Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Malware-gen"
- * MalScore: 10.0
- * File Name: "VZip_724.exe"
- * File Size: 4194888
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive"
- * SHA256: "514e32919a8e2ca99cb5f5cbfcea3129e5088dc029302e01517e188cb52098cd"
- * MD5: "744c0f2cadea1e5d5e4f7132facf8f0b"
- * SHA1: "dd82259ad3fc39edf459fa8cebde0fd97d66c632"
- * SHA512: "9f3d5db10a476391acaa01c24f69a1cd8066e229d308c8b6bd924460f2d338b38d49fdd75bda361c52d59bf6ebc7181a8638359233a9ff4c8dece6b929fbc3a5"
- * CRC32: "AA2E355E"
- * SSDEEP: "98304:nczSf1JTOR+9qJfAmKa59ShS4tSTEh0uMsexyRl0YwYES:czSf1JFgfnwIwhpix8l0CES"
- * Process Execution:
- "VZip_724.exe",
- "VZipUpdate.exe",
- "regsvr32.exe",
- "regsvr32.exe",
- "services.exe",
- "VZipService.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "regsvr32.exe",
- "regsvr32.exe",
- "regsvr32.exe",
- "regsvr32.exe",
- "regsvr32.exe",
- "regsvr32.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipService.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "VZipUpdate.exe",
- "svchost.exe",
- "VZipSvcHost.exe"
- * Executed Commands:
- "\"C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe\" -inst_fix -startby=8",
- "regsvr32.exe /s \"C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll\"",
- "C:\\Windows\\system32\\regsvr32.exe /s \"C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll\"",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipService.exe",
- "C:\\Windows\\SysWOW64\\svchost.exe -k VSvcUpdateGroup",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe -auto -startby=5",
- "C:\\Users\\user\\AppData\\Roaming\\VZip\\UpdateV2\\VZipUpdate.exe -inst_update",
- "\"C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe\" -task -startby=2",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe -task -startby=2",
- "\"C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe\" -update_silence -startby=2",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe -update_silence -startby=2",
- "\"C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe\" -tid=1 -startby=2",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe -tid=1 -startby=2",
- "regsvr32.exe /s /u \"C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll\"",
- "regsvr32.exe /s \"C:\\Users\\user\\AppData\\Roaming\\VZip\\VZipRMExtern64.dll\"",
- "C:\\Windows\\system32\\regsvr32.exe /s /u \"C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll\"",
- "C:\\Users\\user\\AppData\\Roaming\\VZipZhuoMianUp\\VZipSvcHost.exe -startby=16",
- "C:\\Windows\\system32\\regsvr32.exe /s \"C:\\Users\\user\\AppData\\Roaming\\VZip\\VZipRMExtern64.dll\"",
- "\"C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe\" -tid=5 -startby=2",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe -tid=5 -startby=2"
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Attempts to connect to a dead IP:Port (5 unique times)",
- "Details":
- "IP": "221.230.141.50:443"
- "IP": "222.245.77.75:443"
- "IP": "157.185.177.205:80"
- "IP": "106.75.31.186:80"
- "IP": "157.185.163.158:443"
- "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
- "Details":
- "ioc": "www.digicert.com1"
- "Description": "Expresses interest in specific running processes",
- "Details":
- "process": "VZipUpdate.exe"
- "process": "explorer.exe"
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: VZip_724.exe, pid: 2148, offset: 0x00000000, length: 0x003fce93"
- "self_read": "process: VZip_724.exe, pid: 2148, offset: 0x0004901c, length: 0x003b3e7b"
- "self_read": "process: VZipUpdate.exe, pid: 1712, offset: 0x00114a00, length: 0x00000400"
- "self_read": "process: VZipUpdate.exe, pid: 1784, offset: 0x00000000, length: 0x004362f9"
- "self_read": "process: VZipUpdate.exe, pid: 1784, offset: 0x0004901c, length: 0x00398000"
- "self_read": "process: VZipUpdate.exe, pid: 1784, offset: 0x003e501c, length: 0x00050000"
- "self_read": "process: VZipUpdate.exe, pid: 1784, offset: 0x004362f9, length: 0x00000004"
- "self_read": "process: VZipUpdate.exe, pid: 2416, offset: 0x000c4e00, length: 0x00000400"
- "Description": "A process created a hidden window",
- "Details":
- "Process": "VZipUpdate.exe -> regsvr32.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Roaming\\VZip\\UpdateV2\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> regsvr32.exe"
- "Process": "VZipUpdate.exe -> regsvr32.exe"
- "Process": "VZipUpdate.exe -> regsvr32.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "Description": "File has been identified by 4 Antiviruses on VirusTotal as malicious",
- "Details":
- "Avast": "Win32:Malware-gen"
- "AhnLab-V3": "Trojan/Win32.Generic.C1987944"
- "VBA32": "BScope.Adware.LightSee"
- "AVG": "Win32:Malware-gen"
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Users\\user\\AppData\\Roaming\\VZip\\UpdateV2\\VZipUpdate.exe"
