Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Txssvr Service] 'Start' = '00000002'
- '<LS_APPDATA>\pczh_110_157120.exeex.exe' <LS_APPDATA>\pczh_110_157120.exe7231889http://wo####o.qiniudn.com/pczh_110_157120.exe?di####################
- '<LS_APPDATA>\365weatherIns_184.exeex.exe' <LS_APPDATA>\365weatherIns_184.exe7231889http://lm.##ilequ.com/update/365/365weatherIns_184.exe?77###################
- '<LS_APPDATA>\UUSEE_kb1003_Setup_162556.exeex.exe' <LS_APPDATA>\UUSEE_kb1003_Setup_162556.exe7231889http://cl###.t3nlink.com/link/162556/?36################
- '%TEMP%\nsh4.tmp\ns5.tmp' sc create "Txssvr Service" binPath= "%PROGRAM_FILES%\aiqngz3.8\Txsvr.exe" start= auto
- '<LS_APPDATA>\setup_qd262.exeex.exe' <LS_APPDATA>\setup_qd262.exe7231889http://wo####o.qiniudn.com/setup_qd262.exe?37######
- '<LS_APPDATA>\wauee_jx029.exeex.exe' <LS_APPDATA>\wauee_jx029.exe7231889http://do##.jdrili.com/wauee_jx029.exe?37######
- '<LS_APPDATA>\CBSI232A.exeex.exe' <LS_APPDATA>\CBSI232A.exe7231889http://www.91##ok.com/CBSI232A.exe
- '%PROGRAM_FILES%\aiqngz3.8\Aiqngz3.8.exe'
- '%PROGRAM_FILES%\aiqngz3.8\fastlo.exe' /s
- '%TEMP%\nsh4.tmp\ns6.tmp' sc description "Txssvr Service" "Txssvr Service"
- '<LS_APPDATA>\deskgrid_h181.exeex.exe' <LS_APPDATA>\deskgrid_h181.exe7231889http://dl.###emeitu.com/d/deskgrid_h181.exe
- '<LS_APPDATA>\jmsee-1.0.1.368.exeex.exe' <LS_APPDATA>\jmsee-1.0.1.368.exe7231889http://j1##.#inaapp.com/setup_h_48.exe?36##############
- '<LS_APPDATA>\NmnPps_1088.exeex.exe' <LS_APPDATA>\NmnPps_1088.exe7231889http://do##.u5c.net/nmnpps_1088.exe?37######
- '%PROGRAM_FILES%\Your Product\play_3022_31475.exe'
- '%PROGRAM_FILES%\Your Product\114lm_rebo_31475.exe'
- '<LS_APPDATA>\gsnbnoq_30362.exeex.exe' <LS_APPDATA>\gsnbnoq_30362.exe7231889http://ff###.qiniudn.com/gsnbnoq_30362.exe?37####################
- '%TEMP%\_ir_sf_temp_0\irsetup.exe' __IRAOFF:731682 "__IRAFN:<Полный путь к вирусу>" "__IRCT:1" "__IRTSS:0" "__IRSID:S-1-5-21-2052111302-484763869-725345543-1003"
- '%PROGRAM_FILES%\Your Product\pczh_113_31475.exe'
- '%PROGRAM_FILES%\Your Product\Play_2059_31475.exe'
- '<LS_APPDATA>\setup_ad7154.exeex.exe' <LS_APPDATA>\setup_ad7154.exe7231889http://do##.##aoxinrili.com/hezi/jm/setup_ad7154.exe?37##########
- '<LS_APPDATA>\play_2098.exeex.exe' <LS_APPDATA>\play_2098.exe7231889http://cl###.t3nlink.com/link/157141/?na#########################
- '<LS_APPDATA>\doyo_3052_s.exeex.exe' <LS_APPDATA>\doyo_3052_s.exe7231889http://so##.doyo.cn/soft/doyo_3052_s.exe?37######
- '<LS_APPDATA>\Setup_027.exeex.exe' <LS_APPDATA>\Setup_027.exe7231889http://www.sf##y.net/tdj/Setup_027.exe
- '<LS_APPDATA>\kuping_s_51630.exeex.exe' <LS_APPDATA>\kuping_s_51630.exe7231889http://do####ad.wallba.com/download.php/kuping_s_51630.exe?37######
- '<LS_APPDATA>\fgcn_101520.exeex.exe' <LS_APPDATA>\fgcn_101520.exe7231889http://do###.flashget.com/un/fgcn_101520.exe?37##########
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\CBSI232A.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\NmnPps_1088.exeex.exe.bat"
- '<SYSTEM32>\taskkill.exe' /F /IM deskgrid_h181.exeex.exe
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\doyo_3052_s.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\365weatherIns_184.exeex.exe.bat"
- '<SYSTEM32>\taskkill.exe' /F /IM play_2098.exeex.exe
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\jmsee-1.0.1.368.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\wauee_jx029.exeex.exe.bat"
- '<SYSTEM32>\taskkill.exe' /F /IM fgcn_101520.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM NmnPps_1088.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM wauee_jx029.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM 365weatherIns_184.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM CBSI232A.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM doyo_3052_s.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM UUSEE_kb1003_Setup_162556.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM setup_qd262.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM jmsee-1.0.1.368.exeex.exe
- '<SYSTEM32>\taskkill.exe' /F /IM pczh_110_157120.exeex.exe
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\Setup_027.exeex.exe.bat"
- '<SYSTEM32>\taskkill.exe' /F /IM gsnbnoq_30362.exeex.exe
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\kuping_s_51630.exeex.exe.bat"
- '<SYSTEM32>\taskkill.exe' /F /IM Setup_027.exeex.exe
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\gsnbnoq_30362.exeex.exe.bat"
- '<SYSTEM32>\sc.exe' description "Txssvr Service" "Txssvr Service"
- '<SYSTEM32>\sc.exe' create "Txssvr Service" binPath= "%PROGRAM_FILES%\aiqngz3.8\Txsvr.exe" start= auto
- '<SYSTEM32>\taskkill.exe' /F /IM 114lm_rebo_31475.exe
- '<SYSTEM32>\cmd.exe' /c "%PROGRAM_FILES%\Your Product\114lm_rebo_31475.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\pczh_110_157120.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\UUSEE_kb1003_Setup_162556.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\deskgrid_h181.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\setup_qd262.exeex.exe.bat"
- '<SYSTEM32>\taskkill.exe' /F /IM setup_ad7154.exeex.exe
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\setup_ad7154.exeex.exe.bat"
- '<SYSTEM32>\taskkill.exe' /F /IM kuping_s_51630.exeex.exe
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\play_2098.exeex.exe.bat"
- '<SYSTEM32>\cmd.exe' /c "<LS_APPDATA>\fgcn_101520.exeex.exe.bat"
- [<HKCU>\Software\FlashFXP]
- <LS_APPDATA>\NmnPps_1088.exeex.exe
- %HOMEPATH%\Start Menu\Programs\°®Зй.ЦЗ»Ы.3.8\Р¶ФШ.lnk
- <LS_APPDATA>\doyo_3052_s.exeex.exe
- %HOMEPATH%\Start Menu\Programs\°®Зй.ЦЗ»Ы.3.8\°®Зй.ЦЗ»Ы.3.8.lnk
- <LS_APPDATA>\setup_qd262.exeex.exe
- %TEMP%\nsh4.tmp\ns5.tmp
- %TEMP%\nsh4.tmp\nsExec.dll
- %PROGRAM_FILES%\aiqngz3.8\fastlo.exe
- %PROGRAM_FILES%\aiqngz3.8\uninstall.exe
- %PROGRAM_FILES%\aiqngz3.8\Aiqngz3.8.exe
- %PROGRAM_FILES%\aiqngz3.8\Txsvr.exe
- <LS_APPDATA>\play_2098.exeex.exe
- <LS_APPDATA>\setup_ad7154.exeex.exe
- <LS_APPDATA>\fgcn_101520.exeex.exe
- <LS_APPDATA>\wauee_jx029.exeex.exe
- %TEMP%\nsh4.tmp\Math.dll
- %HOMEPATH%\Desktop\°®Зй.ЦЗ»Ы.3.8.lnk
- <LS_APPDATA>\CBSI232A.exeex.exe
- %APPDATA%\zn2720142\min.ini
- %TEMP%\nsh4.tmp\Inetc.dll
- %TEMP%\nsh4.tmp\md5dll.dll
- %APPDATA%\zn2720142\set.ini
- <LS_APPDATA>\365weatherIns_184.exeex.exe
- %TEMP%\oem_te.tmp
- <LS_APPDATA>\pczh_110_157120.exeex.exe
- <LS_APPDATA>\UUSEE_kb1003_Setup_162556.exeex.exe
- <LS_APPDATA>\jmsee-1.0.1.368.exeex.exe
- <LS_APPDATA>\deskgrid_h181.exeex.exe
- %TEMP%\nsh4.tmp\ns6.tmp
- %PROGRAM_FILES%\Your Product\pczh_113_31475.exe
- %PROGRAM_FILES%\Your Product\Uninstall\uninstall.xml
- %PROGRAM_FILES%\Your Product\uninstall.exe
- %PROGRAM_FILES%\Your Product\Play_2059_31475.exe
- %HOMEPATH%\Start Menu\Programs\Your Product\pczh_113_31475.lnk
- %PROGRAM_FILES%\Your Product\114lm_rebo_31475.exe
- %PROGRAM_FILES%\Your Product\play_3022_31475.exe
- %TEMP%\_ir_sf_temp_0\IRIMG1.JPG
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- %TEMP%\_ir_sf_temp_0\irsetup.exe
- %TEMP%\_ir_sf_temp_0\IRIMG2.JPG
- %PROGRAM_FILES%\Your Product\Uninstall\uninstall.dat
- %PROGRAM_FILES%\Your Product\Uninstall\uni1.tmp
- %TEMP%\Your Product Setup Log.txt
- %HOMEPATH%\Start Menu\Programs\Your Product\Play_2059_31475.lnk
- %TEMP%\nsh4.tmp\NSISdl.dll
- %PROGRAM_FILES%\jq\open.ini
- %TEMP%\nsh4.tmp\System.dll
- %HOMEPATH%\Templates\272014215358812\YYM_955WD30.gif
- <LS_APPDATA>\kuping_s_51630.exeex.exe
- <LS_APPDATA>\Setup_027.exeex.exe
- <LS_APPDATA>\gsnbnoq_30362.exeex.exe
- %PROGRAM_FILES%\Your Product\Uninstall\IRIMG1.JPG
- %HOMEPATH%\Start Menu\Programs\Your Product\ИИІҐ.lnk
- %HOMEPATH%\Start Menu\Programs\Your Product\play_3022_31475.lnk
- %PROGRAM_FILES%\Your Product\Uninstall\IRIMG2.JPG
- %TEMP%\nsh4.tmp\Base64.dll
- %TEMP%\nsr3.tmp
- %HOMEPATH%\Start Menu\Programs\Your Product\Uninstall Your Product.lnk
- <LS_APPDATA>\fgcn_101520.exeex.exe
- <LS_APPDATA>\deskgrid_h181.exeex.exe
- <LS_APPDATA>\jmsee-1.0.1.368.exeex.exe
- <LS_APPDATA>\play_2098.exeex.exe
- <LS_APPDATA>\kuping_s_51630.exeex.exe
- <LS_APPDATA>\setup_ad7154.exeex.exe
- %TEMP%\oem_te.tmp
- <LS_APPDATA>\pczh_110_157120.exeex.exe
- <LS_APPDATA>\CBSI232A.exeex.exe
- <LS_APPDATA>\365weatherIns_184.exeex.exe
- <LS_APPDATA>\doyo_3052_s.exeex.exe
- <LS_APPDATA>\NmnPps_1088.exeex.exe
- <LS_APPDATA>\UUSEE_kb1003_Setup_162556.exeex.exe
- <LS_APPDATA>\setup_qd262.exeex.exe
- <LS_APPDATA>\wauee_jx029.exeex.exe
- %TEMP%\nsh4.tmp\System.dll
- %TEMP%\nsh4.tmp\ns6.tmp
- %PROGRAM_FILES%\Your Product\114lm_rebo_31475.exe
- <LS_APPDATA>\gsnbnoq_30362.exeex.exe
- %TEMP%\nsh4.tmp\ns5.tmp
- %TEMP%\_ir_sf_temp_0\irsetup.dat
- %PROGRAM_FILES%\Your Product\Uninstall\uni1.tmp
- %PROGRAM_FILES%\jq\open.ini
- <LS_APPDATA>\Setup_027.exeex.exe
- %TEMP%\nsh4.tmp\md5dll.dll
- %TEMP%\nsh4.tmp\nsExec.dll
- %TEMP%\nsh4.tmp\NSISdl.dll
- %TEMP%\nsh4.tmp\Math.dll
- %HOMEPATH%\Templates\272014215358812\YYM_955WD30.gif
- %TEMP%\nsh4.tmp\Base64.dll
- %TEMP%\nsh4.tmp\Inetc.dll
- 'as######.###rwqer.com.weqrqwe.mab.lzgzs.com':8011
- 'localhost':1059
- 'up####.aiqingzhihui.com':80
- 'cl####.jxdcw.com':80
- cl####.jxdcw.com/tongji.asp?sn#######################################
- up####.aiqingzhihui.com/0403/help1.html
- DNS ASK www.91##ok.com
- DNS ASK lm.##ilequ.com
- DNS ASK wo####o.qiniudn.com
- DNS ASK tj.###ingzhihui.com
- DNS ASK do##.jdrili.com
- DNS ASK dl.###emeitu.com
- DNS ASK tv.###ingzhihui.com
- DNS ASK j1##.#inaapp.com
- DNS ASK so##.doyo.cn
- DNS ASK do##.u5c.net
- DNS ASK do###.flashget.com
- DNS ASK pt.#00e.net
- DNS ASK ff###.qiniudn.com
- DNS ASK as######.###rwqer.com.weqrqwe.mab.lzgzs.com
- DNS ASK up####.aiqingzhihui.com
- DNS ASK cl####.jxdcw.com
- DNS ASK do##.##aoxinrili.com
- DNS ASK cl###.t3nlink.com
- DNS ASK do####ad.wallba.com
- DNS ASK www.sf##y.net
- DNS ASK pl##.lzgzs.com
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: '(null)' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: '3d43sdf2fzf2' WindowName: '??????....'