.tmp to %CommonProgramFiles(x86)%\system sll\hgzprotectservice.dll
- from %CommonProgramFiles(x86)%\system sll\is-iua7p.tmp to %CommonProgramFiles(x86)%\system sll\hgzdriver.sys
- from %CommonProgramFiles(x86)%\system sll\is-jlnnd.tmp to %CommonProgramFiles(x86)%\system sll\hgzdriver64.sys
- from %CommonProgramFiles(x86)%\system sll\is-jimm6.tmp to %CommonProgramFiles(x86)%\system sll\installsvr.dll
- from %CommonProgramFiles(x86)%\system sll\imhksdk\is-fgldd.tmp to %CommonProgramFiles(x86)%\system sll\imhksdk\imhksdk64.dll
- from %CommonProgramFiles(x86)%\system sll\imhksdk\is-tpn63.tmp to %CommonProgramFiles(x86)%\system sll\imhksdk\imhksdk32.dll
- from %CommonProgramFiles(x86)%\system sll\imhksdk\is-c9jp9.tmp to %CommonProgramFiles(x86)%\system sll\imhksdk\imhkcore64.dll
- from %CommonProgramFiles(x86)%\system sll\imhksdk\is-2de6c.tmp to %CommonProgramFiles(x86)%\system sll\imhksdk\imhkcore32.dll
- from %CommonProgramFiles(x86)%\system sll\imhksdk\is-bqear.tmp to %CommonProgramFiles(x86)%\system sll\imhksdk\avfltsdk64.dll
- from %CommonProgramFiles(x86)%\system sll\imhksdk\is-47pq6.tmp to %CommonProgramFiles(x86)%\system sll\imhksdk\avfltsdk32.dll
- from %CommonProgramFiles(x86)%\system sll\imhksdk\is-13h93.tmp to %CommonProgramFiles(x86)%\system sll\imhksdk\avflt64.sys
- from %CommonProgramFiles(x86)%\system sll\imhksdk\is-4sd2u.tmp to %CommonProgramFiles(x86)%\system sll\imhksdk\avflt32.sys
- from %CommonProgramFiles(x86)%\system sll\is-4mukb.tmp to %CommonProgramFiles(x86)%\system sll\imhksdk.net.dll
- from %CommonProgramFiles(x86)%\system sll\x86\is-0rtq9.tmp to %CommonProgramFiles(x86)%\system sll\x86\nvsc.exe
- from %CommonProgramFiles(x86)%\system sll\x86\is-6rto4.tmp to %CommonProgramFiles(x86)%\system sll\x86\glbdll.dll
- from %CommonProgramFiles(x86)%\system sll\is-5or9n.tmp to %CommonProgramFiles(x86)%\system sll\pscfg.dat
- from %CommonProgramFiles(x86)%\system sll\netrcd\is-llv0l.tmp to %CommonProgramFiles(x86)%\system sll\netrcd\sqlite3.dll
- from %CommonProgramFiles(x86)%\system sll\is-uj7b5.tmp to %CommonProgramFiles(x86)%\system sll\client.core.dll
- from %CommonProgramFiles(x86)%\system sll\is-047du.tmp to %CommonProgramFiles(x86)%\system sll\esframework.dll
- from %CommonProgramFiles(x86)%\system sll\is-vuh37.tmp to %CommonProgramFiles(x86)%\system sll\omcs.dll
- from %CommonProgramFiles(x86)%\system sll\is-36g4b.tmp to %CommonProgramFiles(x86)%\system sll\omcs.boost.xml
- from %CommonProgramFiles(x86)%\system sll\is-9s3me.tmp to %CommonProgramFiles(x86)%\system sll\omcs.boost.dll
- from %CommonProgramFiles(x86)%\system sll\is-0igbm.tmp to %CommonProgramFiles(x86)%\system sll\esbasic.xml
- from %CommonProgramFiles(x86)%\system sll\is-eohoj.tmp to %CommonProgramFiles(x86)%\system sll\esbasic.dll
- from %CommonProgramFiles(x86)%\system sll\is-cfdl7.tmp to %CommonProgramFiles(x86)%\system sll\videoenginecore.dll
- from %CommonProgramFiles(x86)%\system sll\is-73040.tmp to %CommonProgramFiles(x86)%\system sll\h264codec.dll
- from %CommonProgramFiles(x86)%\system sll\is-isuck.tmp to %CommonProgramFiles(x86)%\system sll\dxbase.dll
- from %CommonProgramFiles(x86)%\system sll\is-pt9e6.tmp to %CommonProgramFiles(x86)%\system sll\avutil.dll
