Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\Zcom УйАЦ.lnk
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%PROGRAM_FILES%\Zcom\skin.dll' = '%PROGRAM_FILES%\Zcom\skin.dll:*:Enabled:zcom»Ґ¶ЇУйАЦЖЅМЁ'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%PROGRAM_FILES%\Zcom\ZComService.exe' = '%PROGRAM_FILES%\Zcom\ZComService.exe:*:Enabled:zcom»Ґ¶ЇУйАЦЖЅМЁ'
- %PROGRAM_FILES%\Zcom\skin.dll hwnd:65762 tcpport:2380 udpport:4480
- %PROGRAM_FILES%\Zcom\ZComService.exe /i
- <SYSTEM32>\netsh.exe firewall set allowedprogram "%PROGRAM_FILES%\Zcom\~update.exe" zcom»Ґ¶ЇУйАЦЖЅМЁ ENABLE
- <SYSTEM32>\netsh.exe firewall set allowedprogram "%PROGRAM_FILES%\Zcom\ZComService.exe" zcom»Ґ¶ЇУйАЦЖЅМЁ ENABLE
- <SYSTEM32>\netsh.exe firewall set allowedprogram "%PROGRAM_FILES%\Zcom\skin.dll" zcom»Ґ¶ЇУйАЦЖЅМЁ ENABLE
- %PROGRAM_FILES%\Zcom\Client\help\img\no03.png
- %PROGRAM_FILES%\Zcom\Client\help\img\no02.png
- %PROGRAM_FILES%\Zcom\Client\help\img\no01.png
- %PROGRAM_FILES%\Zcom\Client\help\img\no04.png
- %PROGRAM_FILES%\Zcom\Client\help\img\no07.png
- %PROGRAM_FILES%\Zcom\Client\help\img\no06.png
- %PROGRAM_FILES%\Zcom\Client\help\img\no05.png
- %PROGRAM_FILES%\Zcom\Client\help\img\help.png
- %PROGRAM_FILES%\Zcom\Client\help\img\help.bg.png
- %PROGRAM_FILES%\Zcom\Client\help\img\help-1_clip_image001_0000.gif
- %PROGRAM_FILES%\Zcom\Client\help\img\item.png
- %PROGRAM_FILES%\Zcom\Client\help\img\myquestion.png
- %PROGRAM_FILES%\Zcom\Client\help\img\line2.png
- %PROGRAM_FILES%\Zcom\Client\help\img\line.png
- %PROGRAM_FILES%\Zcom\Client\help\img\sign02.png
- %PROGRAM_FILES%\Zcom\Client\help\img\sign01.png
- %PROGRAM_FILES%\Zcom\Client\help\img\shugui06.png
- %PROGRAM_FILES%\Zcom\Client\help\img\sign03.png
- %PROGRAM_FILES%\Zcom\Client\schedule\schedule.css
- %PROGRAM_FILES%\Zcom\Client\help\img\sign05.png
- %PROGRAM_FILES%\Zcom\Client\help\img\sign04.png
- %PROGRAM_FILES%\Zcom\Client\help\img\schedule.png
- %PROGRAM_FILES%\Zcom\Client\help\img\quiz.bg.png
- %PROGRAM_FILES%\Zcom\Client\help\img\nonLink.png
- %PROGRAM_FILES%\Zcom\Client\help\img\shugui01.png
- %PROGRAM_FILES%\Zcom\Client\help\img\shugui05.png
- %PROGRAM_FILES%\Zcom\Client\help\img\shugui03.png
- %PROGRAM_FILES%\Zcom\Client\help\img\shugui02.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\magsub_icon.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\magbar_unsub_on.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\magbar_unsub.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\nodown_offline.gif
- %PROGRAM_FILES%\Zcom\Client\doc\img\tour_title.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\tour_link.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\right_p_title.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\magbar_del_on.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\magbar_del.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\mag_icon.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\magbar_open.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\magbar_sub_on.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\magbar_sub.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\magbar_open_on.png
- %PROGRAM_FILES%\Zcom\Client\help\img\clip_image037.gif
- %PROGRAM_FILES%\Zcom\Client\help\img\bookcase.png
- %PROGRAM_FILES%\Zcom\Client\help\img\allquestion.png