- "binary": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "binary": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
- "binary": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipService.exe"
- "binary": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipService.exe"
- "binary": "C:\\Users\\user\\AppData\\Roaming\\VZipZhuoMianUp\\VZipSvcHost.exe"
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "get_no_useragent": "HTTP traffic contains a GET request with no user-agent header"
- "suspicious_request": "http://down.wdmuz.com/wy/wyp1.dat"
- "suspicious_request": "http://tj.wdmuz.com/pipil.php"
- "suspicious_request": "http://down.wdmuz.com/wbpctl/wbpctl2.shjson?473339"
- "suspicious_request": "http://tj.wdmuz.com/pipia.php?data=9750af6744f09ddc3dc7b77c6886de4a"
- "suspicious_request": "http://down.wdmuz.com/img/wz/wz190720D.zip"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://down.wdmuz.com/wy/wyp1.gif"
- "url": "http://down.wdmuz.com/wy/wyp1.dat"
- "url": "http://tj.wdmuz.com/pipil.php"
- "url": "http://down.wdmuz.com/wbpctl/wbpctl2.shjson?473339"
- "url": "http://tj.wdmuz.com/pipia.php?data=9750af6744f09ddc3dc7b77c6886de4a"
- "url": "http://down.wdmuz.com/img/wz/wz190720D.zip"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: .rsrc, entropy: 6.81, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x00041200, virtual_size: 0x00041060"
- "Description": "Queries information on disks, possibly for anti-virtualization",
- "Details":
- "Description": "A process attempted to delay the analysis task by a long amount of time.",
- "Details":
- "Process": "VZipSvcHost.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
- "Process": "VZipUpdate.exe tried to sleep 34688 seconds, actually delayed analysis time by 0 seconds"
- "Process": "VZipService.exe tried to sleep 5523 seconds, actually delayed analysis time by 0 seconds"
- "Process": "svchost.exe tried to sleep 23400 seconds, actually delayed analysis time by 0 seconds"
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details":
- "Spam": "services.exe (504) called API GetSystemTimeAsFileTime 6396350 times"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "service name": "VZipService"
- "service path": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipService.exe"
- "service name": "VSvcUpdate"
- "service path": "C:\\Windows\\SysWOW64\\svchost.exe -k VSvcUpdateGroup"
- "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\ImagePath"
- "data": "C:\\Windows\\SysWOW64\\svchost.exe -k VSvcUpdateGroup"
- "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\Parameters\\ServiceDll"
- "data": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipSvcHost.dll"
- "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07\\InprocServer32\\(Default)"
- "data": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll"
- "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\E6605199-673A-4B5B-8163-1E406B1FF9B3\\InprocServer32\\(Default)"
- "data": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll"
- "Description": "Collects information about installed applications",
- "Details":
- "Program": "Microsoft Office Shared 64-bit MUI 2013"
- "Program": "Microsoft Excel MUI 2013"
- "Program": "Microsoft Outlook MUI 2013"
- "Program": "Google Chrome"
- "Program": "Notepad++"
- "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xc3\\xb1ol"
- "Program": "Adobe Flash Player 29 ActiveX"
- "Program": "Microsoft Access MUI 2013"
- "Program": "Microsoft Office 64-bit Components 2013"
- "Program": "Microsoft Office Proofing Tools 2013 - English"
- "Program": "Adobe Flash Player 29 NPAPI"
- "Program": "Adobe Acrobat Reader DC"
- "Program": "Adobe Refresh Manager"
- "Program": "\\xc3\\x8e\\xc2\\xa2\\xc3\\x91\\xc2\\xb9"
- "Program": "Microsoft Publisher MUI 2013"
- "Program": "Microsoft DCF MUI 2013"
- "Program": "Microsoft Office Shared MUI 2013"
- "Program": "Microsoft Office OSM MUI 2013"
- "Program": "Microsoft InfoPath MUI 2013"
- "Program": "Microsoft Office Shared Setup Metadata MUI 2013"
- "Program": "Outils de v\\xc3\\xa9rification linguistique 2013 de Microsoft Office\\xc2\\xa0- Fran\\xc3\\xa7ais"
- "Program": "Microsoft Word MUI 2013"
- "Program": "Google Update Helper"
- "Program": "Microsoft OneDrive"
- "Program": "Microsoft Groove MUI 2013"
- "Program": "Oracle VM VirtualBox Guest Additions 6.0.2"
- "Program": "Microsoft Office Shared 64-bit Setup Metadata MUI 2013"
- "Program": "Microsoft Access Setup Metadata MUI 2013"
- "Program": "Microsoft Office OSM UX MUI 2013"
- "Program": "Java Auto Updater"
- "Program": "Microsoft PowerPoint MUI 2013"
- "Program": "Microsoft Office Professional Plus 2013"
- "Program": "Java 8 Update 201"
