Technical Information
- <SYSTEM32>\winlogon.exe
- <SYSTEM32>\msqjvmp32.dll
- %WINDIR%\Fontssystem\ati2evxx.exe
- <SYSTEM32>\IGB_DJOL_1019.dll
- %HOMEPATH%\motou.exe
- %HOMEPATH%\smss.exe
- <SYSTEM32>\FTCCompress.dll
- %WINDIR%\kfnrthoh.dll
- %WINDIR%\wiasoisao.exe
- <DRIVERS>\phy.sys
- C:\Documents and Settings\LocalService\Local Settings\Temp\tmp3A.tmp
- <SYSTEM32>\XSXCompress.dll
- %WINDIR%\kiefncol.dll
- <DRIVERS>\nvscv32.exe
- %PROGRAM_FILES%\Yahoo!\Messenger\ymsgr_tray.exe
- <SYSTEM32>\RxpMoN.Exe
- <SYSTEM32>\ae781.exe
- <SYSTEM32>\rundllforour.exe
- <DRIVERS>\ncscv32.exe
- %WINDIR%\system\dd.exe
- %WINDIR%\system\arp.exe
- %WINDIR%\system\C0NIME.EXE
- <SYSTEM32>\zxarps.exe
- %WINDIR%\system\motou.exe
- %WINDIR%\system\smss.exe
- %PROGRAM_FILES%\ctfmonl.exe
- <SYSTEM32>\naijihzeuyouhz.dll
- <SYSTEM32>\ijougiemnaw.dll
- <SYSTEM32>\NNDCompress.dll
- %WINDIR%\Fonts\gjcsdzc.exe
- %WINDIR%\Fonts\rsjzbsp.exe
- <SYSTEM32>\gnaixnauhuoyizqq.dll
- %WINDIR%\sjswxu.exe
- %WINDIR%\frhhusyk.exe
- <SYSTEM32>\mstfhncn32.dll
- <SYSTEM32>\auhad.dll
- <SYSTEM32>\oadnew.dll
- <DRIVERS>\usbine.sys
- <SYSTEM32>\gnolnait.dll
- <SYSTEM32>\jcinqj.dll
- <SYSTEM32>\bauhgnem.dll
- <SYSTEM32>\fgqadw.dll
- <SYSTEM32>\ogykcx.dll
- <SYSTEM32>\NBNCompress.dll
- %WINDIR%\Fonts\system\ati2evxx.exe
- %PROGRAM_FILES%\Internet Explorer\PLUGINS\Sy_Win7k.Jmp
- <SYSTEM32>\wxptdi.sys
- <SYSTEM32>\caugfe.dll
- %WINDIR%\Fonts\raqjntl.exe
- <SYSTEM32>\usrinit.exe
- <SYSTEM32>\visin.exe
- <SYSTEM32>\mydata.exe
- <SYSTEM32>\moyu103.dll
- <SYSTEM32>\Ravasktao.dll
- %PROGRAM_FILES%\Internet Explorer\PLUGINS\System64.Sys
- <DRIVERS>\usbinte.sys
- %TEMP%\bofang.dll
- %TEMP%\GTIAPI.dll
- %TEMP%\hbcmd.dll
- <SYSTEM32>\upnpsvc.exe
- <SYSTEM32>\UPnPSvc.dll
- %TEMP%\009.mdb
- %TEMP%\ie.exe
- %TEMP%\ie.vbs
- <SYSTEM32>\love.exe
- <SYSTEM32>\ShellDown.exe
- %WINDIR%\Help\B7C8A6484EE3.dll
- %WINDIR%\Help\B7C8A6484EE3.exe
- <SYSTEM32>\ztinetzt.exe
- <SYSTEM32>\ztinetzt.dll
- <SYSTEM32>\Ravasktao.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\abc.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\abc[1].exe
- %CommonProgramFiles%\Microsoft Shared\MSInfo\NewTemp.dll
- %TEMP%\IECONFIG.EXE
- <SYSTEM32>\7df9.dll
- <SYSTEM32>\91b6.dll
- <SYSTEM32>\AE9C6AE4.EXE
- %WINDIR%\preupd.dll
- <SYSTEM32>\1-716696
- <SYSTEM32>\5E9F0D5.DLL
- %WINDIR%\upxdnd.exe
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\isignup.dll
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\isignup.sys
- <SYSTEM32>\ctfnom.exe
- <SYSTEM32>\df91.dll
- <SYSTEM32>\f91b.exe
- %TEMP%\SPy.exe
- %TEMP%\SVCH0ST.exe
- %TEMP%\zhu3.com
- %TEMP%\lfrmewrk.exe
- %TEMP%\mhso.exe
- %TEMP%\RGInstall.dll
- %WINDIR%\e4603.cfg
- %WINDIR%\IMEINPUTS.EXE
- %WINDIR%\msccrt.exe
- %WINDIR%\0e460.dat
- %WINDIR%\4603f.avi
- %WINDIR%\603fa.jpg
- <SYSTEM32>\msbq.exe
- %PROGRAM_FILES%\IEHome.exe
- C:\Gurnonb.exe
- %WINDIR%\windows.ext
- <SYSTEM32>\1ng5.exe
- <SYSTEM32>\10.ext
- <SYSTEM32>\kandofttk.exe
- %WINDIR%\Temp\safesys.exe
- %WINDIR%\Temp\safesys(1).exe
- C:\XoreitD.exe
- C:\donesc.exe
- <SYSTEM32>\xsiscok.exe
- %PROGRAM_FILES%\Windows NT\system\wdfmgr.exe
- <SYSTEM32>\lenschk.exe
- <SYSTEM32>\verclsid.exe
- <SYSTEM32>\pksetexd.exe
- <SYSTEM32>\kvtrwkcc.exe
- <SYSTEM32>\System.exe
- %PROGRAM_FILES%\Windows NT\system\asdfghjkl.exe
- %PROGRAM_FILES%\Counter\Counter.exe
- C:\KMPlayir.exe
- %WINDIR%\547661M.exe
- C:\Kuwoi.exe
- <SYSTEM32>\TL.exe
- %TEMP%\winnjqo.exe
- <SYSTEM32>\qhilyn.bat
- <SYSTEM32>\qbligir.bat
- <SYSTEM32>\vtnyusfs.bat
- <SYSTEM32>\idzam.exe
- %APPDATA%\a.exe
- <SYSTEM32>\tdsrpsh.exe
- <DRIVERS>\fkugv.sys
- <SYSTEM32>\ac97ldr.dll
- <SYSTEM32>\gwchk32.dll
- <SYSTEM32>\video.exe
- %WINDIR%\nnweb\0.exe
- <DRIVERS>\pcidump.sys
- %WINDIR%\faly.exe
- %WINDIR%\71M.exe
- <SYSTEM32>\szace.exe
- %TEMP%\winbbtih.exe
- %ALLUSERSPROFILE%\ApplicationData\Microsoft\Crypto\common32.exe
- <SYSTEM32>\takzs.exe
- %WINDIR%\53M.exe
- %WINDIR%\950312_1945888001x.exe
- <SYSTEM32>\C0NIMEO.exe
- <SYSTEM32>\a1.exe
- %PROGRAM_FILES%\Microsoft Office\SYSTEM\sysbar.exe
- %WINDIR%\ime\IMJPMIG6.exe
- %WINDIR%\Fonts\system\dd.exe
- %PROGRAM_FILES%\Internet Explorer\OnlO0r.bak
- %PROGRAM_FILES%\Internet Explorer\OnlO0r.dll
- <SYSTEM32>\iemnaw.dll
- C:\Documents and Settings\Owner\motou.exe
- C:\Documents and Settings\Owner\smss.exe
- <SYSTEM32>\qzdoor0.dll
- <SYSTEM32>\cmdow.exe
- <SYSTEM32>\qsdoor0.dll
- %PROGRAM_FILES%\Internet Explorer\OnlO0r.obk
- %CommonProgramFiles%\fjOs0r.dll
- <SYSTEM32>\qqdoor0.dll
- <SYSTEM32>\niluw.dll
- <SYSTEM32>\a.exe
- C:\Documents and Settings\LocalService\Local Settings\Temp\tmp33.tmp
- <SYSTEM32>\dpuxlp.dll
- <SYSTEM32>\kawdiaz.exe
- <SYSTEM32>\nuygnef.dll
- %WINDIR%\Fonts\avzxost.exe
- <SYSTEM32>\xwwees.dll
- <SYSTEM32>\vzbcgt.dll
- %WINDIR%\Fonts\jsqxczc.exe
- %WINDIR%\Fonts\gjtmbzc.exe
- %WINDIR%\Fonts\rarjftl.exe
- <SYSTEM32>\fhdoor0.dll
- %WINDIR%\dpgqh.exe
- <SYSTEM32>\rxux15.exe
- <SYSTEM32>\qxfelk.exe
- <SYSTEM32>\HBmhly.exe
- <SYSTEM32>\eput1.exe
- <SYSTEM32>\lqcr25.exe
- %WINDIR%\Downloaded Program Files\ThunderAdvise.dll
- %WINDIR%\AppPatch\DesktopWin.dll
- <DRIVERS>\suchost.exe
- %WINDIR%\sysocmgr.dll
- %WINDIR%\Update.dll
- %PROGRAM_FILES%\Messenger\msgmr.dll
- %WINDIR%\fly.exe
- %WINDIR%\poor.exe
- <SYSTEM32>\qqdoor1.dll
- C:\ntdelect.com
- <SYSTEM32>\kavo.exe
- <SYSTEM32>\fly.exe
- %WINDIR%\eylpw.exe
- <SYSTEM32>\83680.exe
- %WINDIR%\ruzi.exe
- <SYSTEM32>\qzdoor1.dll
- <SYSTEM32>\qsdoor1.dll
- <SYSTEM32>\fhdoor1.dll
- <SYSTEM32>\ShellDown.dll
- <SYSTEM32>\nslookupi.exe
- %WINDIR%\rising721.exe
- %WINDIR%\Help\69GH0BNS.dll
- <SYSTEM32>\systemt.exe
- %WINDIR%\Installer\service.exe
- %WINDIR%\KSVSvc.exe
- %WINDIR%\Debug\UserMode\32BB5B6.exe
- %WINDIR%\~tmp6266.exe
- %WINDIR%\java\classes\66A75.exe
- %WINDIR%\Help\69GH0BNS.exe
- %WINDIR%\Hacker.com.cn.exe
- %WINDIR%\Debug\UserMode\32BB5B6.dll
- %WINDIR%\cmdbcs.exe
- %WINDIR%\wsvs.exe
- <SYSTEM32>\hotpmsta.exe
- <SYSTEM32>\Gjzos.dll
- %WINDIR%\wsttrs.exe
- %WINDIR%\mppds.exe
- <SYSTEM32>\kerner0826.dll
- <SYSTEM32>\kerner0826IE.dll
- <SYSTEM32>\systemm.exe
- <SYSTEM32>\hotpmsta.dat
- <SYSTEM32>\kerne10904.dll
- <SYSTEM32>\kerne10916.dll
- %WINDIR%\java\classes\66A75.dll
- %TEMP%\ztso0.exe
- %TEMP%\fyso0.exe
- %TEMP%\jtso0.exe
- %TEMP%\qjso0.exe
- %TEMP%\wlso0.exe
- %TEMP%\tlso0.exe
- %TEMP%\mhso0.dll
- %TEMP%\daso0.dll
- %TEMP%\woso0.dll
- %TEMP%\wgso0.exe
- %TEMP%\rxso0.exe
- %TEMP%\wdso0.exe
- %WINDIR%\Debug\UserMode\8C00D.dll
- %WINDIR%\Debug\UserMode\8C00D.exe
- %WINDIR%\Debug\UserMode\3CA549D.dll
- C:\NTDETEC.exe
- %TEMP%\gfdgj45.com
- %WINDIR%\~tmp3464.exe
- %TEMP%\daso0.exe
- %TEMP%\woso0.exe
- %TEMP%\wmso0.exe
- %WINDIR%\Debug\UserMode\3CA549D.exe
- %TEMP%\svchost.exe
- %TEMP%\mhso0.exe
- <SYSTEM32>\FuckJacks.exe
- <SYSTEM32>\SVCH0ST.exe
- %WINDIR%\mhsystem.exe
- %WINDIR%\nvscv32.exe
- <DRIVERS>\spoclsv.exe
- <DRIVERS>\spo0lsv.exe
- %WINDIR%\logo.exe
- %WINDIR%\uninstall\rundl132.exe
- C:\zhanlang.exe
- %WINDIR%\kerner0826.exe
- %WINDIR%\kerner10916.exe
- %WINDIR%\logo1.exe
- %WINDIR%\logo_1.exe
- %WINDIR%\KILL.EXE
- %WINDIR%\rose.exe
- %WINDIR%\logo1_.exe
- %WINDIR%\rundl132.exe
- %WINDIR%\logo_.exe
- %WINDIR%\alga.exe
- %WINDIR%\iexp1ore.exe
- %WINDIR%\winlog0n.exe
- %WINDIR%\sxs.exe
- %WINDIR%\rundll32.exe
- %WINDIR%\avp.exe
- C:\zhanlang.vbs
- %WINDIR%\system\internat.exe
- %WINDIR%\system\SYSTEM32.vxd
- %WINDIR%\system\WPC.DLL
- %WINDIR%\system\C.dll
- %WINDIR%\system\svchost.exe
- %WINDIR%\system\internat.exe.tmp
- <SYSTEM32>\mppds.dll
- <SYSTEM32>\wsvs.dll
- <SYSTEM32>\wsttrs.dll
- %WINDIR%\system\icedate.dat
- <SYSTEM32>\ProcSpy.dll
- <SYSTEM32>\cmdbcs.dll
- <SYSTEM32>\msccrt.dll
- %WINDIR%\system\1.exe
- <SYSTEM32>\1.exe
- <SYSTEM32>\copymsi.exe
- <SYSTEM32>\win1ogoin.exe
- <SYSTEM32>\lesosn.exe
- %WINDIR%\system\IceHBO.dll
- %WINDIR%\system\taskmgr.exe
- %WINDIR%\system\7.exe
- %WINDIR%\system\logo_1.exe
- %WINDIR%\system\cmd.dll
- %WINDIR%\system\taskmgr.exe.tmp
- <SYSTEM32>\cmdbcs.exe
- <SYSTEM32>\nwizAsktao.dll
- <SYSTEM32>\nwizAsktao.exe
- <SYSTEM32>\mh102.exe
- <SYSTEM32>\nwizwmsjs.dll
- <SYSTEM32>\nwizwmsjs.exe
- <SYSTEM32>\nwiztlbb.dll
- <SYSTEM32>\nwiztlbb.exe
- <SYSTEM32>\upxdnd.dll
- <SYSTEM32>\nwizqjsj.dll
- <SYSTEM32>\nwizqjsj.exe
- <SYSTEM32>\mppds.exe
- <SYSTEM32>\Logo1_.exe
- <SYSTEM32>\rundl132.exe
- <SYSTEM32>\bootconf.exe
- <SYSTEM32>\ShellExt\svchs0t.exe
- %WINDIR%\bootconf.exe
- %WINDIR%\dll.dll
- <SYSTEM32>\ouvjwsc.exe
- %CommonProgramFiles%\Microsoft Shared\MSInfo\SysWFGQQ2.dll
- <SYSTEM32>\mh102.dll
- <SYSTEM32>\kill.exe
- <SYSTEM32>\sws32.dll
- <SYSTEM32>\dtstorp.exe
- <SYSTEM32>\upxdnd.exe
- %WINDIR%\Web\printers\images\fsfwqads.dll
- %WINDIR%\Web\printers\images\fsfwqads.exe
- C:\pageflieshz.exe
- %PROGRAM_FILES%\Internet Explorer\romdrivers.bkk
- %WINDIR%\Web\printers\images\35B88B196.dll
- %WINDIR%\Web\printers\images\35B88B196.exe
- %WINDIR%\Help\2HJSBC19.exe
- %PROGRAM_FILES%\Internet Explorer\ie2.exe
- <SYSTEM32>\dlyy.dll
- %CommonProgramFiles%\win.exe
- %WINDIR%\~tmp4522.exe
- %WINDIR%\Help\2HJSBC19.dll
- <SYSTEM32>\csvchost.exe
- <SYSTEM32>\cspoolsv.exe
- <SYSTEM32>\clsass.exe
- <SYSTEM32>\nwizmhxy.dll
- <SYSTEM32>\qjsj100.dll
- <SYSTEM32>\nwizmhxy.exe
- %WINDIR%\Installer\services.exee
- %TEMP%\uncrmwyb.dll
- %PROGRAM_FILES%\Internet Explorer\romdrivers.dll
- %WINDIR%\system\wdfngr.exe
- %WINDIR%\CMD.DLL
- %WINDIR%\TASKMSN.exe
- %WINDIR%\Help\AA304E150D0C.exe
- %WINDIR%\Web\printers\images\59594F8550.dll
- %WINDIR%\Web\printers\images\59594F8550.exe
- %WINDIR%\Help\90GTUABC.dll
- %WINDIR%\Help\90GTUABC.exe
- %WINDIR%\Help\AA304E150D0C.dll
- %WINDIR%\Debug\UserMode\8508D.exe
- %WINDIR%\rising659.exe
- %WINDIR%\winlogone.exe
- %WINDIR%\Debug\UserMode\3083516.dll
- %WINDIR%\Debug\UserMode\3083516.exe
- %WINDIR%\Debug\UserMode\8508D.dll
- %TEMP%\tlso0.dll
- %TEMP%\ztso0.dll
- %TEMP%\fyso0.dll
- %TEMP%\wmso0.dll
- %TEMP%\qjso0.dll
- %TEMP%\wlso0.dll
- %TEMP%\wdso0.dll
- %WINDIR%\Help\019JDNCT.dll
- %WINDIR%\Help\019JDNCT.exe
- %TEMP%\jtso0.dll
- %TEMP%\wgso0.dll
- %TEMP%\rxso0.dll
- %WINDIR%\rising413.exe
- %WINDIR%\1.com
- %WINDIR%\exerouter.exe
- %WINDIR%\EXP10RER.com
- <SYSTEM32>\od2media.dll
- <SYSTEM32>\winsp2.exe
- C:\Shell.exe
- %WINDIR%\vdll.dll
- %WINDIR%\sws32.dll
- <SYSTEM32>\wydll.dll
- %WINDIR%\finders.com
- %WINDIR%\Shell.sys
- %WINDIR%\smss.exe
- %HOMEPATH%\Desktop\mlang.dll
- <SYSTEM32>\tf2sound.dll
- <SYSTEM32>\rsvp32_2.dll
- %WINDIR%\rising613.exe
- %WINDIR%\winvar.dll
- %TEMP%\winlogin.exe
- <SYSTEM32>\msvcrl.dll
- <SYSTEM32>\sporder.dll
- <SYSTEM32>\od7media.dll
- <SYSTEM32>\6to4svcr.exe
- <SYSTEM32>\77089387.dat
- <SYSTEM32>\ipv6monl.dll
- ClassName: 'MS_WINHELP' WindowName: '(null)'