- %PROGRAM_FILES%\Zcom\Client\help\img\clip_image038.gif
- %PROGRAM_FILES%\Zcom\Client\help\img\config.png
- %PROGRAM_FILES%\Zcom\Client\help\img\clip_image045.jpg
- %PROGRAM_FILES%\Zcom\Client\help\img\clip_image041.jpg
- %PROGRAM_FILES%\Zcom\Client\doc\img\wait.gif
- %PROGRAM_FILES%\Zcom\Client\doc\img\type_on.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\type_off.png
- %PROGRAM_FILES%\Zcom\Client\help\help-1.html
- %PROGRAM_FILES%\Zcom\Client\help\nonLink.html
- %PROGRAM_FILES%\Zcom\Client\help\help.html
- %PROGRAM_FILES%\Zcom\Client\help\help.css
- %PROGRAM_FILES%\Zcom\skin.dll
- %PROGRAM_FILES%\Zcom\ZComService.exe
- %PROGRAM_FILES%\Zcom\skin\blue\p_skin.ini
- %PROGRAM_FILES%\Zcom\oem.xml
- %PROGRAM_FILES%\Zcom\index.html
- %PROGRAM_FILES%\Zcom\Licence.txt
- %PROGRAM_FILES%\Zcom\updateConfig.xml
- %PROGRAM_FILES%\Zcom\skin\blue\p_quit_false.bmp
- %PROGRAM_FILES%\Zcom\skin\blue\p_finsh_view.bmp
- %PROGRAM_FILES%\Zcom\skin\blue\p_finsh_more.bmp
- %PROGRAM_FILES%\Zcom\skin\blue\p_quit_no.bmp
- %PROGRAM_FILES%\Zcom\skin\blue\p_schedule.bmp
- %PROGRAM_FILES%\Zcom\skin\blue\p_quit_yes.bmp
- %PROGRAM_FILES%\Zcom\skin\blue\p_quit_true.bmp
- %HOMEPATH%\Start Menu\Programs\Zcom\·ГОКzcomНшХѕ.lnk
- %HOMEPATH%\Start Menu\Programs\Zcom\Р¶ФШ Zcom УйАЦ.lnk
- %HOMEPATH%\Start Menu\Programs\Zcom\Zcom УйАЦ.lnk
- %PROGRAM_FILES%\Zcom\uninst.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\0[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\d2a65e6ef78160f8b520c75f68a61e5e[1]
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\d2a65e6ef78160f8b520c75f68a61e5e[1]
- %PROGRAM_FILES%\Zcom\downloads\Category.xml
- %PROGRAM_FILES%\Zcom\ZComAgent.dll
- %PROGRAM_FILES%\Zcom\ZcomUpdate.exe
- %PROGRAM_FILES%\Zcom\downloads\Record.xml
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Zcom УйАЦ.lnk
- %HOMEPATH%\Desktop\Zcom УйАЦ.lnk
- %PROGRAM_FILES%\Zcom\downloads\SubCategory.xml
- %PROGRAM_FILES%\Zcom\Client\schedule\img\stoptask.png
- %PROGRAM_FILES%\Zcom\Client\schedule\img\stop.png
- %PROGRAM_FILES%\Zcom\Client\schedule\img\start.png
- %PROGRAM_FILES%\Zcom\dat\Category
- %PROGRAM_FILES%\Zcom\src\Noname.JPG
- %PROGRAM_FILES%\Zcom\dat\SubCategory
- %PROGRAM_FILES%\Zcom\dat\Record
- %PROGRAM_FILES%\Zcom\Client\schedule\img\download.dot.png
- %PROGRAM_FILES%\Zcom\Client\schedule\img\cancletask.png
- %PROGRAM_FILES%\Zcom\Client\schedule\schedule.html
- %PROGRAM_FILES%\Zcom\Client\schedule\img\percentbar.gif
- %PROGRAM_FILES%\Zcom\Client\schedule\img\resumetask.png
- %PROGRAM_FILES%\Zcom\Client\schedule\img\read.png
- %PROGRAM_FILES%\Zcom\Client\schedule\img\percentbg.gif
- %PROGRAM_FILES%\Zcom\skin\blue\p_back_finsh.bmp
- %PROGRAM_FILES%\Zcom\skin\blue\p_back_close.bmp
- %PROGRAM_FILES%\Zcom\skin\blue\p_back.bmp
- %PROGRAM_FILES%\Zcom\skin\blue\p_back_schedule.bmp
- %PROGRAM_FILES%\Zcom\skin\blue\p_close_over.bmp
- %PROGRAM_FILES%\Zcom\skin\blue\p_close_normal.bmp
- %PROGRAM_FILES%\Zcom\skin\blue\p_close_down.bmp
- %PROGRAM_FILES%\Zcom\src\Thumbs.db
- %PROGRAM_FILES%\Zcom\src\Noname.bmp
- %PROGRAM_FILES%\Zcom\src\Noname.PNG
- %PROGRAM_FILES%\Zcom\src\menu.bmp
- %PROGRAM_FILES%\Zcom\skin\tray.ico
- %PROGRAM_FILES%\Zcom\skin\default.ini
- %PROGRAM_FILES%\Zcom\zcom-cfg\zcom-pref.ini
- %PROGRAM_FILES%\Zcom\Client\doc\img\line_readpage.png
- %PROGRAM_FILES%\Zcom\Client\common\linkArrow.png
- %PROGRAM_FILES%\Zcom\Client\common\link.input.png
- %PROGRAM_FILES%\Zcom\Client\common\link.hover.bg.png
- %PROGRAM_FILES%\Zcom\Client\common\logo.png
- %PROGRAM_FILES%\Zcom\Client\common\main1.bg.png
- %PROGRAM_FILES%\Zcom\Client\common\main.css
- %PROGRAM_FILES%\Zcom\Client\common\main.bg.png
- %PROGRAM_FILES%\Zcom\Client\common\header.css
- %PROGRAM_FILES%\Zcom\Client\common\footer.css
- %PROGRAM_FILES%\Zcom\Client\common\footer.bg.png
- %PROGRAM_FILES%\Zcom\Client\common\homepage.png
- %PROGRAM_FILES%\Zcom\Client\common\link.div.bg.png
- %PROGRAM_FILES%\Zcom\Client\common\link.bg.png
- %PROGRAM_FILES%\Zcom\Client\common\indicator.gif
- %PROGRAM_FILES%\Zcom\Client\common\quiz.png
- %PROGRAM_FILES%\Zcom\Client\common\quiz.hover.png
- %PROGRAM_FILES%\Zcom\Client\common\qq.service.png
- %PROGRAM_FILES%\Zcom\Client\common\search.hover.png
- %PROGRAM_FILES%\Zcom\Client\common\window.js
- %PROGRAM_FILES%\Zcom\Client\common\warn.png
- %PROGRAM_FILES%\Zcom\Client\common\search.png
- %PROGRAM_FILES%\Zcom\Client\common\nave.link.selected.png
- %PROGRAM_FILES%\Zcom\Client\common\nav.page.png
- %PROGRAM_FILES%\Zcom\Client\common\nav.bg.png
- %PROGRAM_FILES%\Zcom\Client\common\noImg.PNG
- %PROGRAM_FILES%\Zcom\Client\common\qq.png
- %PROGRAM_FILES%\Zcom\Client\common\prototype.js
- %PROGRAM_FILES%\Zcom\Client\common\online.js
- %PROGRAM_FILES%\Zcom\Client\alert\img\arrowPreLink.jpg
- %PROGRAM_FILES%\Zcom\Client\alert\img\arrowPreLink.hover.jpg
- %PROGRAM_FILES%\Zcom\Client\alert\img\arrowNextlink.jpg
- %PROGRAM_FILES%\Zcom\Client\alert\img\arrowPreNolink.jpg
- %PROGRAM_FILES%\Zcom\Client\alert\img\over.JPG
- %PROGRAM_FILES%\Zcom\Client\alert\img\nomal.JPG
- %PROGRAM_FILES%\Zcom\Client\alert\img\bg.jpg
- %PROGRAM_FILES%\Zcom\Client\alert\readAlert.html
- %PROGRAM_FILES%\Zcom\Client\alert\alert.js
- %TEMP%\nsp2.tmp\System.dll
- %PROGRAM_FILES%\Zcom\Client\alert\rss.css
- %PROGRAM_FILES%\Zcom\Client\alert\img\arrowNextlink.hover.jpg
- %PROGRAM_FILES%\Zcom\Client\alert\img\arrowNextNoLink.jpg
- %PROGRAM_FILES%\Zcom\Client\alert\unread.xsl
- %PROGRAM_FILES%\Zcom\Client\common\check_online.gif
- %PROGRAM_FILES%\Zcom\Client\common\cancel.png
- %PROGRAM_FILES%\Zcom\Client\common\cancel.hover.png
- %PROGRAM_FILES%\Zcom\Client\common\client.css
- %PROGRAM_FILES%\Zcom\Client\common\favicon.ico
- %PROGRAM_FILES%\Zcom\Client\common\confirm.png
- %PROGRAM_FILES%\Zcom\Client\common\confirm.hover.png
- %PROGRAM_FILES%\Zcom\Client\common\alert.css
- %PROGRAM_FILES%\Zcom\Client\common\Zcom.Client.js
- %PROGRAM_FILES%\Zcom\Client\alert\img\read.jpg
- %PROGRAM_FILES%\Zcom\Client\common\background_total.png
- %PROGRAM_FILES%\Zcom\Client\common\button.png
- %PROGRAM_FILES%\Zcom\Client\common\button.hover.png
- %PROGRAM_FILES%\Zcom\Client\common\bubble-arrow.png
- %PROGRAM_FILES%\Zcom\Client\doc\subcategory.xsl
- %PROGRAM_FILES%\Zcom\Client\doc\style.css
- %PROGRAM_FILES%\Zcom\Client\doc\record_unread.xsl
- %PROGRAM_FILES%\Zcom\Client\doc\svn_info.xsl
- %PROGRAM_FILES%\Zcom\Client\doc\img\bluedot.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\background_total.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\background.png
- %PROGRAM_FILES%\Zcom\Client\doc\item.xsl
- %PROGRAM_FILES%\Zcom\Client\doc\drawitem.xsl
- %PROGRAM_FILES%\Zcom\Client\doc\doc_info.xml
- %PROGRAM_FILES%\Zcom\Client\doc\jscript.js
- %PROGRAM_FILES%\Zcom\Client\doc\record_main.xsl
- %PROGRAM_FILES%\Zcom\Client\doc\record.xsl
- %PROGRAM_FILES%\Zcom\Client\doc\left.xsl
- %PROGRAM_FILES%\Zcom\Client\doc\img\icon_unread_bg.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\icon_unread.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\icon_read_bg.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\left_menu_sub_off.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\left_menu_sub_on_s.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\left_menu_sub_on.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\left_menu_sub_off_s.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\comment.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\bydate_select.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\bydate_icon.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\grayborder.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\icon_read.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\icon_popup.png
- %PROGRAM_FILES%\Zcom\Client\doc\img\icon_disk.png
- %PROGRAM_FILES%\Zcom\Client\common\zcom.alert\top_left.gif
- %PROGRAM_FILES%\Zcom\Client\common\zcom.alert\top.gif
- %PROGRAM_FILES%\Zcom\Client\common\zcom.alert\right.gif
- %PROGRAM_FILES%\Zcom\Client\common\zcom.alert\top_right.gif
- %PROGRAM_FILES%\Zcom\Client\config\img\arrowDown.png
- %PROGRAM_FILES%\Zcom\Client\config\config.html
- %PROGRAM_FILES%\Zcom\Client\config\config.css
- %PROGRAM_FILES%\Zcom\Client\common\zcom.alert\bottom.gif
- %PROGRAM_FILES%\Zcom\Client\common\zcom.alert\Thumbs.db
- %PROGRAM_FILES%\Zcom\Client\common\zcom.alert.css
- %PROGRAM_FILES%\Zcom\Client\common\zcom.alert\bottom_left.gif
- %PROGRAM_FILES%\Zcom\Client\common\zcom.alert\overlay.png
- %PROGRAM_FILES%\Zcom\Client\common\zcom.alert\left.gif
- %PROGRAM_FILES%\Zcom\Client\common\zcom.alert\bottom_right.gif
- %PROGRAM_FILES%\Zcom\Client\doc\build.js
- %PROGRAM_FILES%\Zcom\Client\config\img\saveConfig.png
- %PROGRAM_FILES%\Zcom\Client\config\img\pop.png
- %PROGRAM_FILES%\Zcom\Client\doc\class.js
- %PROGRAM_FILES%\Zcom\Client\doc\doc.html
- %PROGRAM_FILES%\Zcom\Client\doc\config.js
- %PROGRAM_FILES%\Zcom\Client\doc\common.js
- %PROGRAM_FILES%\Zcom\Client\config\img\arrowUp1.png
- %PROGRAM_FILES%\Zcom\Client\config\img\arrowUp.png
- %PROGRAM_FILES%\Zcom\Client\config\img\arrowDown1.png
- %PROGRAM_FILES%\Zcom\Client\config\img\button.hover.png
- %PROGRAM_FILES%\Zcom\Client\config\img\config.png
- %PROGRAM_FILES%\Zcom\Client\config\img\checkbox.png
- %PROGRAM_FILES%\Zcom\Client\config\img\button.png
- %TEMP%\nsp2.tmp\System.dll
- 'cl#####nfo.zcominc.com':80
- '21#.#38.233.120':53
- 'localhost':1037
- 'cl#####tat.zcominc.com':80
- cl#####nfo.zcominc.com/saveinfo/0/d2a65e6ef78160f8b520c75f68a61e5e/0
- cl#####tat.zcominc.com/clientaction/install/zcom/lite/3.41/0/00000000/d2a65e6ef78160f8b520c75f68a61e5e
- cl#####tat.zcominc.com/clientaction/clickrun/zcom/lite/3.41/0/00000000/d2a65e6ef78160f8b520c75f68a61e5e
- DNS ASK ed##che.p2p
- DNS ASK vc####.Zcom.org.cn
- DNS ASK cl#####nfo.zcominc.com
- DNS ASK cl#####tat.zcominc.com
- '23#.#55.255.250':1900
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ZComService' WindowName: ''