- "Program": "Microsoft Office Proofing 2013"
- "Program": "Microsoft Lync MUI 2013"
- "Program": "Microsoft OneNote MUI 2013"
- "Description": "Detects VirtualBox through the presence of a registry key",
- "Details":
- "Description": "Attempts to modify browser security settings",
- "Details":
- * Started Service:
- "VZipService",
- "VSvcUpdate"
- * Mutexes:
- "VZip_install",
- "Global\\846B0D787F8CC6D5",
- "VZip_Fix",
- "06FA88EC1CA2B88D",
- "VZip-auto",
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex",
- "VZip-task",
- "61B00EC2029EC991",
- "1A0D91A871B61814",
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1",
- "846B0D787F8CC6D5",
- "31ADD72FDDB67E3D",
- "8BE8F092922D7043",
- "DBWinMutex",
- "VZipVZipSvcHost.dll",
- "D731875BB31263A9",
- "AB15260608A596B5",
- "NewsFlashFrame"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsu1DDB.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsu1DDC.tmp\\InstHlp.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsu1DDC.tmp\\System.dll",
- "C:\\Users\\user\\AppData\\Local\\VZip\\Uninst.exe",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZip.exe",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZip2.exe",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern.dll",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipKernel.dll",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipMiniNews.exe",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipMiniTray.exe",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipPd.dll",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipService.exe",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe",
- "C:\\Users\\user\\AppData\\Local\\VZip\\zip.sfx",
- "C:\\Users\\user\\AppData\\Local\\VZip\\Lang\\en.ttt",
- "C:\\Users\\user\\AppData\\Local\\VZip\\Lang\\zh-cn.txt",
- "\\??\\PIPE\\srvsvc",
- "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\\\xc3\\x8e\\xc2\\xa2\\xc3\\x91\\xc2\\xb9\\ \\xc3\\x8e\\xc2\\xa2\\xc3\\x91\\xc2\\xb9.lnk",
- "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\\\xc3\\x8e\\xc2\\xa2\\xc3\\x91\\xc2\\xb9\\\\xc3\\x90\\xc2\\xb6\\xc3\\x94\\xc3\\x98 \\xc3\\x8e\\xc2\\xa2\\xc3\\x91\\xc2\\xb9.lnk",
- "C:\\Users\\Public\\Desktop\\\\xc3\\x8e\\xc2\\xa2\\xc3\\x91\\xc2\\xb9.lnk",
- "C:\\Users\\user\\AppData\\Local\\Temp\\service_temp_report",
- "C:\\Users\\user\\AppData\\Roaming\\VZip\\UpdateV2\\VZipUpdate.exe",
- "C:\\Users\\user\\AppData\\Local\\GDIPFONTCACHEV1.DAT",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsc2161.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsr2171.tmp\\InstHlp.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsr2171.tmp\\DuiLib.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsr2171.tmp\\System.dll",
- "C:\\Users\\user\\AppData\\Local\\VZip\\DuiLib.dll",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipRMExtern.dll",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipRMExtern64.dll",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipSvcHost.dll",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipSvcHost.exe",
- "C:\\Users\\user\\AppData\\Roaming\\VZip\\Data\\VZip2",
- "C:\\Users\\user\\AppData\\Roaming\\VZipZhuoMianUp\\VZipSvcHost.exe",
- "C:\\Users\\user\\AppData\\Roaming\\VZip\\VZipRMExtern64.dll",
- "C:\\Users\\user\\AppData\\Roaming\\VZip\\Data\\wwp2",
- "C:\\Users\\user\\AppData\\LocalLow\\BubblesPop\\CheckToTips.ini",
- "C:\\Users\\user\\AppData\\LocalLow\\WeiYa\\skin1.zip",
- "C:\\Users\\user\\AppData\\LocalLow\\WeiYa\\Config.ini"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsp1CD1.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsu1DDC.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsu1DDC.tmp\\InstHlp.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsu1DDC.tmp\\System.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsu1DDC.tmp\\",
- "C:\\Users\\user\\AppData\\Roaming\\VZip\\UpdateV2\\VZipUpdate.exe",
- "C:\\Users\\user\\AppData\\Roaming\\VZip\\Update\\VZipUpdate.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsl1F7B.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsr2171.tmp",
- "C:\\Users\\user\\AppData\\Local\\VZip\\Uninst.exe",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZip.exe",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZip2.exe",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern.dll",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipKernel.dll",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipMiniNews.exe",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipMiniTray.exe",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipPd.dll",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipService.exe",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe",
