Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,%ProgramFiles(x86)%\systemfiles\system32.exe'
- %ProgramFiles(x86)%\systemfiles\2.vbs
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\pause_pressed.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\pause_normal.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\pause_hover.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\mute_pressed.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\mute_normal.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\mute_hover.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\main_dialog.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\fullscreen_pressed.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\fullscreen_normal.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\fullscreen_hover.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\play_normal.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\play_hover.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\explayer_normal.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\explayer_hover.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\explayer_disabled.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\duration_slider_pressed.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\duration_slider_normal.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\duration_slider_hover.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\sopvod.exe
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\sopocx.ocx
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\config.xml
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\uusee\trafficlight.dll
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\fullscreen_disabled.bmp
- %HOMEPATH%\favorites\¾øé«èëìåòõêõГ¼£¡£¡çëóãòõêõµäñû¹âðà éГВЈВЎ.url
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\play_pressed.bmp
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\¾åæ·¼«ëùГøâçµçó°µçêó\uninstall.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\æô¶¯\ìúñ¶qq.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\¾åæ·¼«ëùГøâçµçó°µçêó\В№Г№В·ВЅГøõ¾.lnk
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\¾åæ·¼«ëùГøâçµçó°µçêó.url
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\adv\default\index.html
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\adv\default\home.html
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\adv\default\thumbs.db
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\adv\sopadver.exe
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\sopcore.xml
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\volume_slider_pressed.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\volume_slider_normal.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\volume_slider_hover.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\unmute_pressed.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\unmute_normal.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\unmute_hover.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\thumbs.db
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\stop_pressed.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\stop_normal.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\stop_hover.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\stop_disabled.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\sopstatus_normal.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\soplogo_pressed.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\soplogo_normal.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\uusee\seeplayer.ocx
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\explayer_pressed.bmp
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\uusee\out_mmshttp.dll
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\uusee\in_net.dll
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\9ptv.exe
- %HOMEPATH%\desktop\ìô±¦Гø½ñèõ´òõûìø¼ûçø.lnk
- %HOMEPATH%\favorites\¿´¿´µçêó¾ç£¬×îðâ×îºãµäâìé«ãâ·ñµçêó¾çГøõ¾.url
- %HOMEPATH%\application data\microsoft\internet explorer\quick launch\internet exp1orer.url
- %HOMEPATH%\favorites\׿ô½ñçâГГ±В·ГøéﹺîïГ¼ê飬êö»ú£¬êýâ룬¼òµç£¬»¯×±æ·£¬öó±Г£¬ê×êîµèôúïßïúêû.url
- %HOMEPATH%\favorites\µ±µ±ГГё ВЁc è«çò×î´óµäöðîäГøéïêéµê&¹ºîïöððä.url
- %HOMEPATH%\favorites\ГІГ—ГЁВ¤ГГё - æ·öêГø¹º£¬à öôúò×è¤.url
- %HOMEPATH%\favorites\ìô±¦ГГё - ìô£¡îòï²»¶.url
- %HOMEPATH%\favorites\¾åæ·¸ßçåГøâçµçêó.lnk
- %HOMEPATH%\favorites\ç§ç§ìåóýö±²¥.lnk
- %HOMEPATH%\desktop\ãâ·ñµçó°.lnk
- %HOMEPATH%\desktop\³¬¼¶ºãГæð¡óîï·.lnk
- %HOMEPATH%\desktop\ç§ç§ìåóýö±²¥.lnk
- %HOMEPATH%\favorites\×îðââìé«ãâ·ñµç󰣡¸ßëù¸ßç壡ìììì¸üð⣡£¡£¡.url
- %ProgramFiles(x86)%\systemfiles\taobao.ico
- %ProgramFiles(x86)%\systemfiles\system32.exe
- %ProgramFiles(x86)%\systemfiles\qq.ico
- %ProgramFiles(x86)%\systemfiles\kusila.ico
- %ProgramFiles(x86)%\systemfiles\game.ico
- %ProgramFiles(x86)%\systemfiles\77zb.ico
- %ProgramFiles(x86)%\systemfiles\9ptvs1.exe
- %ProgramFiles(x86)%\systemfiles\9ptv.ico
- %ProgramFiles(x86)%\systemfiles\3.vbs
- %ProgramFiles(x86)%\systemfiles\3.bat
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\uninst.exe
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sopcast\skin\soplogo_hover.bmp
- %HOMEPATH%\favorites\¼«æ·ãà ãäçå´¿ð´õ棡£¡ãà ГВјВґГіВјВЇВєГЇВЈВЎ.url
- %APPDATA%\microsoft\internet explorer\quick launch\ìô±¦Гø½ñèõ´òõûìø¼ûçø.lnk
- %HOMEPATH%\favorites\45575ôúïßð¡óîï·£¬×îºãГæ×î¿ìµäð¡óîï·.url
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sohu\mmcshell.dll
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sina\°²×°.bat
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sina\zlib.dll
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sina\liveupdate.dll
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sina\downloader.dll
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sina\clear.bat
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sina\uclivectrl.ocx
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sina\uclivecore.dll
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\sina\state.dll
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\cctv\cctvupdateinstall.dll
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\kernel\cctv\cctvplayer.ocx
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\readme.txt
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\info.ini
- %HOMEPATH%\desktop\¾åæ·¼«ëùГøâçµçó°µçêó.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\¾åæ·¼«ëùГøâçµçó°µçêó\¾åæ·¼«ëùГøâçµçó°µçêó.lnk
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\chis.ini
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\languages\japanese.ini
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\languages\english.ini
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\languages\chinese gb.ini
- %ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\languages\chinese big5.ini
- %APPDATA%\microsoft\internet explorer\quick launch\ãâ·ñµçó°.lnk
- %APPDATA%\microsoft\internet explorer\quick launch\ç§ç§ìåóýö±²¥.lnk
- %APPDATA%\microsoft\internet explorer\quick launch\³¬¼¶ºãГæð¡óîï·.lnk
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- 'ba##u.com':80
- 'so##.9ptv.com':80
- http://so##.9ptv.com/s1/
- DNS ASK ba##u.com
- DNS ASK so##.9ptv.com
- DNS ASK ww###171.vip
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: '%HOMEPATH%\Desktop'
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "%ProgramFiles(x86)%\systemfiles\2.vbs"
- '%WINDIR%\syswow64\wscript.exe' "%ProgramFiles(x86)%\systemfiles\3.vbs"
- '%ProgramFiles(x86)%\systemfiles\9ptvs1.exe'
- '%ProgramFiles(x86)%\¾åæ·¼«ëùГøâçµçó°µçêó\9ptv.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%ProgramFiles(x86)%\systemfiles\3.bat" "
- '%WINDIR%\syswow64\reg.exe' del "HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command" /v
- '%WINDIR%\syswow64\reg.exe' add "HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command" /v "" /d "%ProgramFiles(x86)%\Internet Explorer\iexplore.exe http://www.626dh.cn/?cry6" /f
- '%WINDIR%\syswow64\cmd.exe' /c ""%ProgramFiles(x86)%\systemfiles\3.bat" "' (with hidden window)
- '%WINDIR%\syswow64\wscript.exe' "%ProgramFiles(x86)%\systemfiles\3.vbs"' (with hidden window)