Technical Information
- [HKLM\Software\Classes\.\Shell\open\command] '' = '"Rundll32.exe" "%WINDIR%\fsvr.lex" Resetrun'
- %TEMP%\is-l81is.tmp\<File name>.tmp
- %WINDIR%\wintemp_64\rd.txt
- %WINDIR%\wintemp_64\sanguo.ico
- %WINDIR%\wintemp_64\taobao.ico
- %WINDIR%\wintemp_64\xianjian.ico
- %WINDIR%\wintemp_64\zhuoyue.ico
- %WINDIR%\fsvr.lex
- %WINDIR%\wintemp_64\mzsg.ico
- %WINDIR%\wintemp_64\ppn1.ico
- %WINDIR%\data1
- %TEMP%\etilqs_hda3vdcny1rqkdy
- %TEMP%\etilqs_imii7lk7wqkuzro
- %TEMP%\etilqs_ya4dgjraqs13f0g
- %TEMP%\etilqs_fhajiwydhnsuagw
- %TEMP%\etilqs_y9a4kyfgpddhftj
- %TEMP%\etilqs_hpddalnah9zgtqg
- %TEMP%\etilqs_ecb4oz1hohg1nwh
- %TEMP%\etilqs_p0ljgvzszm7bwbe
- %WINDIR%\wintemp_64\minigame.ico
- %WINDIR%\wintemp_64\lc.ico
- %WINDIR%\wintemp_64\hao.ico
- %TEMP%\is-v6ktg.tmp\_isetup\_setup64.tmp
- %TEMP%\is-v6ktg.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-v6ktg.tmp\installdll.dll
- %ProgramFiles(x86)%\huanbang123\is-41nat.tmp
- %ProgramFiles(x86)%\huanbang123\is-riik5.tmp
- %ProgramFiles(x86)%\huanbang123\is-74f1p.tmp
- %ProgramFiles(x86)%\huanbang123\is-lp923.tmp
- %TEMP%\is-v6ktg.tmp\_isetup\_regdll.tmp
- %ProgramFiles(x86)%\huanbang123\unins000.dat
- %WINDIR%\install.tmp
- %WINDIR%\wintemp_64\2xi.ico
- %WINDIR%\wintemp_64\altersvr.dll
- %WINDIR%\wintemp_64\config.ini
- %WINDIR%\wintemp_64\dangdangwang.ico
- %WINDIR%\wintemp_64\data1
- %WINDIR%\wintemp_64\fsvr.lex
- %WINDIR%\wintemp_64\install.tmp
- %TEMP%\etilqs_qprm14md3xei15t
- %TEMP%\etilqs_malv5gthg38deal
- %ProgramFiles(x86)%\huanbang123\install.tmp
- %TEMP%\is-v6ktg.tmp\installdll.dll
- %TEMP%\is-v6ktg.tmp\_isetup\_regdll.tmp
- %TEMP%\is-v6ktg.tmp\_isetup\_setup64.tmp
- %TEMP%\is-v6ktg.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-l81is.tmp\<File name>.tmp
- from %ProgramFiles(x86)%\huanbang123\is-41nat.tmp to %ProgramFiles(x86)%\huanbang123\unins000.exe
- from %ProgramFiles(x86)%\huanbang123\is-riik5.tmp to %ProgramFiles(x86)%\huanbang123\installdll.dll
- from %ProgramFiles(x86)%\huanbang123\is-74f1p.tmp to %ProgramFiles(x86)%\huanbang123\install.tmp
- from %ProgramFiles(x86)%\huanbang123\is-lp923.tmp to %ProgramFiles(x86)%\huanbang123\info.desc
- '12#.#24.9.113':8022
- 'au######te.geo.opera.com':80
- 'au######te.geo.opera.com':443
- 'google.com':80
- 'se####.yahoo.com':80
- 'du###uckgo.com':443
- 'am##on.com':80
- 'bing.com':80
- 'am##on.com':443
- 'se####.yahoo.com':443
- 'en.###ipedia.org':80
- 'en.###ipedia.org':443
- 'si#####ck2.opera.com':80
- 're###.opera.com':80
- 'ya###.opera.com':80
- 'fa###ook.com':80
- http://au######te.geo.opera.com/geolocation/
- http://www.google.com/favicon.ico
- http://se####.yahoo.com/favicon.ico
- http://www.am##on.com/favicon.ico
- http://www.bing.com/s/a/bing_p.ico
- http://en.###ipedia.org/favicon.ico
- http://si#####ck2.opera.com/?ho###################################################
- http://re###.opera.com/www.opera.com/firstrun/
- http://si#####ck2.opera.com/?ho#######################################################
- http://re###.opera.com/favicon.ico
- http://ya###.opera.com/favicon.ico
- http://re###.opera.com/speeddials/partner/facebook
- http://www.fa###ook.com/campaign/landing.php?ca#########################
- 'au######te.geo.opera.com':443
- 'du###uckgo.com':443
- 'am##on.com':443
- 'se####.yahoo.com':443
- 'en.###ipedia.org':443
- 'ya###.opera.com':443
- DNS ASK google.com
- DNS ASK au######te.geo.opera.com
