paladin316

VZip_724_exe_2019-07-20_08_30.txt

Jul 20th, 2019
2,286
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 42.27 KB | None | 0 0
  1.  
  2. * MalFamily: "Malware-gen"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "VZip_724.exe"
  7. * File Size: 4194888
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive"
  9. * SHA256: "514e32919a8e2ca99cb5f5cbfcea3129e5088dc029302e01517e188cb52098cd"
  10. * MD5: "744c0f2cadea1e5d5e4f7132facf8f0b"
  11. * SHA1: "dd82259ad3fc39edf459fa8cebde0fd97d66c632"
  12. * SHA512: "9f3d5db10a476391acaa01c24f69a1cd8066e229d308c8b6bd924460f2d338b38d49fdd75bda361c52d59bf6ebc7181a8638359233a9ff4c8dece6b929fbc3a5"
  13. * CRC32: "AA2E355E"
  14. * SSDEEP: "98304:nczSf1JTOR+9qJfAmKa59ShS4tSTEh0uMsexyRl0YwYES:czSf1JFgfnwIwhpix8l0CES"
  15.  
  16. * Process Execution:
  17. "VZip_724.exe",
  18. "VZipUpdate.exe",
  19. "regsvr32.exe",
  20. "regsvr32.exe",
  21. "services.exe",
  22. "VZipService.exe",
  23. "VZipUpdate.exe",
  24. "VZipUpdate.exe",
  25. "VZipUpdate.exe",
  26. "regsvr32.exe",
  27. "regsvr32.exe",
  28. "regsvr32.exe",
  29. "regsvr32.exe",
  30. "regsvr32.exe",
  31. "regsvr32.exe",
  32. "VZipUpdate.exe",
  33. "VZipUpdate.exe",
  34. "VZipUpdate.exe",
  35. "VZipUpdate.exe",
  36. "VZipUpdate.exe",
  37. "VZipUpdate.exe",
  38. "VZipUpdate.exe",
  39. "VZipUpdate.exe",
  40. "VZipUpdate.exe",
  41. "VZipUpdate.exe",
  42. "VZipService.exe",
  43. "VZipUpdate.exe",
  44. "VZipUpdate.exe",
  45. "VZipUpdate.exe",
  46. "VZipUpdate.exe",
  47. "VZipUpdate.exe",
  48. "VZipUpdate.exe",
  49. "VZipUpdate.exe",
  50. "VZipUpdate.exe",
  51. "VZipUpdate.exe",
  52. "VZipUpdate.exe",
  53. "VZipUpdate.exe",
  54. "VZipUpdate.exe",
  55. "VZipUpdate.exe",
  56. "VZipUpdate.exe",
  57. "VZipUpdate.exe",
  58. "VZipUpdate.exe",
  59. "VZipUpdate.exe",
  60. "VZipUpdate.exe",
  61. "VZipUpdate.exe",
  62. "VZipUpdate.exe",
  63. "VZipUpdate.exe",
  64. "VZipUpdate.exe",
  65. "VZipUpdate.exe",
  66. "VZipUpdate.exe",
  67. "svchost.exe",
  68. "VZipSvcHost.exe"
  69.  
  70.  
  71. * Executed Commands:
  72. "\"C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe\" -inst_fix -startby=8",
  73. "regsvr32.exe /s \"C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll\"",
  74. "C:\\Windows\\system32\\regsvr32.exe /s \"C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll\"",
  75. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipService.exe",
  76. "C:\\Windows\\SysWOW64\\svchost.exe -k VSvcUpdateGroup",
  77. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe -auto -startby=5",
  78. "C:\\Users\\user\\AppData\\Roaming\\VZip\\UpdateV2\\VZipUpdate.exe -inst_update",
  79. "\"C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe\" -task -startby=2",
  80. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe -task -startby=2",
  81. "\"C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe\" -update_silence -startby=2",
  82. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe -update_silence -startby=2",
  83. "\"C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe\" -tid=1 -startby=2",
  84. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe -tid=1 -startby=2",
  85. "regsvr32.exe /s /u \"C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll\"",
  86. "regsvr32.exe /s \"C:\\Users\\user\\AppData\\Roaming\\VZip\\VZipRMExtern64.dll\"",
  87. "C:\\Windows\\system32\\regsvr32.exe /s /u \"C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll\"",
  88. "C:\\Users\\user\\AppData\\Roaming\\VZipZhuoMianUp\\VZipSvcHost.exe -startby=16",
  89. "C:\\Windows\\system32\\regsvr32.exe /s \"C:\\Users\\user\\AppData\\Roaming\\VZip\\VZipRMExtern64.dll\"",
  90. "\"C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe\" -tid=5 -startby=2",
  91. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe -tid=5 -startby=2"
  92.  
  93.  
  94. * Signatures Detected:
  95.  
  96. "Description": "Creates RWX memory",
  97. "Details":
  98.  
  99.  
  100. "Description": "Attempts to connect to a dead IP:Port (5 unique times)",
  101. "Details":
  102.  
  103. "IP": "221.230.141.50:443"
  104.  
  105.  
  106. "IP": "222.245.77.75:443"
  107.  
  108.  
  109. "IP": "157.185.177.205:80"
  110.  
  111.  
  112. "IP": "106.75.31.186:80"
  113.  
  114.  
  115. "IP": "157.185.163.158:443"
  116.  
  117.  
  118.  
  119.  
  120. "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
  121. "Details":
  122.  
  123. "ioc": "www.digicert.com1"
  124.  
  125.  
  126.  
  127.  
  128. "Description": "Expresses interest in specific running processes",
  129. "Details":
  130.  
  131. "process": "VZipUpdate.exe"
  132.  
  133.  
  134. "process": "explorer.exe"
  135.  
  136.  
  137.  
  138.  
  139. "Description": "Reads data out of its own binary image",
  140. "Details":
  141.  
  142. "self_read": "process: VZip_724.exe, pid: 2148, offset: 0x00000000, length: 0x003fce93"
  143.  
  144.  
  145. "self_read": "process: VZip_724.exe, pid: 2148, offset: 0x0004901c, length: 0x003b3e7b"
  146.  
  147.  
  148. "self_read": "process: VZipUpdate.exe, pid: 1712, offset: 0x00114a00, length: 0x00000400"
  149.  
  150.  
  151. "self_read": "process: VZipUpdate.exe, pid: 1784, offset: 0x00000000, length: 0x004362f9"
  152.  
  153.  
  154. "self_read": "process: VZipUpdate.exe, pid: 1784, offset: 0x0004901c, length: 0x00398000"
  155.  
  156.  
  157. "self_read": "process: VZipUpdate.exe, pid: 1784, offset: 0x003e501c, length: 0x00050000"
  158.  
  159.  
  160. "self_read": "process: VZipUpdate.exe, pid: 1784, offset: 0x004362f9, length: 0x00000004"
  161.  
  162.  
  163. "self_read": "process: VZipUpdate.exe, pid: 2416, offset: 0x000c4e00, length: 0x00000400"
  164.  
  165.  
  166.  
  167.  
  168. "Description": "A process created a hidden window",
  169. "Details":
  170.  
  171. "Process": "VZipUpdate.exe -> regsvr32.exe"
  172.  
  173.  
  174. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Roaming\\VZip\\UpdateV2\\VZipUpdate.exe"
  175.  
  176.  
  177. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  178.  
  179.  
  180. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  181.  
  182.  
  183. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  184.  
  185.  
  186. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  187.  
  188.  
  189. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  190.  
  191.  
  192. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  193.  
  194.  
  195. "Process": "VZipUpdate.exe -> regsvr32.exe"
  196.  
  197.  
  198. "Process": "VZipUpdate.exe -> regsvr32.exe"
  199.  
  200.  
  201. "Process": "VZipUpdate.exe -> regsvr32.exe"
  202.  
  203.  
  204. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  205.  
  206.  
  207. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  208.  
  209.  
  210. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  211.  
  212.  
  213. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  214.  
  215.  
  216. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  217.  
  218.  
  219. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  220.  
  221.  
  222. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  223.  
  224.  
  225. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  226.  
  227.  
  228. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  229.  
  230.  
  231. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  232.  
  233.  
  234. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  235.  
  236.  
  237. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  238.  
  239.  
  240. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  241.  
  242.  
  243. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  244.  
  245.  
  246. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  247.  
  248.  
  249. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  250.  
  251.  
  252. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  253.  
  254.  
  255. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  256.  
  257.  
  258. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  259.  
  260.  
  261. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  262.  
  263.  
  264. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  265.  
  266.  
  267. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  268.  
  269.  
  270. "Process": "VZipUpdate.exe -> C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  271.  
  272.  
  273.  
  274.  
  275. "Description": "File has been identified by 4 Antiviruses on VirusTotal as malicious",
  276. "Details":
  277.  
  278. "Avast": "Win32:Malware-gen"
  279.  
  280.  
  281. "AhnLab-V3": "Trojan/Win32.Generic.C1987944"
  282.  
  283.  
  284. "VBA32": "BScope.Adware.LightSee"
  285.  
  286.  
  287. "AVG": "Win32:Malware-gen"
  288.  
  289.  
  290.  
  291.  
  292. "Description": "Drops a binary and executes it",
  293. "Details":
  294.  
  295. "binary": "C:\\Users\\user\\AppData\\Roaming\\VZip\\UpdateV2\\VZipUpdate.exe"
  296.  
  297.  
  298. "binary": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  299.  
  300.  
  301. "binary": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe"
  302.  
  303.  
  304. "binary": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipService.exe"
  305.  
  306.  
  307. "binary": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipService.exe"
  308.  
  309.  
  310. "binary": "C:\\Users\\user\\AppData\\Roaming\\VZipZhuoMianUp\\VZipSvcHost.exe"
  311.  
  312.  
  313.  
  314.  
  315. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  316. "Details":
  317.  
  318. "get_no_useragent": "HTTP traffic contains a GET request with no user-agent header"
  319.  
  320.  
  321. "suspicious_request": "http://down.wdmuz.com/wy/wyp1.dat"
  322.  
  323.  
  324. "suspicious_request": "http://tj.wdmuz.com/pipil.php"
  325.  
  326.  
  327. "suspicious_request": "http://down.wdmuz.com/wbpctl/wbpctl2.shjson?473339"
  328.  
  329.  
  330. "suspicious_request": "http://tj.wdmuz.com/pipia.php?data=9750af6744f09ddc3dc7b77c6886de4a"
  331.  
  332.  
  333. "suspicious_request": "http://down.wdmuz.com/img/wz/wz190720D.zip"
  334.  
  335.  
  336.  
  337.  
  338. "Description": "Performs some HTTP requests",
  339. "Details":
  340.  
  341. "url": "http://down.wdmuz.com/wy/wyp1.gif"
  342.  
  343.  
  344. "url": "http://down.wdmuz.com/wy/wyp1.dat"
  345.  
  346.  
  347. "url": "http://tj.wdmuz.com/pipil.php"
  348.  
  349.  
  350. "url": "http://down.wdmuz.com/wbpctl/wbpctl2.shjson?473339"
  351.  
  352.  
  353. "url": "http://tj.wdmuz.com/pipia.php?data=9750af6744f09ddc3dc7b77c6886de4a"
  354.  
  355.  
  356. "url": "http://down.wdmuz.com/img/wz/wz190720D.zip"
  357.  
  358.  
  359.  
  360.  
  361. "Description": "The binary likely contains encrypted or compressed data.",
  362. "Details":
  363.  
  364. "section": "name: .rsrc, entropy: 6.81, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x00041200, virtual_size: 0x00041060"
  365.  
  366.  
  367.  
  368.  
  369. "Description": "Queries information on disks, possibly for anti-virtualization",
  370. "Details":
  371.  
  372.  
  373. "Description": "A process attempted to delay the analysis task by a long amount of time.",
  374. "Details":
  375.  
  376. "Process": "VZipSvcHost.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
  377.  
  378.  
  379. "Process": "VZipUpdate.exe tried to sleep 34688 seconds, actually delayed analysis time by 0 seconds"
  380.  
  381.  
  382. "Process": "VZipService.exe tried to sleep 5523 seconds, actually delayed analysis time by 0 seconds"
  383.  
  384.  
  385. "Process": "svchost.exe tried to sleep 23400 seconds, actually delayed analysis time by 0 seconds"
  386.  
  387.  
  388.  
  389.  
  390. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  391. "Details":
  392.  
  393. "Spam": "services.exe (504) called API GetSystemTimeAsFileTime 6396350 times"
  394.  
  395.  
  396.  
  397.  
  398. "Description": "Installs itself for autorun at Windows startup",
  399. "Details":
  400.  
  401. "service name": "VZipService"
  402.  
  403.  
  404. "service path": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipService.exe"
  405.  
  406.  
  407. "service name": "VSvcUpdate"
  408.  
  409.  
  410. "service path": "C:\\Windows\\SysWOW64\\svchost.exe -k VSvcUpdateGroup"
  411.  
  412.  
  413. "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\ImagePath"
  414.  
  415.  
  416. "data": "C:\\Windows\\SysWOW64\\svchost.exe -k VSvcUpdateGroup"
  417.  
  418.  
  419. "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\Parameters\\ServiceDll"
  420.  
  421.  
  422. "data": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipSvcHost.dll"
  423.  
  424.  
  425. "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07\\InprocServer32\\(Default)"
  426.  
  427.  
  428. "data": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll"
  429.  
  430.  
  431. "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\E6605199-673A-4B5B-8163-1E406B1FF9B3\\InprocServer32\\(Default)"
  432.  
  433.  
  434. "data": "C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll"
  435.  
  436.  
  437.  
  438.  
  439. "Description": "Collects information about installed applications",
  440. "Details":
  441.  
  442.  
  443.  
  444. "Program": "Microsoft Office Shared 64-bit MUI 2013"
  445.  
  446.  
  447.  
  448.  
  449. "Program": "Microsoft Excel MUI 2013"
  450.  
  451.  
  452. "Program": "Microsoft Outlook MUI 2013"
  453.  
  454.  
  455.  
  456.  
  457. "Program": "Google Chrome"
  458.  
  459.  
  460.  
  461.  
  462. "Program": "Notepad++"
  463.  
  464.  
  465. "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xc3\\xb1ol"
  466.  
  467.  
  468. "Program": "Adobe Flash Player 29 ActiveX"
  469.  
  470.  
  471.  
  472.  
  473. "Program": "Microsoft Access MUI 2013"
  474.  
  475.  
  476. "Program": "Microsoft Office 64-bit Components 2013"
  477.  
  478.  
  479. "Program": "Microsoft Office Proofing Tools 2013 - English"
  480.  
  481.  
  482. "Program": "Adobe Flash Player 29 NPAPI"
  483.  
  484.  
  485. "Program": "Adobe Acrobat Reader DC"
  486.  
  487.  
  488. "Program": "Adobe Refresh Manager"
  489.  
  490.  
  491. "Program": "\\xc3\\x8e\\xc2\\xa2\\xc3\\x91\\xc2\\xb9"
  492.  
  493.  
  494. "Program": "Microsoft Publisher MUI 2013"
  495.  
  496.  
  497. "Program": "Microsoft DCF MUI 2013"
  498.  
  499.  
  500.  
  501.  
  502. "Program": "Microsoft Office Shared MUI 2013"
  503.  
  504.  
  505. "Program": "Microsoft Office OSM MUI 2013"
  506.  
  507.  
  508. "Program": "Microsoft InfoPath MUI 2013"
  509.  
  510.  
  511. "Program": "Microsoft Office Shared Setup Metadata MUI 2013"
  512.  
  513.  
  514. "Program": "Outils de v\\xc3\\xa9rification linguistique 2013 de Microsoft Office\\xc2\\xa0- Fran\\xc3\\xa7ais"
  515.  
  516.  
  517. "Program": "Microsoft Word MUI 2013"
  518.  
  519.  
  520.  
  521.  
  522. "Program": "Google Update Helper"
  523.  
  524.  
  525.  
  526.  
  527.  
  528.  
  529. "Program": "Microsoft OneDrive"
  530.  
  531.  
  532. "Program": "Microsoft Groove MUI 2013"
  533.  
  534.  
  535. "Program": "Oracle VM VirtualBox Guest Additions 6.0.2"
  536.  
  537.  
  538.  
  539.  
  540.  
  541.  
  542. "Program": "Microsoft Office Shared 64-bit Setup Metadata MUI 2013"
  543.  
  544.  
  545. "Program": "Microsoft Access Setup Metadata MUI 2013"
  546.  
  547.  
  548. "Program": "Microsoft Office OSM UX MUI 2013"
  549.  
  550.  
  551. "Program": "Java Auto Updater"
  552.  
  553.  
  554. "Program": "Microsoft PowerPoint MUI 2013"
  555.  
  556.  
  557. "Program": "Microsoft Office Professional Plus 2013"
  558.  
  559.  
  560. "Program": "Java 8 Update 201"
  561.  
  562.  
  563. "Program": "Microsoft Office Proofing 2013"
  564.  
  565.  
  566. "Program": "Microsoft Lync MUI 2013"
  567.  
  568.  
  569.  
  570.  
  571.  
  572.  
  573. "Program": "Microsoft OneNote MUI 2013"
  574.  
  575.  
  576.  
  577.  
  578. "Description": "Detects VirtualBox through the presence of a registry key",
  579. "Details":
  580.  
  581.  
  582. "Description": "Attempts to modify browser security settings",
  583. "Details":
  584.  
  585.  
  586.  
  587. * Started Service:
  588. "VZipService",
  589. "VSvcUpdate"
  590.  
  591.  
  592. * Mutexes:
  593. "VZip_install",
  594. "Global\\846B0D787F8CC6D5",
  595. "VZip_Fix",
  596. "06FA88EC1CA2B88D",
  597. "VZip-auto",
  598. "Local\\ZoneAttributeCacheCounterMutex",
  599. "Local\\ZonesCacheCounterMutex",
  600. "Local\\ZonesLockedCacheCounterMutex",
  601. "VZip-task",
  602. "61B00EC2029EC991",
  603. "1A0D91A871B61814",
  604. "CicLoadWinStaWinSta0",
  605. "Local\\MSCTF.CtfMonitorInstMutexDefault1",
  606. "846B0D787F8CC6D5",
  607. "31ADD72FDDB67E3D",
  608. "8BE8F092922D7043",
  609. "DBWinMutex",
  610. "VZipVZipSvcHost.dll",
  611. "D731875BB31263A9",
  612. "AB15260608A596B5",
  613. "NewsFlashFrame"
  614.  
  615.  
  616. * Modified Files:
  617. "C:\\Users\\user\\AppData\\Local\\Temp\\nsu1DDB.tmp",
  618. "C:\\Users\\user\\AppData\\Local\\Temp\\nsu1DDC.tmp\\InstHlp.dll",
  619. "C:\\Users\\user\\AppData\\Local\\Temp\\nsu1DDC.tmp\\System.dll",
  620. "C:\\Users\\user\\AppData\\Local\\VZip\\Uninst.exe",
  621. "C:\\Users\\user\\AppData\\Local\\VZip\\VZip.exe",
  622. "C:\\Users\\user\\AppData\\Local\\VZip\\VZip2.exe",
  623. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern.dll",
  624. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll",
  625. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipKernel.dll",
  626. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipMiniNews.exe",
  627. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipMiniTray.exe",
  628. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipPd.dll",
  629. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipService.exe",
  630. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe",
  631. "C:\\Users\\user\\AppData\\Local\\VZip\\zip.sfx",
  632. "C:\\Users\\user\\AppData\\Local\\VZip\\Lang\\en.ttt",
  633. "C:\\Users\\user\\AppData\\Local\\VZip\\Lang\\zh-cn.txt",
  634. "\\??\\PIPE\\srvsvc",
  635. "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\\\xc3\\x8e\\xc2\\xa2\\xc3\\x91\\xc2\\xb9\\ \\xc3\\x8e\\xc2\\xa2\\xc3\\x91\\xc2\\xb9.lnk",
  636. "C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\\\xc3\\x8e\\xc2\\xa2\\xc3\\x91\\xc2\\xb9\\\\xc3\\x90\\xc2\\xb6\\xc3\\x94\\xc3\\x98 \\xc3\\x8e\\xc2\\xa2\\xc3\\x91\\xc2\\xb9.lnk",
  637. "C:\\Users\\Public\\Desktop\\\\xc3\\x8e\\xc2\\xa2\\xc3\\x91\\xc2\\xb9.lnk",
  638. "C:\\Users\\user\\AppData\\Local\\Temp\\service_temp_report",
  639. "C:\\Users\\user\\AppData\\Roaming\\VZip\\UpdateV2\\VZipUpdate.exe",
  640. "C:\\Users\\user\\AppData\\Local\\GDIPFONTCACHEV1.DAT",
  641. "C:\\Users\\user\\AppData\\Local\\Temp\\nsc2161.tmp",
  642. "C:\\Users\\user\\AppData\\Local\\Temp\\nsr2171.tmp\\InstHlp.dll",
  643. "C:\\Users\\user\\AppData\\Local\\Temp\\nsr2171.tmp\\DuiLib.dll",
  644. "C:\\Users\\user\\AppData\\Local\\Temp\\nsr2171.tmp\\System.dll",
  645. "C:\\Users\\user\\AppData\\Local\\VZip\\DuiLib.dll",
  646. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipRMExtern.dll",
  647. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipRMExtern64.dll",
  648. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipSvcHost.dll",
  649. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipSvcHost.exe",
  650. "C:\\Users\\user\\AppData\\Roaming\\VZip\\Data\\VZip2",
  651. "C:\\Users\\user\\AppData\\Roaming\\VZipZhuoMianUp\\VZipSvcHost.exe",
  652. "C:\\Users\\user\\AppData\\Roaming\\VZip\\VZipRMExtern64.dll",
  653. "C:\\Users\\user\\AppData\\Roaming\\VZip\\Data\\wwp2",
  654. "C:\\Users\\user\\AppData\\LocalLow\\BubblesPop\\CheckToTips.ini",
  655. "C:\\Users\\user\\AppData\\LocalLow\\WeiYa\\skin1.zip",
  656. "C:\\Users\\user\\AppData\\LocalLow\\WeiYa\\Config.ini"
  657.  