- "C:\\Users\\user\\AppData\\Local\\VZip\\zip.sfx",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsr2171.tmp\\DuiLib.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsr2171.tmp\\InstHlp.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsr2171.tmp\\System.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsr2171.tmp\\",
- "C:\\Users\\user\\AppData\\Roaming\\VZip\\Data\\VZip2",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipSvcHost.exe",
- "C:\\Users\\user\\AppData\\Local\\VZip\\VZipRMExtern64.dll",
- "C:\\Users\\user\\AppData\\Roaming\\VZip\\Data\\VZip3",
- "C:\\Users\\user\\AppData\\Roaming\\VZip\\Data\\wwp2"
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\SOFTWARE\\VZip",
- "HKEY_CURRENT_USER\\Software\\VZip\\UserSID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\VZip",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\VZip\\UserSID",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\SOFTWARE\\VZip\\VZip",
- "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\QID",
- "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
- "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\AppDataPath",
- "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\isps",
- "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\InstallPath",
- "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\InstallTime",
- "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\InstallSvrTime",
- "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\Shell",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip\\DisplayName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip\\Publisher",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip\\DisplayIcon",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip\\UninstallString",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip\\DisplayVersion",
- "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\AV",
- "HKEY_CLASSES_ROOT\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07\\InprocServer32",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07\\InprocServer32\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07\\InprocServer32\\ThreadingModel",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07",
- "HKEY_CLASSES_ROOT\\*\\shellex\\ContextMenuHandlers\\VZipShell",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\shellex\\ContextMenuHandlers\\VZipShell\\(Default)",
- "HKEY_CLASSES_ROOT\\Folder\\shellex\\ContextMenuHandlers\\VZipShell",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\ContextMenuHandlers\\VZipShell\\(Default)",
- "HKEY_CLASSES_ROOT\\Directory\\shellex\\ContextMenuHandlers\\VZipShell",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\shellex\\ContextMenuHandlers\\VZipShell\\(Default)",
- "HKEY_CLASSES_ROOT\\Directory\\Background\\shellex\\ContextMenuHandlers\\VZipShell",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\Background\\shellex\\ContextMenuHandlers\\VZipShell\\(Default)",
- "HKEY_CLASSES_ROOT\\Directory\\shellex\\DragDropHandlers\\VZipShell",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\shellex\\DragDropHandlers\\VZipShell\\(Default)",
- "HKEY_CLASSES_ROOT\\Drive\\shellex\\DragDropHandlers\\VZipShell",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\DragDropHandlers\\VZipShell\\(Default)",
- "HKEY_CLASSES_ROOT\\Directory\\Background\\shellex\\DragDropHandlers\\VZipShell",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\Background\\shellex\\DragDropHandlers\\VZipShell\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\VZip Shell Extension",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\VZip Shell Extension\\(Default)",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VZipService\\Start",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VZipService\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\Start",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\ErrorControl",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\ImagePath",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\WOW64",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\ObjectName",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
- "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\Mistiming",
- "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\UpdateTime",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\SOFTWARE\\VZip\\VZipUpdate",
- "HKEY_CURRENT_USER\\Software\\VZip\\VZipUpdate\\m",
- "HKEY_CURRENT_USER\\Software\\VZip\\VZipUpdate\\dver",
- "HKEY_CURRENT_USER\\SOFTWARE\\VZipSvcHost",
- "HKEY_CURRENT_USER\\Software\\VZipSvcHost\\UserSID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\VZipSvcHost",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\VZipSvcHost\\UserSID",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\SOFTWARE\\VZipSvcHost\\VZipSvcHost",
