Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Hzssvr Service] 'Start' = '00000002'
- '%TEMP%\nsc6.tmp\ns8.tmp' sc description "Hzssvr Service" "Hzssvr Service"
- '%PROGRAM_FILES%\ainqngz3.9\Ainqngz3.9.exe'
- '%PROGRAM_FILES%\ainqngz3.9\jistlo.exe' /s
- '%PROGRAM_FILES%\Favorite\ico\_xhzm10_s.exe'
- '%PROGRAM_FILES%\Favorite\ico\pczh_107_306.exe'
- '%TEMP%\nsc6.tmp\ns7.tmp' sc create "Hzssvr Service" binPath= "%PROGRAM_FILES%\ainqngz3.9\Hzsvr.exe" start= auto
- '<SYSTEM32>\sc.exe' description "Hzssvr Service" "Hzssvr Service"
- '<SYSTEM32>\sc.exe' create "Hzssvr Service" binPath= "%PROGRAM_FILES%\ainqngz3.9\Hzsvr.exe" start= auto
- [<HKCU>\Software\FlashFXP]
- %PROGRAM_FILES%\Favorite\ico\_xhzm10_s.exe
- %PROGRAM_FILES%\Favorite\ico\ay.ico
- %PROGRAM_FILES%\Favorite\ico\360.ico
- %PROGRAM_FILES%\Favorite\ico\123.ico
- %PROGRAM_FILES%\Favorite\ico\23451.ico
- %PROGRAM_FILES%\Favorite\ico\tb1.ico
- %HOMEPATH%\Desktop\360°ІИ«дЇААЖч.lnk
- %PROGRAM_FILES%\Favorite\ico\sg1.ico
- %PROGRAM_FILES%\Favorite\ico\ie.ico
- %PROGRAM_FILES%\Favorite\ico\pczh_107_306.exe
- %PROGRAM_FILES%\yunboplayer\uboskin\skin\min.jpg
- %PROGRAM_FILES%\yunboplayer\uboskin\skin\pk.jpg
- %PROGRAM_FILES%\yunboplayer\uboskin\skin\menu.jpg
- %PROGRAM_FILES%\yunboplayer\uboskin\skin\max-1.jpg
- %PROGRAM_FILES%\yunboplayer\uboskin\skin\max-2.jpg
- %PROGRAM_FILES%\Favorite\ЛС№·µјєЅ.url
- %PROGRAM_FILES%\Favorite\МФ±¦Нш.url
- %PROGRAM_FILES%\Favorite\2345µјєЅ.url
- %PROGRAM_FILES%\yunboplayer\uboskin\skin\tv.jpg
- %PROGRAM_FILES%\yunboplayer\uboskin\skin\zb.jpg
- %TEMP%\nsh5.tmp
- %TEMP%\nsc6.tmp\ns8.tmp
- %HOMEPATH%\Desktop\°®Зй.ЦЗ»Ы.3.9.lnk
- %TEMP%\nsc6.tmp\ns7.tmp
- %HOMEPATH%\Start Menu\Programs\°®Зй.ЦЗ»Ы.3.9\°®Зй.ЦЗ»Ы.3.9.lnk
- %TEMP%\nsc6.tmp\nsExec.dll
- %TEMP%\nsc6.tmp\md5dll.dll
- %TEMP%\nsc6.tmp\Inetc.dll
- %APPDATA%\zn520146\set.ini
- %TEMP%\nsc6.tmp\Math.dll
- %APPDATA%\zn520146\min.ini
- %TEMP%\nsc6.tmp\NSISdl.dll
- %HOMEPATH%\Templates\52014617574843\YYM_955WD30.gif
- %TEMP%\nsc6.tmp\System.dll
- %TEMP%\nsc6.tmp\Base64.dll
- %HOMEPATH%\Desktop\ФЖІҐУ°КУєР.lnk
- %PROGRAM_FILES%\ainqngz3.9\Hzsvr.exe
- %HOMEPATH%\Start Menu\Programs\°®Зй.ЦЗ»Ы.3.9\Р¶ФШ.lnk
- %PROGRAM_FILES%\ainqngz3.9\jistlo.exe
- %PROGRAM_FILES%\ainqngz3.9\Ainqngz3.9.exe
- %PROGRAM_FILES%\ainqngz3.9\uninstall.exe
- %PROGRAM_FILES%\yunboplayer\favorite\ico\123.ico
- %PROGRAM_FILES%\yunboplayer\favorite\ico\23451.ico
- %PROGRAM_FILES%\yunboplayer\favorite\МФ±¦Нш.url
- %PROGRAM_FILES%\yunboplayer\favorite\2345µјєЅ.url
- %PROGRAM_FILES%\yunboplayer\favorite\ЛС№·µјєЅ.url
- %PROGRAM_FILES%\yunboplayer\favorite\ico\ie.ico
- %PROGRAM_FILES%\yunboplayer\favorite\ico\pczh_107_306.exe
- %PROGRAM_FILES%\yunboplayer\favorite\ico\ay.ico
- %PROGRAM_FILES%\yunboplayer\favorite\ico\360.ico
- %PROGRAM_FILES%\yunboplayer\favorite\ico\_xhzm10_s.exe
- %TEMP%\nsi3.tmp\yunbodown
- %PROGRAM_FILES%\yunboplayer\link.txt
- %TEMP%\nsi3.tmp\NSISdl.dll
- %TEMP%\nss2.tmp
- %TEMP%\nsi3.tmp\System.dll
- %PROGRAM_FILES%\yunboplayer\app\loading.swf
- %PROGRAM_FILES%\yunboplayer\app\yunboapp.exe
- %PROGRAM_FILES%\yunboplayer\app\loading.html
- %PROGRAM_FILES%\yunboplayer\tj.txt
- %PROGRAM_FILES%\yunboplayer\ubohe.db
- %PROGRAM_FILES%\yunboplayer\favorite\ico\sg1.ico
- %PROGRAM_FILES%\yunboplayer\uboskin\skin\bj.jpg
- %PROGRAM_FILES%\yunboplayer\uboskin\skin\dibulan.jpg
- %PROGRAM_FILES%\yunboplayer\uboskin\skin\biaotilan.jpg
- %PROGRAM_FILES%\yunboplayer\uboskin\skin\Close.jpg
- %PROGRAM_FILES%\yunboplayer\uboskin\skin\bf.jpg
- %PROGRAM_FILES%\yunboplayer\uboskin\skin\logo.tif
- %PROGRAM_FILES%\yunboplayer\uboskin\skin\lt.jpg
- %PROGRAM_FILES%\yunboplayer\uboskin\skin\logo.jpg
- %PROGRAM_FILES%\yunboplayer\uboskin\skin\hp.jpg
- %PROGRAM_FILES%\yunboplayer\uboskin\skin\list.jpg
- %PROGRAM_FILES%\yunboplayer\uboskin\uboplaylist.xml
- %PROGRAM_FILES%\yunboplayer\uboskin\app\loading.html
- %PROGRAM_FILES%\yunboplayer\uboskin\icon.ico
- %PROGRAM_FILES%\yunboplayer\favorite\ico\tb1.ico
- %PROGRAM_FILES%\yunboplayer\uboskin\config.ini
- %PROGRAM_FILES%\yunboplayer\uboskin\html\loading.swf
- %PROGRAM_FILES%\yunboplayer\uboskin\html\logo.gif
- %PROGRAM_FILES%\yunboplayer\uboskin\html\loading.html
- %PROGRAM_FILES%\yunboplayer\uboskin\app\loading.swf
- %PROGRAM_FILES%\yunboplayer\uboskin\html\gbook.html
- %TEMP%\nsc6.tmp\md5dll.dll
- %TEMP%\nsc6.tmp\Math.dll
- %TEMP%\nsc6.tmp\Inetc.dll
- %TEMP%\nsc6.tmp\System.dll
- %TEMP%\nsc6.tmp\NSISdl.dll
- %TEMP%\nsc6.tmp\nsExec.dll
- %TEMP%\nsc6.tmp\Base64.dll
- %TEMP%\nsi3.tmp\yunbodown
- %TEMP%\nsi3.tmp\System.dll
- %TEMP%\nsi3.tmp\NSISdl.dll
- %TEMP%\nsc6.tmp\ns8.tmp
- %TEMP%\nsc6.tmp\ns7.tmp
- %HOMEPATH%\Templates\52014617574843\YYM_955WD30.gif
- 'localhost':1059
- 'cd##.##wn.17173ie.com':80
- 'pp#.#dsbw.cn':80
- pp#.#dsbw.cn/app.txt
- DNS ASK tj.###ingzhihui.com
- DNS ASK tv.###ingzhihui.com
- DNS ASK up####.aiqingzhihui.com
- DNS ASK pp#.#dsbw.cn
- DNS ASK cd##.##wn.17173ie.com
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'