- from %CommonProgramFiles(x86)%\system sll\is-kp8fo.tmp to %CommonProgramFiles(x86)%\system sll\avformat.dll
- from %CommonProgramFiles(x86)%\system sll\is-71g9t.tmp to %CommonProgramFiles(x86)%\system sll\avcodec.dll
- from %CommonProgramFiles(x86)%\system sll\is-09o8p.tmp to %CommonProgramFiles(x86)%\system sll\audioenginecore.dll
- from %CommonProgramFiles(x86)%\system sll\is-103p7.tmp to %CommonProgramFiles(x86)%\system sll\aopsdk.dll
- from %CommonProgramFiles(x86)%\system sll\is-ii7o5.tmp to %CommonProgramFiles(x86)%\system sll\cskin.dll
- from %CommonProgramFiles(x86)%\system sll\is-dtqfd.tmp to %CommonProgramFiles(x86)%\system sll\abc.html
- from %CommonProgramFiles(x86)%\system sll\is-3faeg.tmp to %CommonProgramFiles(x86)%\system sll\uninstall.win10.exe
- from %CommonProgramFiles(x86)%\system sll\is-rl82v.tmp to %CommonProgramFiles(x86)%\system sll\sll.exe.config
- from %CommonProgramFiles(x86)%\system sll\is-q1hmn.tmp to %CommonProgramFiles(x86)%\system sll\remote.im.dll.config
- from %CommonProgramFiles(x86)%\system sll\is-c5hfn.tmp to %CommonProgramFiles(x86)%\system sll\remote.im.win10.dll
- from %CommonProgramFiles(x86)%\system sll\is-cntfv.tmp to %CommonProgramFiles(x86)%\system sll\remote.im.dll
- from %CommonProgramFiles(x86)%\system sll\is-7438l.tmp to %CommonProgramFiles(x86)%\system sll\sll.win10.exe
- from %CommonProgramFiles(x86)%\system sll\is-vhdnl.tmp to %CommonProgramFiles(x86)%\system sll\sll.exe
- from %CommonProgramFiles(x86)%\system sll\is-cseq3.tmp to %CommonProgramFiles(x86)%\system sll\justlib.xml
- from %CommonProgramFiles(x86)%\system sll\is-qu83e.tmp to %CommonProgramFiles(x86)%\system sll\justlib.win10.dll
- from %CommonProgramFiles(x86)%\system sll\is-96hri.tmp to %CommonProgramFiles(x86)%\system sll\justlib.dll
- from %CommonProgramFiles(x86)%\system sll\is-u26b7.tmp to %CommonProgramFiles(x86)%\system sll\remote.model.win10.dll
- from %CommonProgramFiles(x86)%\system sll\is-i0chq.tmp to %CommonProgramFiles(x86)%\system sll\remote.model.dll
- from %CommonProgramFiles(x86)%\system sll\is-3r136.tmp to %CommonProgramFiles(x86)%\system sll\remote.core.win10.dll
- from %CommonProgramFiles(x86)%\system sll\is-35a0t.tmp to %CommonProgramFiles(x86)%\system sll\remote.core.dll
- from %CommonProgramFiles(x86)%\system sll\is-mcbrq.tmp to %CommonProgramFiles(x86)%\system sll\omcs.xml
- from %CommonProgramFiles(x86)%\system sll\is-ho5ss.tmp to %CommonProgramFiles(x86)%\system sll\esframework.xml
- from %CommonProgramFiles(x86)%\system sll\is-eakt2.tmp to %CommonProgramFiles(x86)%\system sll\start.exe
- from %CommonProgramFiles(x86)%\system sll\is-r7dcp.tmp to %CommonProgramFiles(x86)%\system sll\hzzinstaller.exe
- from %CommonProgramFiles(x86)%\system sll\is-h2d2p.tmp to %CommonProgramFiles(x86)%\system sll\ptprocctl.dll
- from %CommonProgramFiles(x86)%\system sll\is-t45r5.tmp to %CommonProgramFiles(x86)%\system sll\init.txt
- from %CommonProgramFiles(x86)%\system sll\is-1lshg.tmp to %CommonProgramFiles(x86)%\system sll\sysim.db
- from %CommonProgramFiles(x86)%\system sll\is-1oq2d.tmp to %CommonProgramFiles(x86)%\system sll\syscfg.db
- from %CommonProgramFiles(x86)%\system sll\is-f8inl.tmp to %CommonProgramFiles(x86)%\system sll\eula.rtf
- from %CommonProgramFiles(x86)%\system sll\is-kc6ju.tmp to %CommonProgramFiles(x86)%\system sll\favicon.ico
- from %CommonProgramFiles(x86)%\system sll\is-3eq28.tmp to %CommonProgramFiles(x86)%\system sll\system.data.sqlite.dll
- from %CommonProgramFiles(x86)%\system sll\is-s6av5.tmp to %CommonProgramFiles(x86)%\system sll\paintframework.dll
- from %CommonProgramFiles(x86)%\system sll\is-8qa7j.tmp to %CommonProgramFiles(x86)%\system sll\networkmonitor.dll
- from %CommonProgramFiles(x86)%\system sll\is-0hqrn.tmp to %CommonProgramFiles(x86)%\system sll\newtonsoft.json.dll
- from %CommonProgramFiles(x86)%\system sll\is-533p7.tmp to %CommonProgramFiles(x86)%\system sll\history.db
- from %CommonProgramFiles(x86)%\system sll\is-l8gji.tmp to %CommonProgramFiles(x86)%\system sll\fdmodlue.dll
- from %CommonProgramFiles(x86)%\system sll\is-isq5s.tmp to %CommonProgramFiles(x86)%\system sll\getsigninfo.dll
- from %CommonProgramFiles(x86)%\system sll\is-aorsp.tmp to %CommonProgramFiles(x86)%\system sll\msvcr90.dll
- from %CommonProgramFiles(x86)%\system sll\is-eqgbk.tmp to %CommonProgramFiles(x86)%\system sll\msvcr100.dll
- from %CommonProgramFiles(x86)%\system sll\is-ro13r.tmp to %CommonProgramFiles(x86)%\system sll\msvcp90.dll
- from %CommonProgramFiles(x86)%\system sll\is-2obpn.tmp to %CommonProgramFiles(x86)%\system sll\msvcp100.dll
- from %CommonProgramFiles(x86)%\system sll\is-m4t5b.tmp to %CommonProgramFiles(x86)%\system sll\msvcm90.dll
- from %CommonProgramFiles(x86)%\system sll\is-qv22n.tmp to %CommonProgramFiles(x86)%\system sll\mskbitex.exe
- from %CommonProgramFiles(x86)%\system sll\is-nq1o8.tmp to %CommonProgramFiles(x86)%\system sll\mskbit.dll
- from %CommonProgramFiles(x86)%\system sll\is-ncu7m.tmp to %CommonProgramFiles(x86)%\system sll\comupdate.exe
- from %CommonProgramFiles(x86)%\system sll\is-i7grq.tmp to %CommonProgramFiles(x86)%\system sll\uninstall.exe.config
- from %CommonProgramFiles(x86)%\system sll\is-t28t2.tmp to %CommonProgramFiles(x86)%\system sll\uninstall.exe
- from %CommonProgramFiles(x86)%\system sll\is-sr236.tmp to %CommonProgramFiles(x86)%\system sll\ygport.exe
- from %CommonProgramFiles(x86)%\system sll\is-jfsq2.tmp to %CommonProgramFiles(x86)%\system sll\checkfirewall.exe
- from %CommonProgramFiles(x86)%\system sll\is-9ek82.tmp to %CommonProgramFiles(x86)%\system sll\sllsrv.exe
- from %CommonProgramFiles(x86)%\system sll\is-su02h.tmp to %CommonProgramFiles(x86)%\system sll\tasksetter.exe
- from %CommonProgramFiles(x86)%\system sll\is-0rgb9.tmp to %CommonProgramFiles(x86)%\system sll\hzzsrvinit.exe
- from %CommonProgramFiles(x86)%\system sll\is-9q6ml.tmp to %CommonProgramFiles(x86)%\system sll\hzzinit.exe
- from %CommonProgramFiles(x86)%\system sll\is-s5m5m.tmp to %CommonProgramFiles(x86)%\system sll\startdlp.exe
- from %CommonProgramFiles(x86)%\system sll\is-q7mll.tmp to %CommonProgramFiles(x86)%\system sll\swresample-0bp1.dll
- %CommonProgramFiles(x86)%\system sll\abc.html
- http://sh#####pi.huigezi.org/api/GetServerParamByMID?mi########
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- http://up####.hgzvip.net:8000/sixemployee/update.dat?t=############
- http://up####.hgzvip.net:8000/sixemployee/control.ini
- http://up####.hgzvip.net:8000/sixemployee/update/abc.html
- DNS ASK ji####x.hgzvip.net
- DNS ASK om####.hgzvip.net
- DNS ASK p2###.hgzvip.net
- DNS ASK sh#####pi.huigezi.org
- DNS ASK microsoft.com
- DNS ASK up####.hgzvip.net
- 'ji####x.hgzvip.net':9901
- ClassName: 'EDIT' WindowName: ''
- 'C:\_108754.exe' /verysilent
- '%CommonProgramFiles(x86)%\system sll\sll.exe'
- '%CommonProgramFiles(x86)%\system sll\fmtm\start.exe'
- '%CommonProgramFiles(x86)%\system sll\comupdate.exe' http://up####.hgzvip.net:8000/sixemployee
- '%CommonProgramFiles(x86)%\system sll\sllsrv.exe'
- '%CommonProgramFiles(x86)%\system sll\x64\nvsc.exe' hide
- '%CommonProgramFiles(x86)%\system sll\checkfirewall.exe' %CommonProgramFiles(x86)%\System Sll\sll.exe
- '%CommonProgramFiles(x86)%\system sll\start.exe' hide
- '%CommonProgramFiles(x86)%\system sll\tasksetter.exe' /watch
- '%TEMP%\is-shve3.tmp\hzzinstaller.exe' /stopsll
- '%CommonProgramFiles(x86)%\system sll\hzzsrvinit.exe' /install
- '%CommonProgramFiles(x86)%\system sll\hzzinstaller.exe' /delinnoun
- '%CommonProgramFiles(x86)%\system sll\keyboard\sysoft.exe'
- '%TEMP%\is-iu932.tmp\_108754.tmp' /SL5="$100214,15712940,141312,C:\_108754.exe" /verysilent
- '%CommonProgramFiles(x86)%\system sll\tasksetter.exe' /install
- '%CommonProgramFiles(x86)%\system sll\hzzinstaller.exe' /hidedir /dir "%CommonProgramFiles(x86)%\System Sll\"
- '%CommonProgramFiles(x86)%\system sll\hzzinit.exe' /kill
- '%CommonProgramFiles(x86)%\system sll\hzzinstaller.exe' /judgesys
- '%CommonProgramFiles(x86)%\system sll\hzzinstaller.exe' /setidrdb "C:\_108754.exe"
- '%CommonProgramFiles(x86)%\system sll\fmtm\x64\fmtm.exe'
- '%CommonProgramFiles(x86)%\system sll\hzzinit.exe' /kill' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c SC description "sllService" "hzz ctl check module"' (with hidden window)
- '%TEMP%\is-shve3.tmp\hzzinstaller.exe' /stopsll' (with hidden window)
- '%CommonProgramFiles(x86)%\system sll\hzzinstaller.exe' /setidrdb "C:\_108754.exe"' (with hidden window)
- '%CommonProgramFiles(x86)%\system sll\tasksetter.exe' /install' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c Schtasks /run /tn "System Sll"' (with hidden window)
- '%CommonProgramFiles(x86)%\system sll\sll.exe' ' (with hidden window)
- '%CommonProgramFiles(x86)%\system sll\hzzinstaller.exe' /hidedir /dir "%CommonProgramFiles(x86)%\System Sll\"' (with hidden window)
- '%CommonProgramFiles(x86)%\system sll\tasksetter.exe' /watch' (with hidden window)
- '%CommonProgramFiles(x86)%\system sll\hzzinstaller.exe' /judgesys' (with hidden window)
- '%CommonProgramFiles(x86)%\system sll\hzzinstaller.exe' /delinnoun' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c Schtasks /run /tn "System Sll"
- '%WINDIR%\syswow64\schtasks.exe' /run /tn "System Sll"
- '<SYSTEM32>\taskeng.exe' {51D9CE32-C713-4BB0-8AC1-7D12714C343D} S-1-5-21-1960123792-2022915161-3775307078-1001:jonjdvyfx\user:Interactive:[1]
- '%WINDIR%\syswow64\cmd.exe' /c SC description "sllService" "hzz ctl check module"
- '%WINDIR%\syswow64\sc.exe' description "sllService" "hzz ctl check module"
- '%WINDIR%\syswow64\cmd.exe'