- "HKEY_CURRENT_USER\\Software\\VZipSvcHost\\VZipSvcHost\\AppDataPath",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Svchost\\VSvcUpdateGroup",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\Parameters",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\Parameters\\ServiceDll",
- "HKEY_CURRENT_USER\\Software\\VZipSvcHost\\VZipSvcHost\\rmsrv",
- "HKEY_CURRENT_USER\\Software\\VZipSvcHost\\VZipSvcHost\\rmshell",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\VZip\\VZip\\Mistiming",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\VZip\\VZip\\StartUpTime5",
- "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\StartUpTime2",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\VZipSvcHost\\VZipSvcHost\\StartTime",
- "HKEY_CLASSES_ROOT\\CLSID\\E6605199-673A-4B5B-8163-1E406B1FF9B3",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\E6605199-673A-4B5B-8163-1E406B1FF9B3\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\E6605199-673A-4B5B-8163-1E406B1FF9B3\\InprocServer32",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\E6605199-673A-4B5B-8163-1E406B1FF9B3\\InprocServer32\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\E6605199-673A-4B5B-8163-1E406B1FF9B3\\InprocServer32\\ThreadingModel",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved\\E6605199-673A-4B5B-8163-1E406B1FF9B3",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\shellex\\ContextMenuHandlers\\VZipRMExtern",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\shellex\\ContextMenuHandlers\\VZipRMExtern\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\shellex\\ContextMenuHandlers\\VZipRMExtern",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\shellex\\ContextMenuHandlers\\VZipRMExtern\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\ContextMenuHandlers\\VZipRMExtern",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\ContextMenuHandlers\\VZipRMExtern\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\shellex\\ContextMenuHandlers\\VZipRMExtern",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\shellex\\ContextMenuHandlers\\VZipRMExtern\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\VZipRMExtern",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\VZipRMExtern\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_AJAX_CONNECTIONEVENTS\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_ENABLE_CLIPCHILDREN_OPTIMIZATION\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_MANAGE_SCRIPT_CIRCULAR_REFS\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_DOMSTORAGE\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_GPU_RENDERING\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_IVIEWOBJECTDRAW_DMLT9_WITH_GDI\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_DISABLE_LEGACY_COMPRESSION\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BLOCK_LMZ_OBJECT\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BLOCK_LMZ_SCRIPT\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_DISABLE_NAVIGATION_SOUNDS\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SCRIPTURL_MITIGATION\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SPELLCHECKING\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_STATUS_BAR_THROTTLING\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_TABBED_BROWSING\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_VALIDATE_NAVIGATE_URL\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_WEBOC_DOCUMENT_ZOOM\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_WEBOC_POPUPMANAGEMENT\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_WEBOC_MOVESIZECHILD\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_ADDON_MANAGEMENT\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_WEBSOCKET\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_WINDOW_RESTRICTIONS\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_XMLHTTP\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\StartUpTime3",
- "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\OinterValTime",
- "HKEY_CURRENT_USER\\Software\\VZip\\VZipUpdate\\otherM",
- "HKEY_CURRENT_USER\\Software\\VZip\\VZipUpdate\\oTherDver",
