Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\nsp3.tmp\Statistics.exe' = '%TEMP%\nsp3.tmp\Statistics.exe:*:En...
- '%TEMP%\nsp3.tmp\Statistics.exe' cmd=2567&ctype=1&itype=11&ver=9.15.1596.0&str1=CB24A8ACD4F5EA2C503C1DC1F2D2077E&str2=channel1&vid=AngarCl.exe&url=<File name>.exe
- %TEMP%\nsp3.tmp\pic\strongbtn.png
- %TEMP%\nsp3.tmp\pic\weakbtn.png
- %TEMP%\nsp3.tmp\pic\shadow_active.png
- %TEMP%\nsp3.tmp\pic\onekey.png
- %TEMP%\nsp3.tmp\pic\express.png
- %TEMP%\nsp3.tmp\pic\custom.png
- %TEMP%\nsp3.tmp\pic\close.png
- %TEMP%\nsp3.tmp\pic\full_bg.png
- %TEMP%\nsp3.tmp\pic\empty_bg.png
- %TEMP%\nsp3.tmp\bind.ini
- %TEMP%\nsp3.tmp\modern-wizard.bmp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\web_report[1].htm
- %TEMP%\nsp3.tmp\pcmgrdlcore.zip
- %TEMP%\nsp3.tmp\ioSpecial.ini
- %TEMP%\nsp3.tmp\pic\slogan.png
- %TEMP%\nsp3.tmp\pic\shadow_deactive.png
- %TEMP%\nsp3.tmp\pic\Minimize.png
- %TEMP%\nsp3.tmp\pic\logo.png
- %TEMP%\nsp3.tmp\Statistics.exe
- %APPDATA%\Tencent\QQLive\user.ini
- %TEMP%\nsp3.tmp\pic\bg2.png
- %TEMP%\nsp3.tmp\pic\bg1.png
- %TEMP%\nsp3.tmp\System.dll
- %TEMP%\nsp3.tmp\InstallHelper.dll
- %TEMP%\nsk2.tmp
- %TEMP%\nsp3.tmp\ProcDll.dll
- %APPDATA%\Tencent\QQLive\Log\QQLiveInstall.log
- %TEMP%\nsp3.tmp\pic\InstallingBG05.png
- %TEMP%\nsp3.tmp\pic\InstallingBG04.png
- %TEMP%\nsp3.tmp\pic\checkbox.png
- %TEMP%\nsp3.tmp\pic\browse.png
- %TEMP%\nsp3.tmp\pic\InstallingBG03.png
- %TEMP%\nsp3.tmp\pic\bg4.png
- %TEMP%\nsp3.tmp\pic\bg3.png
- %TEMP%\nsp3.tmp\pic\InstallingBG02.png
- %TEMP%\nsp3.tmp\pic\InstallingBG01.png
- 'rc##.#ideo.qq.com':80
- 'dl###1.qq.com':80
- 'localhost':1039
- http://dl###1.qq.com/qqtv/downloader/pcmgrdlcore.zip?ti#############
- http://dl###1.qq.com/qqtv/bind/bind.ini?ti#############
- http://rc##.#ideo.qq.com/web_report
- DNS ASK rc##.#ideo.qq.com
- DNS ASK dl###1.qq.com
- ClassName: '#32770' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''