Technical Information
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\3FB824C44CC7ED623B66C8.lnk
- %PROGRAM_FILES%\bigsoft\PPTV(pplive)_forqd572.exe
- "%TEMP%\PPTV(pplive)_forqd572.exe" (downloaded from the Internet)
- <SYSTEM32>\attrib.exe "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\фп└└╞ў╔╧═°.lnk" +r
- <SYSTEM32>\attrib.exe "%ALLUSERSPROFILE%\╫└├ц\╠╘╧▓╗╢.lnk" +r
- <SYSTEM32>\attrib.exe "%ALLUSERSPROFILE%\╫└├ц\фп└└╞ў╔╧═°.lnk" +r
- <SYSTEM32>\wscript.exe "%WINDIR%\onlyyou\4acfa28ff1b446ee645bdba8bb7081c5.vbs"
- %WINDIR%\regedit.exe -s "%WINDIR%\onlyyou\zhuyao.reg"
- <SYSTEM32>\attrib.exe "%APPDATA%\Microsoft\Internet Explorer\Quick Launch\╠╘╧▓╗╢.lnk" +r
- <SYSTEM32>\attrib.exe "%PROGRAM_FILES%\ilovetb" +s +r +h
- <SYSTEM32>\attrib.exe "%PROGRAM_FILES%\iloveu" +s +r +h
- <SYSTEM32>\attrib.exe "%PROGRAM_FILES%\iloveu\TheWorld.ini" +s +r +h
- <SYSTEM32>\cmd.exe /c ""%WINDIR%\onlyyou\4CC7ED623B609D70.bat" "
- <SYSTEM32>\attrib.exe "%PROGRAM_FILES%\ilovetb\TheWorld.ini" +s +r +h
- <SYSTEM32>\attrib.exe "%PROGRAM_FILES%\mycher" +s +r +h
- <SYSTEM32>\attrib.exe "%PROGRAM_FILES%\mycher\itemlist.conf" +s +r +h
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_12.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_11.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_14.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_13.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_10.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_7.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_6.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_9.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_8.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\download.cnet.com_favicon.ico
- %PROGRAM_FILES%\ilovetb\ImgCache\m445.mail.qq.com_favicon.ico
- %PROGRAM_FILES%\ilovetb\ImgCache\comment5.news.qq.com_favicon.ico
- %PROGRAM_FILES%\ilovetb\ImgCache\taoke.alimama.com_favicon.ico
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_19.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_16.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_15.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_18.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_17.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_5.bmp
- %WINDIR%\onlyyou\icons\Thumbs.db
- %WINDIR%\onlyyou\icons\xtzj.ico
- %PROGRAM_FILES%\ilovetb\TheWorld.exe
- %PROGRAM_FILES%\ilovetb\xihuan.ico
- %WINDIR%\onlyyou\icons\xihuan.ico
- %WINDIR%\onlyyou\icons\dang.ico
- %WINDIR%\onlyyou\icons\2345.ico
- %WINDIR%\onlyyou\icons\joyo.ico
- %WINDIR%\onlyyou\icons\Internet.ico
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_2.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_1.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_4.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_3.bmp
- %PROGRAM_FILES%\ilovetb\ImgCache\MouseGesture_0.bmp
- %PROGRAM_FILES%\ilovetb\TheWorld.ini
- %PROGRAM_FILES%\ilovetb\dailytips.ini
- %PROGRAM_FILES%\ilovetb\ImgCache\www.ioage.com_favicon.ico
- %PROGRAM_FILES%\ilovetb\theworld.ac
- %PROGRAM_FILES%\ilovetb\ImgCache\www.taobao.com_favicon.ico
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_9.bmp
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_8.bmp
- %ALLUSERSPROFILE%\Desktop\МФПІ»¶.lnk
- %PROGRAM_FILES%\bigsoft\PPTV(pplive)_forqd572.exe
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_7.bmp
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_4.bmp
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_3.bmp
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_6.bmp
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_5.bmp
- %ALLUSERSPROFILE%\Start Menu\Programs\дЇААЖчЙПНш.lnk
- %ALLUSERSPROFILE%\Start Menu\дЇААЖчЙПНш.lnk
- %TEMP%\PPTV(pplive)_forqd572.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\69I9OPW5\PPTV(pplive)_forqd572[1].exe
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\дЇААЖчЙПНш.lnk
- %ALLUSERSPROFILE%\Start Menu\МФПІ»¶.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\МФПІ»¶.lnk
- %ALLUSERSPROFILE%\Desktop\дЇААЖчЙПНш.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\МФПІ»¶.lnk
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_2.bmp
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_0.bmp
- %PROGRAM_FILES%\iloveu\iloveu.ico
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_10.bmp
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_1.bmp
- %PROGRAM_FILES%\iloveu\theworld.ac
- %PROGRAM_FILES%\iloveu\dailytips.ini
- %PROGRAM_FILES%\ilovetb\ImgCache\union.dangdang.com_favicon.ico
- %PROGRAM_FILES%\iloveu\TheWorld.ini
- %PROGRAM_FILES%\iloveu\TheWorld.exe
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_17.bmp
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_16.bmp
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_19.bmp
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_18.bmp
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_15.bmp
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_12.bmp
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_11.bmp
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_14.bmp
- %PROGRAM_FILES%\iloveu\ImgCache\MouseGesture_13.bmp
- %PROGRAM_FILES%\mycher\icons\iPhoto.png
- %PROGRAM_FILES%\mycher\icons\iMovie.png
- %PROGRAM_FILES%\mycher\icons\LinkURL.png
- %PROGRAM_FILES%\mycher\icons\iTunes.png
- %PROGRAM_FILES%\mycher\icons\iChat.png
- %PROGRAM_FILES%\mycher\icons\default.png
- %PROGRAM_FILES%\mycher\icons\Dashboard.png
- %PROGRAM_FILES%\mycher\icons\iCal.png
- %PROGRAM_FILES%\mycher\icons\Finder.png
- %PROGRAM_FILES%\mycher\icons\TrashFull.png
- %PROGRAM_FILES%\mycher\icons\TrashEmpty.png
- %PROGRAM_FILES%\mycher\icons\shopcart.png
- %PROGRAM_FILES%\mycher\icons\chonglang Shortcut.png
- %PROGRAM_FILES%\mycher\icons\SystemPrefs.png
- %PROGRAM_FILES%\mycher\icons\QuickTime.png
- %PROGRAM_FILES%\mycher\icons\Mail.png
- %PROGRAM_FILES%\mycher\icons\Safari.png
- %PROGRAM_FILES%\mycher\icons\RKLauncher.png
- %PROGRAM_FILES%\mycher\icons\Address Book.png
- %PROGRAM_FILES%\mycher\RKDocklet.dll
- %PROGRAM_FILES%\mycher\RKLauncher.conf
- %PROGRAM_FILES%\mycher\excluded.conf
- %PROGRAM_FILES%\mycher\icons.conf
- %PROGRAM_FILES%\mycher\RKLauncher.dll
- %TEMP%\_ir_sf7_temp_0\irsetup.dat
- %TEMP%\_ir_sf7_temp_0\irsetup.exe
- %PROGRAM_FILES%\mycher\YzDocklet.dll
- %TEMP%\_ir_sf7_temp_0\IRIMG1.JPG
- %PROGRAM_FILES%\mycher\docklets\RecycleBin\icons\SLATE_READ_ME.txt
- %PROGRAM_FILES%\mycher\docklets\RecycleBin\RecycleBin_readme.txt
- %PROGRAM_FILES%\mycher\docklets\RecycleBin\icons\trash_full.ico
- %PROGRAM_FILES%\mycher\docklets\RecycleBin\icons\trash_empty.ico
- %PROGRAM_FILES%\mycher\docklets\RecycleBin\RecycleBin.ini
- %PROGRAM_FILES%\mycher\RKLauncher.exe
- %PROGRAM_FILES%\mycher\dockletstemp.ini
- %PROGRAM_FILES%\mycher\docklets\RecycleBin\RecycleBin.dll
- %PROGRAM_FILES%\mycher\itemlist.conf
- %PROGRAM_FILES%\mycher\icons\shopcartadd.png
- %WINDIR%\onlyyou\navinfo.db
- %WINDIR%\onlyyou\360se_s.ini
- %WINDIR%\onlyyou\tan.bat
- %WINDIR%\onlyyou\TtConf.dat
- %WINDIR%\onlyyou\360sefav.db
- %WINDIR%\onlyyou\4acfa28ff1b446ee645bdba8bb7081c5.vbs
- %WINDIR%\onlyyou\4CC7ED623B609D70.bat
- %WINDIR%\onlyyou\zhu.reg
- %WINDIR%\onlyyou\A60f3C.vbs
- %WINDIR%\onlyyou\Fav\МФ°ЎМФ - МФЈЎОТПІ»¶.url
- %WINDIR%\onlyyou\Fav\µ±µ±НшЎЄНшЙП№єОпЦРРД.url
- %WINDIR%\onlyyou\Fav\ѕ©¶«ЙМіЗ.url
- %WINDIR%\onlyyou\Fav\ВМЙ«ИнјюХѕ.url
- %WINDIR%\onlyyou\Fav\ЧїФЅСЗВнС·.url
- %WINDIR%\onlyyou\config.xml
- %WINDIR%\onlyyou\del.bat
- %WINDIR%\onlyyou\Fav\·ІїНіПЖ·.url
- %WINDIR%\onlyyou\Fav\2345НшХѕЦ®јТ.url
- %WINDIR%\onlyyou\5e643138f47194aa.bat
- %PROGRAM_FILES%\mycher\icons\buy.png
- %PROGRAM_FILES%\mycher\icons\xtzj.ico
- %PROGRAM_FILES%\mycher\lang\rkl_SimplifiedChinese.lang
- %PROGRAM_FILES%\mycher\icons\icon_tao.png
- %PROGRAM_FILES%\mycher\icons\xihuan.ico
- %PROGRAM_FILES%\mycher\icons\dang.ico
- %PROGRAM_FILES%\mycher\icons\main.ico
- %PROGRAM_FILES%\mycher\icons\joyo.ico
- %PROGRAM_FILES%\mycher\icons\chonglang.ico
- %WINDIR%\onlyyou\gongju.reg
- %PROGRAM_FILES%\mycher\themes\Default\theme.conf
- %WINDIR%\onlyyou\3FB824C44CC7ED623B609D702462D6C8.vbs
- %WINDIR%\onlyyou\zhuyao.reg
- %PROGRAM_FILES%\mycher\themes\Default\sep.png
- %PROGRAM_FILES%\mycher\themes\Default\bg.png
- %PROGRAM_FILES%\mycher\plugins\RKScaleEffect\RKScaleEffect.dll
- %PROGRAM_FILES%\mycher\themes\Default\poof.png
- %PROGRAM_FILES%\mycher\themes\Default\mark.png
- %PROGRAM_FILES%\iloveu\TheWorld.ini
- %PROGRAM_FILES%\mycher\itemlist.conf
- %PROGRAM_FILES%\ilovetb\TheWorld.ini
- %WINDIR%\onlyyou\icons\Thumbs.db
- %PROGRAM_FILES%\ilovetb\theworld.ac
- %PROGRAM_FILES%\iloveu\theworld.ac
- %TEMP%\_ir_sf7_temp_0\irsetup.exe
- %TEMP%\_ir_sf7_temp_0\IRIMG1.JPG
- %TEMP%\_ir_sf7_temp_0\irsetup.dat
- 'do####ad.pplive.com':80
- 'localhost':1037
- do####ad.pplive.com/PPTV(pplive)_forqd572.exe
- DNS ASK do####ad.pplive.com
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'MS_WINHELP' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''