- "HKEY_CURRENT_USER\\Software\\WeiYa",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\Setting",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\ZZGG",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_GPU_RENDERING ",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_GPU_RENDERING \\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_IVIEWOBJECTDRAW_DMLT9_WITH_GDI ",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_IVIEWOBJECTDRAW_DMLT9_WITH_GDI \\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_NINPUT_LEGACYMODE",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_NINPUT_LEGACYMODE\\VZipUpdate.exe",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\Common",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\\\xe6\\xb4\\xbb\\xe5\\x8a\\xa82\\xe7\\xbd\\x91\\xe8\\xb5\\x9a0",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\Tag",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\ZKGG",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\CpID",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\WeiYa",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\Setting\\WPPopDate",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\Setting\\WPPopTime",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\WeiYa\\\\xe6\\xb4\\xbb\\xe5\\x8a\\xa82\\xe7\\xbd\\x91\\xe8\\xb5\\x9a0",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\\\xe6\\xb4\\xbb\\xe5\\x8a\\xa82\\xe7\\xbd\\x91\\xe8\\xb5\\x9a0\\WPPopDate",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\\\xe6\\xb4\\xbb\\xe5\\x8a\\xa82\\xe7\\xbd\\x91\\xe8\\xb5\\x9a0\\WPPopTime",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\\\xe6\\xb4\\xbb\\xe5\\x8a\\xa82\\xe7\\xbd\\x91\\xe8\\xb5\\x9a0\\20190720",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\\\xe6\\xb4\\xbb\\xe5\\x8a\\xa82\\xe7\\xbd\\x91\\xe8\\xb5\\x9a0\\PopTimes",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\UserInfo",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\UserInfo\\PopedAllTims",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\0",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\0\\20190720",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\ZKGG\\20190720",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\Setting\\PopTimes",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\Setting\\LdSkinMD5",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\WeiYa\\ExceptionCloseTimes",
- "HKEY_CURRENT_USER\\Software\\WeiYa\\Setting\\DisSelfDayV1"
- * Deleted Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07"
- * DNS Communications:
- "type": "A",
- "request": "api.zhanfukeji.cn",
- "answers":
- "data": "222.245.77.75",
- "type": "A"
- "data": "157.185.163.158",
- "type": "A"
- "data": "api.zhanfukeji.cn.wswebpic.com",
- "type": "CNAME"
- "type": "A",
- "request": "down.zhanfukeji.cn",
- "answers":
- "data": "221.230.141.50",
- "type": "A"
- "data": "down.zhanfukeji.cn.wsdvs.com",
- "type": "CNAME"
- "type": "A",
- "request": "down.wdmuz.com",
- "answers":
- "data": "down.wdmuz.com.wsglb0.com",
- "type": "CNAME"
- "data": "157.185.177.205",
- "type": "A"
- "type": "A",
- "request": "tj.wdmuz.com",
- "answers":
- "data": "106.75.31.186",
- "type": "A"
- * Domains:
- "ip": "157.185.177.205",
- "domain": "down.wdmuz.com"
- "ip": "221.230.141.50",
- "domain": "down.zhanfukeji.cn"
- "ip": "157.185.163.158",
- "domain": "api.zhanfukeji.cn"
- "ip": "106.75.31.186",
- "domain": "tj.wdmuz.com"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://down.wdmuz.com/wy/wyp1.gif",
- "user-agent": "WinHttpClient",
- "method": "GET",
- "host": "down.wdmuz.com",
- "version": "1.1",
- "path": "/wy/wyp1.gif",
- "data": "GET /wy/wyp1.gif HTTP/1.1\r\nConnection: Keep-Alive\r\nUser-Agent: WinHttpClient\r\nHost: down.wdmuz.com\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://down.wdmuz.com/wy/wyp1.dat",
- "user-agent": "",
- "method": "GET",
- "host": "down.wdmuz.com",
- "version": "1.1",
- "path": "/wy/wyp1.dat",
- "data": "GET /wy/wyp1.dat HTTP/1.1\r\nHost: down.wdmuz.com\r\nAccept: */*\r\n\r\n",
- "port": 80
- "count": 27,
- "body": "",
- "uri": "http://tj.wdmuz.com/pipil.php",
- "user-agent": "",
- "method": "GET",
- "host": "tj.wdmuz.com",
- "version": "1.1",
- "path": "/pipil.php",
- "data": "GET /pipil.php HTTP/1.1\r\nHost: tj.wdmuz.com\r\nAccept: */*\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://down.wdmuz.com/wbpctl/wbpctl2.shjson?473339",
- "user-agent": "",
- "method": "GET",
- "host": "down.wdmuz.com",
- "version": "1.1",
- "path": "/wbpctl/wbpctl2.shjson?473339",
- "data": "GET /wbpctl/wbpctl2.shjson?473339 HTTP/1.1\r\nHost: down.wdmuz.com\r\nAccept: */*\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://tj.wdmuz.com/pipia.php?data=9750af6744f09ddc3dc7b77c6886de4a",
- "user-agent": "",
- "method": "GET",
- "host": "tj.wdmuz.com",
- "version": "1.1",
- "path": "/pipia.php?data=9750af6744f09ddc3dc7b77c6886de4a",
- "data": "GET /pipia.php?data=9750af6744f09ddc3dc7b77c6886de4a HTTP/1.1\r\nHost: tj.wdmuz.com\r\nAccept: */*\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://down.wdmuz.com/img/wz/wz190720D.zip",
- "user-agent": "",
- "method": "GET",
- "host": "down.wdmuz.com",
- "version": "1.1",
- "path": "/img/wz/wz190720D.zip",
- "data": "GET /img/wz/wz190720D.zip HTTP/1.1\r\nHost: down.wdmuz.com\r\nAccept: */*\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment