Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\kangle] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\kangle] 'ImagePath' = '%ProgramFiles%\Bangteng\Kangle\bin\kangle.exe --ntsrv'
- C:\ho\234578.php
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\category.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\cart32.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\cart16.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\cart128.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\background_new.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\background_game.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\16\16-drop4.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\animation_default.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\30\30-steady4.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\30\30-steady2.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\30\30-steady1.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\30\30-rise4.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\30\30-rise3.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\30\30-rise2.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\cart48.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\goto_icon.png
- C:\llq\1c2j4\AppData\Roaming\SogouExplorer\commcfg.xml
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\30\30-lowest4.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\message.png
- C:\llq\1c2j4\AppData\Roaming\Mozilla\Firefox\Profiles\key4.db
- C:\llq\1c2j4\AppData\Roaming\Mozilla\Firefox\Profiles\cert9.db
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Preferences
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\popup_new.html
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\manifest.json
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\include.preload.js
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\include.postload.js
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\pop_background.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\popup.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\pleasewait.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\option_icon.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\open_background.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\null.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\newimage.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\30\30-rise1.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\30\30-steady3.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\30\30-lowest3.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\30\30-lowest2.png
- C:\llq\1c2j4\AppData\Roaming\SogouExplorer\Extension\com.aifenhui\1.0.0\default-big.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\popup.html
- C:\llq\1c2j4\AppData\Roaming\360se6\apps\data\users\login.ini
- C:\llq\1c2j4\AppData\Roaming\360se6\apps\data\users\default\360sefav.db
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Secure Preferences
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Preferences_01
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Preferences
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\popup_new.html
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\options.html
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\16\16-drop2.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\manifest.json
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\include.preload.js
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\include.postload.js
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\taoChong64x64.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\icon-48.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\16\16-drop3.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\icon-19.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\16\16-lowest1.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\16\16-lowest3.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\30\30-lowest1.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\16\16-drop1.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\30\30-drop4.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\30\30-drop3.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\30\30-drop2.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\30\30-drop1.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\16\16-steady4.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\16\16-steady3.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\16\16-steady2.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\16\16-steady1.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\16\16-rise4.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\16\16-rise3.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\16\16-rise2.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\16\16-rise1.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\16\16-lowest4.png
- C:\llq\1c2j4\AppData\Roaming\360se6\User Data\Default\Extensions\dobbgecnokkloebjbcnjpgcopegjabpa\43.2.1.1_0\images\16\16-lowest2.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\icon-32.png
- C:\llq\1c2j4\AppData\Roaming\SogouExplorer\Extension\com.aifenhui\1.0.0\default.ico
- C:\luub\k1j311.cmd
- %ProgramFiles%\Bangteng\Kangle\bin\autoupdate.exe
- %ProgramFiles%\Bangteng\Kangle\bin\netisapi.dll
- %WINDIR%\assembly\tmp\0BLOQRUL\netisapi.dll
- %ProgramFiles%\Bangteng\Kangle\bin\pcre.dll
- C:\Config.Msi\29bcc.rbs
- %WINDIR%\Installer\MSI6.tmp
- %ProgramFiles%\Bangteng\Kangle\www\index.html
- %ProgramFiles%\Bangteng\Kangle\webadmin\kangle.css
- %WINDIR%\Installer\MSI4.tmp
- %TEMP%\CFG3.tmp
- %WINDIR%\Installer\MSI2.tmp
- %WINDIR%\Installer\29bc9.msi
- %WINDIR%\certutil.log
- C:\index1.html
- %WINDIR%\Installer\MSI5.tmp
- C:\Youdao\pf\config.xml
- %ProgramFiles%\Bangteng\Kangle\bin\libiconv2.dll
- %WINDIR%\Installer\29bd0.msi
- %ProgramFiles%\Bangteng\Kangle\etc\lang_zh.xml
- %ProgramFiles%\Bangteng\Kangle\etc\lang.xml
- %ProgramFiles%\Bangteng\Kangle\bin\extworker.exe
- %ProgramFiles%\Bangteng\Kangle\bin\ssleay32.dll
- %ProgramFiles%\Bangteng\Kangle\webadmin\core.whm
- %ProgramFiles%\Bangteng\Kangle\COPYRIGHT.rtf
- %ProgramFiles%\Bangteng\Kangle\.autoupdate.conf
- %ProgramFiles%\Bangteng\Kangle\etc\lang_en.xml
- %ProgramFiles%\Bangteng\Kangle\bin\webdav.dll
- %ProgramFiles%\Bangteng\Kangle\webadmin\logo.gif
- %ProgramFiles%\Bangteng\Kangle\bin\libeay32.dll
- %ProgramFiles%\Bangteng\Kangle\bin\zlib1.dll
- %ProgramFiles%\Bangteng\Kangle\bin\kangle.exe
- %ProgramFiles%\Bangteng\Kangle\bin\sqlite3.dll
- C:\index.html
- %WINDIR%\Installer\29bcb.ipi
- C:\Youdao\s.txt
- C:\sm\SMD-96.lnk
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\sprite.png
- C:\llq\1c2j4\AppData\Roaming\SogouExplorer\Extension\com.aifenhui\1.0.0\manifest.xml
- C:\luub\7ac21j.cmd
- C:\luub\21.jpg
- C:\luub\20.jpg
- C:\luub\19.jpg
- C:\llq\serverb.key
- C:\llq\serverb.crt
- C:\llq\cs.htm
- C:\llq\certutil.lnk
- C:\llq\ca15.cer
- C:\llq\1c2j4\AppData\Roaming\SogouExplorer\favorite3.dat
- C:\llq\1c2j4\AppData\Roaming\SogouExplorer\Extension4.db
- C:\llq\1c2j4\AppData\Roaming\SogouExplorer\Extension3.db
- C:\llq\1c2j4\AppData\Roaming\SogouExplorer\Extension\com.sogou.muti-translate\1.7.1.33\js\main.js
- C:\llq\1c2j4\AppData\Roaming\SogouExplorer\Extension\com.aifenhui\1.0.0\sgs.js
- C:\luub\i4bofang11.html
- C:\llq\1c2j4\AppData\Roaming\SogouExplorer\Extension\com.aifenhui\1.0.0\sg.js
- C:\luub\style.css
- C:\luub\tulogo.gif
- C:\luub\yhfdjtjyt.gif
- C:\sm\MKD-S61.lnk
- C:\sm\1115609_easyicon.ico
- %ProgramFiles% (x86)\Bangteng\Kangle\www\index1.html
- %ProgramFiles% (x86)\Bangteng\Kangle\www\fzkl86.asp
- %ProgramFiles% (x86)\Bangteng\Kangle\www\fz.asp
- %ProgramFiles% (x86)\Bangteng\Kangle\ext\tpl_php52\php5ts.dll
- %ProgramFiles% (x86)\Bangteng\Kangle\ext\tpl_php52\php5isapi.dll
- %ProgramFiles% (x86)\Bangteng\Kangle\etc\config.xml
- %ProgramFiles% (x86)\86klepd.php
- %ProgramFiles%\klepd.php
- %ProgramFiles%\Bangteng\Kangle\www\index1.html
- %ProgramFiles%\Bangteng\Kangle\www\fzklxp.asp
- %ProgramFiles%\Bangteng\Kangle\www\fz.asp
- %ProgramFiles%\Bangteng\Kangle\etc\config.xml
- C:\sm\shuo4.html
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\icon-16.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\icon-128.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\cart48.png
- C:\llq\1c2j4\AppData\Local\2345Explorer\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb\2.0.5_0\icons\audio.png
- C:\llq\1c2j4\AppData\Local\2345Explorer\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb\2.0.5_0\icons\48.png
- C:\llq\1c2j4\AppData\Local\2345Explorer\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb\2.0.5_0\icons\38.png
- C:\llq\1c2j4\AppData\Local\2345Explorer\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb\2.0.5_0\icons\32.png
- C:\llq\1c2j4\AppData\Local\2345Explorer\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb\2.0.5_0\icons\19.png
- C:\llq\1c2j4\AppData\Local\2345Explorer\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb\2.0.5_0\manifest.json
- C:\llq\1c2j4\AppData\Local\2345Explorer\User Data\Default\Secure Preferences
- C:\llq\1c2j4\AppData\Local\2345Explorer\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb\2.0.5_0\icons\16.png
- C:\llq\1c2j4\AppData\Local\2345Explorer\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb\2.0.5_0\bubble_compiled.js
- C:\klbi\klssl.exe
- C:\klbi\kl318kj.lnk
- C:\klbi\cjq21.cmd
- C:\klbi\cj2.lnk
- C:\llq\1c2j4\AppData\Local\2345Explorer\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb\2.0.5_0\icons\128.png
- C:\llq\1c2j4\AppData\Local\2345Explorer\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb\2.0.5_0\bubble_gss.css
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\5.png
- C:\llq\1c2j4\AppData\Local\360Chrome\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\541.2.9.6_0\images\discount.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\2.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\1.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcajlbggkngndkclhoihkflldkaeeohm\4.2.3_0\manifest.json
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcajlbggkngndkclhoihkflldkaeeohm\4.2.3_0\include.preload.js
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcajlbggkngndkclhoihkflldkaeeohm\4.2.3_0\include.postload.js
- C:\llq\1c2j4\AppData\Local\360Chrome\Chrome\User Data\Default\Preferences
- C:\llq\1c2j4\AppData\Local\360Chrome\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\541.2.9.6_0\manifest.json
- C:\llq\1c2j4\AppData\Local\360Chrome\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\541.2.9.6_0\include.preload.js
- C:\llq\1c2j4\AppData\Local\360Chrome\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\541.2.9.6_0\include.postload.js
- C:\llq\1c2j4\AppData\Local\360Chrome\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\541.2.9.6_0\images\icon-32.png
- C:\llq\1c2j4\AppData\Local\360Chrome\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\541.2.9.6_0\images\icon-19.png
- C:\llq\1c2j4\AppData\Local\360Chrome\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\541.2.9.6_0\images\icon-16.png
- C:\llq\1c2j4\AppData\Local\360Chrome\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\541.2.9.6_0\images\icon-128.png
- C:\llq\1c2j4\AppData\Local\360Chrome\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\541.2.9.6_0\images\discount_hover.png
- C:\klbi\cj.lnk
- C:\klbi\certutilgl.lnk
- C:\llq\1c2j4\AppData\Local\2345Explorer\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb\2.0.5_0\_metadata\verified_contents.json
- C:\klbi\certutil15.exe
- C:\klbi\certutil.lnk
- C:\ho\iexp.php
- C:\ho\dakai.php
- C:\ho\ggxp.php
- C:\ho\gg78.php
- C:\ho\gai.php
- C:\ho\fz.asp
- C:\ho\desktop.ini
- C:\ho\dakainr.php
- C:\ho\cj.php
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\4.png
- C:\ho\360xp.php
- C:\ho\360jsxp.php
- C:\ho\360js78.php
- C:\ho\36078.php
- C:\ho\2345xp.php
- C:\ho\lb78.php
- C:\ho\lbxp.php
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\3.png
- C:\ho\pdhosts.php
- C:\ho\llqcj.asp
- C:\ho\ie78.php
- C:\klbi\436.msi
- C:\klbi\3msistub2.exe
- C:\kj3\xxhos45600.bat
- C:\kj3\Shortcut.exe
- C:\hos\hosts
- C:\hos\h357.php
- C:\ho\tuihst.php
- C:\ho\sgxp.php
- C:\ho\sg78.php
- C:\ho\qqxp.php
- C:\ho\qq78.php
- C:\ho\pdssl.asp
- C:\ho\pdkl86.asp
- C:\ho\pdkl.asp
- C:\klbi\c2j1.rar
- C:\llq\1c2j4\AppData\Local\2345Explorer\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb\2.0.5_0\icons\new_translation.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\6.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\16\16-steady4.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\16\16-drop1.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\16\16-steady3.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\16\16-steady2.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\16\16-steady1.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\16\16-rise4.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\16\16-rise3.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\16\16-rise2.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\16\16-rise1.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\16\16-lowest4.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\16\16-lowest3.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\16\16-lowest2.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\16\16-lowest1.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\16\16-drop4.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\16\16-drop3.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\16\16-drop2.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\80-80.jpg
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\30\30-drop1.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\30\30-drop2.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\30\30-drop3.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\30\30-drop4.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\cart16.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\cart128.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\30\30-steady4.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\30\30-steady3.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\30\30-steady2.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\30\30-steady1.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\30\30-rise4.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\30\30-rise3.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\30\30-rise2.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\30\30-rise1.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\30\30-lowest4.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\30\30-lowest3.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\30\30-lowest2.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\30\30-lowest1.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\images\cart32.png
- %ProgramFiles%\Bangteng\Kangle\bin\kasp.dll
- %ProgramFiles%\Bangteng\Kangle\var\kangle.pid
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\hlppekcioiicbfafmmgikkdkljnjpiao\5.2.2_0\content.js
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\help_hover.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\icon-huihui.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\icon-32.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\icon-19.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\icon-16.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\icon-128.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\huihuigwzs_sp.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\help.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\logo.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\glyphicons-halflings-white.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\feedback_hover.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\feedback.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\discount_hover.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\discount.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\banner-item.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\hlppekcioiicbfafmmgikkdkljnjpiao\cjpd.js
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\0_0\bg.html
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\more_pic.png
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\include.postload.js
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\icon.png
- C:\llq\1c2j4\AppData\Local\Tencent\QQBrowser\content.js
- C:\llq\1c2j4\AppData\Local\liebao\User Data\Default\Preferences.1
- C:\llq\1c2j4\AppData\Local\liebao\User Data\Default\Preferences
- C:\llq\1c2j4\AppData\Local\liebao\User Data\Default\Extensions\ikhdkkncnoglghljlkmcimlnlhkeamad\4.3_0\manifest.json
- C:\llq\1c2j4\AppData\Local\liebao\User Data\Default\Extensions\ikhdkkncnoglghljlkmcimlnlhkeamad\4.3_0\js\content.js
- C:\llq\1c2j4\AppData\Local\liebao\User Data\Default\Extensions\ikhdkkncnoglghljlkmcimlnlhkeamad\4.3_0\js\com.js
- C:\llq\1c2j4\AppData\Local\liebao\User Data\Default\Extensions\ikhdkkncnoglghljlkmcimlnlhkeamad\4.3_0\img\logo.png
- C:\llq\1c2j4\AppData\Local\liebao\User Data\Default\Extensions\ikhdkkncnoglghljlkmcimlnlhkeamad\4.3_0\css\popup.css
- C:\llq\1c2j4\AppData\Local\liebao\User Data\Default\Extensions\ikhdkkncnoglghljlkmcimlnlhkeamad\4.3_0\css\content.css
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Preferences
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\popup.html
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\manifest.json
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\include.preload.js
- C:\llq\1c2j4\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohjkicjidmohhfcjjlahfppkdblibkkb\14.21.0_0\images\tips_bg.png
- %ProgramFiles%\Bangteng\Kangle\var\server.log
- C:\ho\desktop.ini
- C:\Config.Msi\29bce.rbf
- %WINDIR%\Installer\MSI2.tmp
- %WINDIR%\Installer\MSI4.tmp
- %WINDIR%\Installer\MSI5.tmp
- %WINDIR%\Installer\MSI6.tmp
- C:\Config.Msi\29bcd.rbf
- C:\Config.Msi\29bce.rbf
- C:\Config.Msi\29bcf.rbf
- C:\Config.Msi\29bcc.rbs
- %WINDIR%\Installer\29bc9.msi
- %WINDIR%\Installer\29bcb.ipi
- from %WINDIR%\WinSxS\Manifests\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375.cat to C:\Config.Msi\29bcd.rbf
- from %WINDIR%\WinSxS\Policies\x86_policy.9.0.Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_x-ww_b7353f75\9.0.21022.8.cat to C:\Config.Msi\29bcf.rbf
- from %ProgramFiles%\Bangteng\Kangle\etc\config.xml to C:\Config.Msi\29bce.rbf
- %ProgramFiles%\Bangteng\Kangle\etc\config.xml
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- 'C:\klbi\certutil15.exe' -addstore -enterprise "root" C:\llq\ca15.cer
- '%ProgramFiles%\Bangteng\Kangle\bin\kangle.exe' --install
- '%ProgramFiles%\Bangteng\Kangle\bin\kangle.exe' --ntsrv
- '%ProgramFiles%\Bangteng\Kangle\bin\kangle.exe' "--shutdown" "12644" "--active" "12640" "--notice" "12636" "--worker_index" "0" "--ppid" "3204"
- '<SYSTEM32>\cmd.exe' /c ""C:\luub\7ac21j.cmd" "
- '<SYSTEM32>\mshta.exe' vbscript:createobject("wscript.shell").run("""C:\luub\7ac21j.cmd"" h",0)(window.close)
- '<SYSTEM32>\cmd.exe' /c ""C:\luub\7ac21j.cmd" h"
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' C:\luub\i4bofang11.html
- '<SYSTEM32>\attrib.exe' "%ProgramFiles% (x86)\Bangteng\Kangle\etc\config.xml" -h +r
- '<SYSTEM32>\msiexec.exe' /i C:\klbi\436.msi /qn
- '<SYSTEM32>\cmd.exe' /c ""C:\klbi\cjq21.cmd" "
- '<SYSTEM32>\msiexec.exe' /V
- '<SYSTEM32>\mshta.exe' vbscript:createobject("wscript.shell").run("""C:\klbi\cjq21.cmd"" h",0)(window.close)
- '<SYSTEM32>\cmd.exe' /c ""C:\klbi\cjq21.cmd" h"
- '<SYSTEM32>\ping.exe' -n 2 localhost
- '<SYSTEM32>\msiexec.exe' -Embedding C11CBB29717DDC865F817164C063F5B2
- '<SYSTEM32>\attrib.exe' "%ProgramFiles%\Bangteng\Kangle\etc\config.xml" -h +r