  658.  
  659. * Deleted Files:
  660. "C:\\Users\\user\\AppData\\Local\\Temp\\nsp1CD1.tmp",
  661. "C:\\Users\\user\\AppData\\Local\\Temp\\nsu1DDC.tmp",
  662. "C:\\Users\\user\\AppData\\Local\\Temp\\nsu1DDC.tmp\\InstHlp.dll",
  663. "C:\\Users\\user\\AppData\\Local\\Temp\\nsu1DDC.tmp\\System.dll",
  664. "C:\\Users\\user\\AppData\\Local\\Temp\\nsu1DDC.tmp\\",
  665. "C:\\Users\\user\\AppData\\Roaming\\VZip\\UpdateV2\\VZipUpdate.exe",
  666. "C:\\Users\\user\\AppData\\Roaming\\VZip\\Update\\VZipUpdate.exe",
  667. "C:\\Users\\user\\AppData\\Local\\Temp\\nsl1F7B.tmp",
  668. "C:\\Users\\user\\AppData\\Local\\Temp\\nsr2171.tmp",
  669. "C:\\Users\\user\\AppData\\Local\\VZip\\Uninst.exe",
  670. "C:\\Users\\user\\AppData\\Local\\VZip\\VZip.exe",
  671. "C:\\Users\\user\\AppData\\Local\\VZip\\VZip2.exe",
  672. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern.dll",
  673. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipExtern64.dll",
  674. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipKernel.dll",
  675. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipMiniNews.exe",
  676. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipMiniTray.exe",
  677. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipPd.dll",
  678. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipService.exe",
  679. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipUpdate.exe",
  680. "C:\\Users\\user\\AppData\\Local\\VZip\\zip.sfx",
  681. "C:\\Users\\user\\AppData\\Local\\Temp\\nsr2171.tmp\\DuiLib.dll",
  682. "C:\\Users\\user\\AppData\\Local\\Temp\\nsr2171.tmp\\InstHlp.dll",
  683. "C:\\Users\\user\\AppData\\Local\\Temp\\nsr2171.tmp\\System.dll",
  684. "C:\\Users\\user\\AppData\\Local\\Temp\\nsr2171.tmp\\",
  685. "C:\\Users\\user\\AppData\\Roaming\\VZip\\Data\\VZip2",
  686. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipSvcHost.exe",
  687. "C:\\Users\\user\\AppData\\Local\\VZip\\VZipRMExtern64.dll",
  688. "C:\\Users\\user\\AppData\\Roaming\\VZip\\Data\\VZip3",
  689. "C:\\Users\\user\\AppData\\Roaming\\VZip\\Data\\wwp2"
  690.  
  691.  
  692. * Modified Registry Keys:
  693. "HKEY_CURRENT_USER\\SOFTWARE\\VZip",
  694. "HKEY_CURRENT_USER\\Software\\VZip\\UserSID",
  695. "HKEY_LOCAL_MACHINE\\SOFTWARE\\VZip",
  696. "HKEY_LOCAL_MACHINE\\SOFTWARE\\VZip\\UserSID",
  697. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\SOFTWARE\\VZip\\VZip",
  698. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\QID",
  699. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  700. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\AppDataPath",
  701. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\isps",
  702. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\InstallPath",
  703. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\InstallTime",
  704. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\InstallSvrTime",
  705. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\Shell",
  706. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip",
  707. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip\\DisplayName",
  708. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip\\Publisher",
  709. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip\\DisplayIcon",
  710. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip\\UninstallString",
  711. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\VZip\\DisplayVersion",
  712. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\AV",
  713. "HKEY_CLASSES_ROOT\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07",
  714. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07\\(Default)",
  715. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07\\InprocServer32",
  716. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07\\InprocServer32\\(Default)",
  717. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07\\InprocServer32\\ThreadingModel",
  718. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07",
  719. "HKEY_CLASSES_ROOT\\*\\shellex\\ContextMenuHandlers\\VZipShell",
  720. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\shellex\\ContextMenuHandlers\\VZipShell\\(Default)",
  721. "HKEY_CLASSES_ROOT\\Folder\\shellex\\ContextMenuHandlers\\VZipShell",
  722. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\ContextMenuHandlers\\VZipShell\\(Default)",
  723. "HKEY_CLASSES_ROOT\\Directory\\shellex\\ContextMenuHandlers\\VZipShell",
  724. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\shellex\\ContextMenuHandlers\\VZipShell\\(Default)",
  725. "HKEY_CLASSES_ROOT\\Directory\\Background\\shellex\\ContextMenuHandlers\\VZipShell",
  726. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\Background\\shellex\\ContextMenuHandlers\\VZipShell\\(Default)",
  727. "HKEY_CLASSES_ROOT\\Directory\\shellex\\DragDropHandlers\\VZipShell",
  728. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\shellex\\DragDropHandlers\\VZipShell\\(Default)",
  729. "HKEY_CLASSES_ROOT\\Drive\\shellex\\DragDropHandlers\\VZipShell",
  730. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\DragDropHandlers\\VZipShell\\(Default)",
  731. "HKEY_CLASSES_ROOT\\Directory\\Background\\shellex\\DragDropHandlers\\VZipShell",
  732. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\Background\\shellex\\DragDropHandlers\\VZipShell\\(Default)",
  733. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\VZip Shell Extension",
  734. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\VZip Shell Extension\\(Default)",
  735. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VZipService\\Start",
  736. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VZipService\\Type",
  737. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate",
  738. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\Type",
  739. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\Start",
  740. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\ErrorControl",
  741. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\ImagePath",
  742. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\WOW64",
  743. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\ObjectName",
  744. "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  745. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  746. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  747. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\Mistiming",
  748. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\UpdateTime",
  749. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\SOFTWARE\\VZip\\VZipUpdate",
  750. "HKEY_CURRENT_USER\\Software\\VZip\\VZipUpdate\\m",
  751. "HKEY_CURRENT_USER\\Software\\VZip\\VZipUpdate\\dver",
  752. "HKEY_CURRENT_USER\\SOFTWARE\\VZipSvcHost",
  753. "HKEY_CURRENT_USER\\Software\\VZipSvcHost\\UserSID",
  754. "HKEY_LOCAL_MACHINE\\SOFTWARE\\VZipSvcHost",
  755. "HKEY_LOCAL_MACHINE\\SOFTWARE\\VZipSvcHost\\UserSID",
  756. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\SOFTWARE\\VZipSvcHost\\VZipSvcHost",
  757. "HKEY_CURRENT_USER\\Software\\VZipSvcHost\\VZipSvcHost\\AppDataPath",
  758. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Svchost\\VSvcUpdateGroup",
  759. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\Parameters",
  760. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VSvcUpdate\\Parameters\\ServiceDll",
  761. "HKEY_CURRENT_USER\\Software\\VZipSvcHost\\VZipSvcHost\\rmsrv",
  762. "HKEY_CURRENT_USER\\Software\\VZipSvcHost\\VZipSvcHost\\rmshell",
  763. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\VZip\\VZip\\Mistiming",
  764. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\VZip\\VZip\\StartUpTime5",
  765. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\StartUpTime2",
  766. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\VZipSvcHost\\VZipSvcHost\\StartTime",
  767. "HKEY_CLASSES_ROOT\\CLSID\\E6605199-673A-4B5B-8163-1E406B1FF9B3",
  768. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\E6605199-673A-4B5B-8163-1E406B1FF9B3\\(Default)",
  769. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\E6605199-673A-4B5B-8163-1E406B1FF9B3\\InprocServer32",
  770. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\E6605199-673A-4B5B-8163-1E406B1FF9B3\\InprocServer32\\(Default)",
  771. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\E6605199-673A-4B5B-8163-1E406B1FF9B3\\InprocServer32\\ThreadingModel",
  772. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved\\E6605199-673A-4B5B-8163-1E406B1FF9B3",
  773. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\shellex\\ContextMenuHandlers\\VZipRMExtern",
  774. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\shellex\\ContextMenuHandlers\\VZipRMExtern\\(Default)",
  775. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\shellex\\ContextMenuHandlers\\VZipRMExtern",
  776. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\shellex\\ContextMenuHandlers\\VZipRMExtern\\(Default)",
  777. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\ContextMenuHandlers\\VZipRMExtern",
  778. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\ContextMenuHandlers\\VZipRMExtern\\(Default)",
  779. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\shellex\\ContextMenuHandlers\\VZipRMExtern",
  780. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\shellex\\ContextMenuHandlers\\VZipRMExtern\\(Default)",
  781. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\VZipRMExtern",
  782. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\VZipRMExtern\\(Default)",
  783. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION\\VZipUpdate.exe",
  784. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_AJAX_CONNECTIONEVENTS\\VZipUpdate.exe",
  785. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_ENABLE_CLIPCHILDREN_OPTIMIZATION\\VZipUpdate.exe",
  786. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_MANAGE_SCRIPT_CIRCULAR_REFS\\VZipUpdate.exe",
  787. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_DOMSTORAGE\\VZipUpdate.exe",
  788. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_GPU_RENDERING\\VZipUpdate.exe",
  789. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_IVIEWOBJECTDRAW_DMLT9_WITH_GDI\\VZipUpdate.exe",
  790. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_DISABLE_LEGACY_COMPRESSION\\VZipUpdate.exe",
  791. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN\\VZipUpdate.exe",
  792. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BLOCK_LMZ_OBJECT\\VZipUpdate.exe",
  793. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BLOCK_LMZ_SCRIPT\\VZipUpdate.exe",
  794. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_DISABLE_NAVIGATION_SOUNDS\\VZipUpdate.exe",
  795. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SCRIPTURL_MITIGATION\\VZipUpdate.exe",
  796. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SPELLCHECKING\\VZipUpdate.exe",
  797. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_STATUS_BAR_THROTTLING\\VZipUpdate.exe",
  798. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_TABBED_BROWSING\\VZipUpdate.exe",
  799. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_VALIDATE_NAVIGATE_URL\\VZipUpdate.exe",
  800. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_WEBOC_DOCUMENT_ZOOM\\VZipUpdate.exe",
  801. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_WEBOC_POPUPMANAGEMENT\\VZipUpdate.exe",
  802. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_WEBOC_MOVESIZECHILD\\VZipUpdate.exe",
  803. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_ADDON_MANAGEMENT\\VZipUpdate.exe",
  804. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_WEBSOCKET\\VZipUpdate.exe",
  805. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_WINDOW_RESTRICTIONS\\VZipUpdate.exe",
  806. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_XMLHTTP\\VZipUpdate.exe",
  807. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\StartUpTime3",
  808. "HKEY_CURRENT_USER\\Software\\VZip\\VZip\\OinterValTime",
  809. "HKEY_CURRENT_USER\\Software\\VZip\\VZipUpdate\\otherM",
  810. "HKEY_CURRENT_USER\\Software\\VZip\\VZipUpdate\\oTherDver",
  811. "HKEY_CURRENT_USER\\Software\\WeiYa",
  812. "HKEY_CURRENT_USER\\Software\\WeiYa\\Setting",
  813. "HKEY_CURRENT_USER\\Software\\WeiYa\\ZZGG",
  814. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_GPU_RENDERING ",
  815. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_GPU_RENDERING \\VZipUpdate.exe",
  816. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_IVIEWOBJECTDRAW_DMLT9_WITH_GDI ",
  817. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_IVIEWOBJECTDRAW_DMLT9_WITH_GDI \\VZipUpdate.exe",
  818. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_NINPUT_LEGACYMODE",
  819. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_NINPUT_LEGACYMODE\\VZipUpdate.exe",
  820. "HKEY_CURRENT_USER\\Software\\WeiYa\\Common",
  821. "HKEY_CURRENT_USER\\Software\\WeiYa\\\\xe6\\xb4\\xbb\\xe5\\x8a\\xa82\\xe7\\xbd\\x91\\xe8\\xb5\\x9a0",
  822. "HKEY_CURRENT_USER\\Software\\WeiYa\\Tag",
  823. "HKEY_CURRENT_USER\\Software\\WeiYa\\ZKGG",
  824. "HKEY_CURRENT_USER\\Software\\WeiYa\\CpID",
  825. "HKEY_CURRENT_USER\\Software\\WeiYa\\WeiYa",
  826. "HKEY_CURRENT_USER\\Software\\WeiYa\\Setting\\WPPopDate",
  827. "HKEY_CURRENT_USER\\Software\\WeiYa\\Setting\\WPPopTime",
  828. "HKEY_CURRENT_USER\\Software\\WeiYa\\WeiYa\\\\xe6\\xb4\\xbb\\xe5\\x8a\\xa82\\xe7\\xbd\\x91\\xe8\\xb5\\x9a0",
  829. "HKEY_CURRENT_USER\\Software\\WeiYa\\\\xe6\\xb4\\xbb\\xe5\\x8a\\xa82\\xe7\\xbd\\x91\\xe8\\xb5\\x9a0\\WPPopDate",
  830. "HKEY_CURRENT_USER\\Software\\WeiYa\\\\xe6\\xb4\\xbb\\xe5\\x8a\\xa82\\xe7\\xbd\\x91\\xe8\\xb5\\x9a0\\WPPopTime",
  831. "HKEY_CURRENT_USER\\Software\\WeiYa\\\\xe6\\xb4\\xbb\\xe5\\x8a\\xa82\\xe7\\xbd\\x91\\xe8\\xb5\\x9a0\\20190720",
  832. "HKEY_CURRENT_USER\\Software\\WeiYa\\\\xe6\\xb4\\xbb\\xe5\\x8a\\xa82\\xe7\\xbd\\x91\\xe8\\xb5\\x9a0\\PopTimes",
  833. "HKEY_CURRENT_USER\\Software\\WeiYa\\UserInfo",
  834. "HKEY_CURRENT_USER\\Software\\WeiYa\\UserInfo\\PopedAllTims",
  835. "HKEY_CURRENT_USER\\Software\\WeiYa\\0",
  836. "HKEY_CURRENT_USER\\Software\\WeiYa\\0\\20190720",
  837. "HKEY_CURRENT_USER\\Software\\WeiYa\\ZKGG\\20190720",
  838. "HKEY_CURRENT_USER\\Software\\WeiYa\\Setting\\PopTimes",
  839. "HKEY_CURRENT_USER\\Software\\WeiYa\\Setting\\LdSkinMD5",
  840. "HKEY_CURRENT_USER\\Software\\WeiYa\\WeiYa\\ExceptionCloseTimes",
  841. "HKEY_CURRENT_USER\\Software\\WeiYa\\Setting\\DisSelfDayV1"
  842.  
  843.  
  844. * Deleted Registry Keys:
  845. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  846. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  847. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  848. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  849. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved\\C67A2E32-82ED-4DD6-82FE-86D970C8FA07"
  850.  
  851.  
  852. * DNS Communications:
  853.  
  854. "type": "A",
  855. "request": "api.zhanfukeji.cn",
  856. "answers":
  857.  
  858. "data": "222.245.77.75",
  859. "type": "A"
  860.  
  861.  
  862. "data": "157.185.163.158",
  863. "type": "A"
  864.  
  865.  
  866. "data": "api.zhanfukeji.cn.wswebpic.com",
  867. "type": "CNAME"
  868.  
  869.  
  870.  
  871.  
  872. "type": "A",
  873. "request": "down.zhanfukeji.cn",
  874. "answers":
  875.  
  876. "data": "221.230.141.50",
  877. "type": "A"
  878.  
  879.  
  880. "data": "down.zhanfukeji.cn.wsdvs.com",
  881. "type": "CNAME"
  882.  
  883.  
  884.  
  885.  
  886. "type": "A",
  887. "request": "down.wdmuz.com",
  888. "answers":
  889.  
  890. "data": "down.wdmuz.com.wsglb0.com",
  891. "type": "CNAME"
  892.  
  893.  
  894. "data": "157.185.177.205",
  895. "type": "A"
  896.  
  897.  
  898.  
  899.  
  900. "type": "A",
  901. "request": "tj.wdmuz.com",
  902. "answers":
  903.  
  904. "data": "106.75.31.186",
  905. "type": "A"
  906.  
  907.  
  908.  
  909.  
  910.  
  911. * Domains:
  912.  
  913. "ip": "157.185.177.205",
  914. "domain": "down.wdmuz.com"
  915.  
  916.  
  917. "ip": "221.230.141.50",
  918. "domain": "down.zhanfukeji.cn"
  919.  
  920.  
  921. "ip": "157.185.163.158",
  922. "domain": "api.zhanfukeji.cn"
  923.  
  924.  
  925. "ip": "106.75.31.186",
  926. "domain": "tj.wdmuz.com"
  927.  
  928.  
  929.  
  930. * Network Communication - ICMP:
  931.  
  932. * Network Communication - HTTP:
  933.  
  934. "count": 1,
  935. "body": "",
  936. "uri": "http://down.wdmuz.com/wy/wyp1.gif",
  937. "user-agent": "WinHttpClient",
  938. "method": "GET",
  939. "host": "down.wdmuz.com",
  940. "version": "1.1",
  941. "path": "/wy/wyp1.gif",
  942. "data": "GET /wy/wyp1.gif HTTP/1.1\r\nConnection: Keep-Alive\r\nUser-Agent: WinHttpClient\r\nHost: down.wdmuz.com\r\n\r\n",
  943. "port": 80
  944.  
  945.  
  946. "count": 1,
  947. "body": "",
  948. "uri": "http://down.wdmuz.com/wy/wyp1.dat",
  949. "user-agent": "",
  950. "method": "GET",
  951. "host": "down.wdmuz.com",
  952. "version": "1.1",
  953. "path": "/wy/wyp1.dat",
  954. "data": "GET /wy/wyp1.dat HTTP/1.1\r\nHost: down.wdmuz.com\r\nAccept: */*\r\n\r\n",
  955. "port": 80
  956.  
  957.  
  958. "count": 27,
  959. "body": "",
  960. "uri": "http://tj.wdmuz.com/pipil.php",
  961. "user-agent": "",
  962. "method": "GET",
  963. "host": "tj.wdmuz.com",
  964. "version": "1.1",
  965. "path": "/pipil.php",
  966. "data": "GET /pipil.php HTTP/1.1\r\nHost: tj.wdmuz.com\r\nAccept: */*\r\n\r\n",
  967. "port": 80
  968.  
  969.  
  970. "count": 1,
  971. "body": "",
  972. "uri": "http://down.wdmuz.com/wbpctl/wbpctl2.shjson?473339",
  973. "user-agent": "",
  974. "method": "GET",
  975. "host": "down.wdmuz.com",
  976. "version": "1.1",
  977. "path": "/wbpctl/wbpctl2.shjson?473339",
  978. "data": "GET /wbpctl/wbpctl2.shjson?473339 HTTP/1.1\r\nHost: down.wdmuz.com\r\nAccept: */*\r\n\r\n",
  979. "port": 80
  980.  
  981.  
  982. "count": 1,
  983. "body": "",
  984. "uri": "http://tj.wdmuz.com/pipia.php?data=9750af6744f09ddc3dc7b77c6886de4a",
  985. "user-agent": "",
  986. "method": "GET",
  987. "host": "tj.wdmuz.com",
  988. "version": "1.1",
  989. "path": "/pipia.php?data=9750af6744f09ddc3dc7b77c6886de4a",
  990. "data": "GET /pipia.php?data=9750af6744f09ddc3dc7b77c6886de4a HTTP/1.1\r\nHost: tj.wdmuz.com\r\nAccept: */*\r\n\r\n",
  991. "port": 80
  992.  
  993.  
  994. "count": 1,
  995. "body": "",
  996. "uri": "http://down.wdmuz.com/img/wz/wz190720D.zip",
  997. "user-agent": "",
  998. "method": "GET",
  999. "host": "down.wdmuz.com",
  1000. "version": "1.1",
  1001. "path": "/img/wz/wz190720D.zip",
  1002. "data": "GET /img/wz/wz190720D.zip HTTP/1.1\r\nHost: down.wdmuz.com\r\nAccept: */*\r\n\r\n",
  1003. "port": 80
  1004.  
  1005.  
  1006.  
  1007. * Network Communication - SMTP:
  1008.  
  1009. * Network Communication - Hosts:
  1010.  
  1011. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment