Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%PROGRAM_FILES%\knamqh_70784.exe' = '%PROGRAM_FILES%\knamqh_70784.exe:*:Enabled:百度卫士在线安装程序'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] '%PROGRAM_FILES%\knamqh_70784.exe' = '%PROGRAM_FILES%\knamqh_70784.exe:*:Enabled:百度卫士在线安装程序'
- '%PROGRAM_FILES%\YYMusic2\20140405094902\YYSpeed.exe'
- '%PROGRAM_FILES%\YYMusic2\20140405094902\YYMusic.exe' -tuopan
- '%PROGRAM_FILES%\aqing2.9\zatray.exe' /s
- '%PROGRAM_FILES%\aqing2.9\Aqing2.9.exe'
- '%PROGRAM_FILES%\fjyy\fjyy.exe'
- '%PROGRAM_FILES%\setup_2948-162271.exe'
- '%PROGRAM_FILES%\knamqh_70784.exe'
- '%PROGRAM_FILES%\fjyy_slient_zhimeng_163076.exe'
- '%PROGRAM_FILES%\pczh_110_158679.exe'
- %WINDIR%\Explorer.EXE
- [<HKCU>\Software\FlashFXP]
- %PROGRAM_FILES%\YYMusic2\20140405094902\avcodec-54.dll
- %PROGRAM_FILES%\YYMusic2\20140405094902\avcore.dll
- %PROGRAM_FILES%\YYMusic2\20140405094902\Skin\progresstooltip.png
- %PROGRAM_FILES%\YYMusic2\20140405094902\audio.dll
- %PROGRAM_FILES%\YYMusic2\20140405094902\avformat-54.dll
- %PROGRAM_FILES%\YYMusic2\20140405094902\DuiLib.dll
- %PROGRAM_FILES%\YYMusic2\20140405094902\favorfm.xml
- %PROGRAM_FILES%\YYMusic2\20140405094902\avutil-52.dll
- %PROGRAM_FILES%\YYMusic2\20140405094902\channels.xml
- %PROGRAM_FILES%\YYMusic2\20140405094902\Skin\mainframeshadow.png
- %PROGRAM_FILES%\YYMusic2\20140405094902\Data\client.ini
- %PROGRAM_FILES%\YYMusic2\20140405094902\Data\dh.ini
- %PROGRAM_FILES%\YYMusic2\20140405094902\YYMusic.exe
- %PROGRAM_FILES%\YYMusic2\20140405094902\YYSpeed.exe
- %PROGRAM_FILES%\YYMusic2\20140405094902\Data\server.ini
- %PROGRAM_FILES%\YYMusic2\20140405094902\Data\version.ini
- %PROGRAM_FILES%\YYMusic2\20140405094902\Skin\hotkeytipbk.png
- %PROGRAM_FILES%\YYMusic2\20140405094902\Data\setup.ini
- %PROGRAM_FILES%\YYMusic2\20140405094902\Data\user2.ini
- %PROGRAM_FILES%\YYMusic2\20140405094902\libav.dll
- %HOMEPATH%\Start Menu\Programs\°®Зй.ЦЗ»Ы.2.9\°®Зй.ЦЗ»Ы.2.9.lnk
- %HOMEPATH%\Desktop\°®Зй.ЦЗ»Ы.2.9.lnk
- %PROGRAM_FILES%\aqing2.9\ToolZhApp.exe
- %HOMEPATH%\Start Menu\Programs\°®Зй.ЦЗ»Ы.2.9\Р¶ФШ.lnk
- %TEMP%\nse6.tmp\Math.dll
- %APPDATA%\ZhiHui520144\min.ini
- %APPDATA%\ZhiHui520144\set.ini
- %TEMP%\nse6.tmp\md5dll.dll
- %TEMP%\nse6.tmp\Inetc.dll
- %PROGRAM_FILES%\aqing2.9\zatray.exe
- %PROGRAM_FILES%\YYMusic2\20140405094902\source.dll
- %PROGRAM_FILES%\YYMusic2\20140405094902\swresample-0.dll
- %PROGRAM_FILES%\YYMusic2\20140405094902\pthreadGC2.dll
- %PROGRAM_FILES%\YYMusic2\20140405094902\Skin.rs
- %HOMEPATH%\Start Menu\Programs\YYMusic2\YYMusic2.lnk
- %PROGRAM_FILES%\aqing2.9\Aqing2.9.exe
- %PROGRAM_FILES%\aqing2.9\uninstall.exe
- %HOMEPATH%\Start Menu\Programs\YYMusic2\№Щ·ЅЦчТі.lnk
- %HOMEPATH%\Start Menu\Programs\YYMusic2\ЕдЦГ№¤ѕЯ\Р¶ФШYYMusic2.lnk
- %PROGRAM_FILES%\fjyy\skin\cale.png
- %PROGRAM_FILES%\fjyy\skin\close.png
- %TEMP%\nse6.tmp\Base64.dll
- %PROGRAM_FILES%\fjyy\skin\bg.png
- %PROGRAM_FILES%\fjyy\skin\Cmd.png
- %PROGRAM_FILES%\fjyy\skin\Mstsc.png
- %TEMP%\nse6.tmp\System.dll
- %PROGRAM_FILES%\fjyy\skin\Msconfig.png
- %PROGRAM_FILES%\fjyy\skin\MsPaint.png
- %PROGRAM_FILES%\fjyy\install_1396720136.tmp
- %PROGRAM_FILES%\pczh_110_158679.exe
- %PROGRAM_FILES%\fjyy_slient_zhimeng_163076.exe
- %PROGRAM_FILES%\knamqh_70784.exe
- %PROGRAM_FILES%\setup_2948-162271.exe
- %TEMP%\nsm2.tmp
- %TEMP%\nsh3.tmp\BDMSkin.dll
- %PROGRAM_FILES%\fjyy\Config.ini
- %TEMP%\nsh3.tmp\res\onlineWnd.zip
- %TEMP%\nso5.tmp
- %PROGRAM_FILES%\fjyy\skin\Notepad.png
- %TEMP%\nsh3.tmp\BDLogicUtils.dll
- %TEMP%\nsh3.tmp\BDMNetGetInfo.dll
- %ALLUSERSPROFILE%\Start Menu\附件应用.lnk
- %TEMP%\nsh3.tmp\hu.dll
- %TEMP%\nsh3.tmp\tmpk0jpar.dll
- %PROGRAM_FILES%\YYMusic2\20140405094902\SysConfig.ini
- %PROGRAM_FILES%\YYMusic2\20140405094902\Unins.exe
- %HOMEPATH%\Templates\52014494857468\YYM_955WD30.gif
- <LS_APPDATA>\附件应用.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\附件应用\卸载附件应用.lnk
- %PROGRAM_FILES%\fjyy\unist.exe
- %TEMP%\nsh3.tmp\BDMDownload.dll
- %PROGRAM_FILES%\fjyy\skin\taskmgr.png
- %PROGRAM_FILES%\fjyy\fjyy.exe
- %TEMP%\nsh3.tmp\dl.dll
- %ALLUSERSPROFILE%\Start Menu\Programs\附件应用\附件应用.lnk
- %TEMP%\nse6.tmp\NSISdl.dll
- %ALLUSERSPROFILE%\Desktop\附件应用.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\附件应用.lnk
- %TEMP%\nse6.tmp\md5dll.dll
- %TEMP%\nse6.tmp\Math.dll
- %TEMP%\nse6.tmp\System.dll
- %TEMP%\nse6.tmp\NSISdl.dll
- %HOMEPATH%\Templates\52014494857468\YYM_955WD30.gif
- %PROGRAM_FILES%\fjyy\install_1396720136.tmp
- %TEMP%\nse6.tmp\Inetc.dll
- %TEMP%\nse6.tmp\Base64.dll
- 'localhost':1047
- 'up####.aiqingzhihui.com':80
- '<IP-адрес в локальной сети>':445
- up####.aiqingzhihui.com/0324/help1.html
- DNS ASK tj.###ingzhihui.com
- DNS ASK up####.yinyue.fm
- DNS ASK ai####.aiqingzhihui.com
- DNS ASK tv.###ingzhihui.com
- DNS ASK cl####.jxdcw.com
- DNS ASK up####.aiqingzhihui.com
- DNS ASK we####.baidu.com
- DNS ASK p.#.#aidu.com
- ClassName: 'Progman' WindowName: 'Program Manager'
- ClassName: '(null)' WindowName: 'taskmgr.exe'
- ClassName: '#32770' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'ToolbarWindow32' WindowName: '(null)'
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'BDMOnLineWnd' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'SysPager' WindowName: '(null)'
- ClassName: 'TrayNotifyWnd' WindowName: '(null)'