- DNS ASK se####.yahoo.com
- DNS ASK du###uckgo.com
- DNS ASK am##on.com
- DNS ASK bing.com
- DNS ASK bi##.#ikimedia.org
- DNS ASK en.###ipedia.org
- DNS ASK si#####ck2.opera.com
- DNS ASK re###.opera.com
- DNS ASK ya###.opera.com
- DNS ASK op##a.com
- DNS ASK xi###i189.com
- DNS ASK fa###ook.com
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Opera_MessageWindow' WindowName: '%APPDATA%\Opera Software\Opera Stable'
- '%TEMP%\is-l81is.tmp\<File name>.tmp' /SL5="$50244,1711953,53248,<Full path to file>"
- '%WINDIR%\syswow64\regedit.exe' -s "%ProgramFiles(x86)%\huanbang123\info.desc"
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2916.4.1523203035\2022517613" --lang=en-US --no-sandbox --enable-proprietary-media-types-playback /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2916.11.1593631888\730318971" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2916.10.1528402273\85425917" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2916.7.1685601296\185417519" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2916.9.157589796\1511019743" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2916.8.1409010735\1581347858" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2916.6.88454777\309650925" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2916.5.155731351\621087434" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera_crashreporter.exe' --type=utility --channel="2916.4.1523203035\2022517613" --lang=en-US --no-sandbox --enable-proprietary-media-types-playback /prefetch:-645351001 /crash-reporter-parent-id=1836
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=renderer --alt-high-dpi-setting=96 --disable-direct-npapi-requests --enable-deferred-image-decoding --lang=en-US --enable-proprietary-media-types-playback --disable-client-side-phishing-...
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=gpu-process --channel="2916.0.850037012\1604995755" --enable-proprietary-media-types-playback --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,19,42 --gpu-vendor-id=0x0000 --gpu...
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera_crashreporter.exe' -noautoupdate --ran-launcher -- http://www.xiazai189.com/new/bf02/default.html?from=rj0073 /crash-reporter-parent-id=2916
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' -noautoupdate --ran-launcher -- http://www.xiazai189.com/new/bf02/default.html?from=rj0073
- '%ProgramFiles(x86)%\opera\launcher.exe' -noautoupdate -- "http://www.xiazai189.com/new/bf02/default.html?from=rj0073"
- '%WINDIR%\syswow64\rundll32.exe' "%WINDIR%\wintemp_64\altersvr.dll" Scanprocess
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2916.12.900264763\1388087849" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2916.15.728296274\237886446" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
- '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=renderer --alt-high-dpi-setting=96 --disable-direct-npapi-requests --enable-deferred-image-decoding --lang=en-US --enable-proprietary-media-types-playback --extension-process --enable-we...
- '%ProgramFiles(x86)%\opera\launcher.exe' -noautoupdate -- "http://www.xiazai189.com/new/bf02/default.html?from=rj0073"' (with hidden window)
- '%WINDIR%\syswow64\rundll32.exe' "%WINDIR%\wintemp_64\altersvr.dll" Scanprocess' (with hidden window)
- '%WINDIR%\syswow64\regedit.exe' -s "%ProgramFiles(x86)%\huanbang123\info.desc"' (with hidden window)