Technical Information
- '%TEMP%\nsw3.tmp\kuping_s_51022.exe'
- '%TEMP%\nsw3.tmp\setup_open_4127.exe'
- '%TEMP%\nsw3.tmp\SoHuVA_4.2.0.0-c204900009-ng-s-run-x.exe'
- '%TEMP%\nsw3.tmp\setup_3155.exe'
- '%TEMP%\nsw3.tmp\pipi_dae_274.exe'
- '%TEMP%\nsw3.tmp\setup_t10110.exe'
- '%TEMP%\nsw3.tmp\92046_al.exe'
- '%TEMP%\nsw3.tmp\pczh_155.exe'
- '%TEMP%\nsw3.tmp\shenmatv_dae_300.exe'
- '%TEMP%\nsw3.tmp\setups30112.exe'
- '%TEMP%\nsw3.tmp\setup_qd206.exe'
- '%TEMP%\nsw3.tmp\mx_4zengjie.exe'
- '%TEMP%\nsw3.tmp\vmmc_70208.exe'
- '%TEMP%\nsw3.tmp\setup1146568.exe'
- '%TEMP%\nsw3.tmp\vxdpwbw_30071.exe'
- '%TEMP%\nsw3.tmp\dianxin_silent[108].exe'
- '%TEMP%\nsw3.tmp\setup_3155.exe' (downloaded from the Internet)
- '%TEMP%\nsw3.tmp\mx_4zengjie.exe' (downloaded from the Internet)
- '%TEMP%\nsw3.tmp\pipi_dae_274.exe' (downloaded from the Internet)
- '%TEMP%\nsw3.tmp\dianxin_silent[108].exe' (downloaded from the Internet)
- '%TEMP%\nsw3.tmp\setup_t10110.exe' (downloaded from the Internet)
- '%TEMP%\nsw3.tmp\92046_al.exe' (downloaded from the Internet)
- '%TEMP%\nsw3.tmp\vmmc_70208.exe' (downloaded from the Internet)
- '%TEMP%\nsw3.tmp\setup1146568.exe' (downloaded from the Internet)
- '%TEMP%\nsw3.tmp\setup_qd206.exe' (downloaded from the Internet)
- '%TEMP%\nsw3.tmp\vxdpwbw_30071.exe' (downloaded from the Internet)
- '%TEMP%\nsw3.tmp\setups30112.exe' (downloaded from the Internet)
- '%TEMP%\nsw3.tmp\pczh_155.exe' (downloaded from the Internet)
- '%TEMP%\nsw3.tmp\shenmatv_dae_300.exe' (downloaded from the Internet)
- '%TEMP%\nsw3.tmp\setup_open_4127.exe' (downloaded from the Internet)
- '%TEMP%\nsw3.tmp\SoHuVA_4.2.0.0-c204900009-ng-s-run-x.exe' (downloaded from the Internet)
- '%TEMP%\nsw3.tmp\kuping_s_51022.exe' (downloaded from the Internet)
- %TEMP%\nsw3.tmp\pczh_155.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\zhihui[1].gif
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\shenma[1].gif
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\ailiao[1].gif
- %TEMP%\nsw3.tmp\shenmatv_dae_300.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\kuping[1].gif
- %TEMP%\nsw3.tmp\SoHuVA_4.2.0.0-c204900009-ng-s-run-x.exe
- %TEMP%\nsw3.tmp\kuping_s_51022.exe
- %TEMP%\nsw3.tmp\setup_open_4127.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\wuji[1].gif
- %TEMP%\nsw3.tmp\92046_al.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\dianxin[1].gif
- %TEMP%\nsw3.tmp\setup_3155.exe
- %TEMP%\nsw3.tmp\dianxin_silent[108].exe
- %TEMP%\nsw3.tmp\mx_4zengjie.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\mx_4zengjie[1].txt
- %TEMP%\nsw3.tmp\setup_t10110.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\xiaoxin[1].gif
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\pipi_dae_274[1].txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\yinyue[1].gif
- %TEMP%\nsw3.tmp\pipi_dae_274.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\SoHuVA_4.0.0.73-c204900009-ng-s-run-x[1].txt
- %PROGRAM_FILES%\їбІҐУ°Тф\uninst.exe
- %HOMEPATH%\Start Menu\Programs\їбІҐУ°Тф\Uninstall.lnk
- %TEMP%\nsw3.tmp\System.dll
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\kk[1].htm
- %TEMP%\nsw3.tmp\inetc.dll
- %TEMP%\nsw3.tmp\FindProcDLL.dll
- %TEMP%\nsg2.tmp
- %PROGRAM_FILES%\їбІҐУ°Тф\play.exe
- %HOMEPATH%\Desktop\їбІҐУ°Тф.lnk
- %HOMEPATH%\Start Menu\Programs\їбІҐУ°Тф\їбІҐУ°Тф.lnk
- %PROGRAM_FILES%\їбІҐУ°Тф\black.htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\baiduweishi[1].gif
- %TEMP%\nsw3.tmp\setup_qd206.exe
- %TEMP%\nsw3.tmp\vmmc_70208.exe
- %TEMP%\nsw3.tmp\setup1146568.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\ruixing[1].gif
- %TEMP%\nsw3.tmp\vxdpwbw_30071.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\baidushadu[1].gif
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\gongju[1].gif
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\setup_qd206[1].txt
- %TEMP%\nsw3.tmp\setups30112.exe
- %TEMP%\nsw3.tmp\setup_qd206.exe
- %TEMP%\nsw3.tmp\setup_t10110.exe
- %TEMP%\nsw3.tmp\setup_3155.exe
- %TEMP%\nsw3.tmp\setup_open_4127.exe
- %TEMP%\nsw3.tmp\shenmatv_dae_300.exe
- %TEMP%\nsw3.tmp\vmmc_70208.exe
- %TEMP%\nsw3.tmp\vxdpwbw_30071.exe
- %TEMP%\nsw3.tmp\SoHuVA_4.2.0.0-c204900009-ng-s-run-x.exe
- %TEMP%\nsw3.tmp\System.dll
- %TEMP%\nsw3.tmp\setups30112.exe
- %TEMP%\nsw3.tmp\FindProcDLL.dll
- %TEMP%\nsw3.tmp\inetc.dll
- %TEMP%\nsw3.tmp\92046_al.exe
- %TEMP%\nsw3.tmp\dianxin_silent[108].exe
- %TEMP%\nsw3.tmp\kuping_s_51022.exe
- %TEMP%\nsw3.tmp\pipi_dae_274.exe
- %TEMP%\nsw3.tmp\setup1146568.exe
- %TEMP%\nsw3.tmp\mx_4zengjie.exe
- %TEMP%\nsw3.tmp\pczh_155.exe
- 'd.##dtw.com':80
- 'dl.#ipi.cn':80
- 'mk.##xthon.cn':80
- 'yu##.yyjdpm.net':80
- 'do####ad.yyjdpm.net':80
- 'do##.guangsu.cn':80
- do####ad.yyjdpm.net/ailiao.gif
- do####ad.yyjdpm.net/xiaoxin.gif
- do####ad.yyjdpm.net/zhihui.gif
- do####ad.yyjdpm.net/shenma.gif
- do####ad.yyjdpm.net/dianxin.gif
- mk.##xthon.cn/max4/zxr/mx_4zengjie.txt
- dl.#ipi.cn/pipi_dae_274.txt
- do####ad.yyjdpm.net/yinyue.gif
- do##.guangsu.cn/qdn/setup_qd206.txt
- do####ad.yyjdpm.net/baiduweishi.gif
- do####ad.yyjdpm.net/baidushadu.gif
- do####ad.yyjdpm.net/gongju.gif
- do####ad.yyjdpm.net/kuping.gif
- do####ad.yyjdpm.net/wuji.gif
- do####ad.yyjdpm.net/ruixing.gif
- d.##dtw.com/exe/SoHuVA_4.0.0.73-c204900009-ng-s-run-x.txt
- yu##.yyjdpm.net/kk.php
- DNS ASK d.##dtw.com
- DNS ASK dl.#ipi.cn
- DNS ASK mk.##xthon.cn
- DNS ASK yu##.yyjdpm.net
- DNS ASK do####ad.yyjdpm.net
- DNS ASK do##.guangsu.cn
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'