MicroWorld-eScan: Application.Agent.BNR
BitDefender: Application.Agent.BNR
ESET-NOD32: a variant of Win32/UltraReach.AG potentially unsafe
ClamAV: Win.Malware.Agent-6410010-0
GData: Win32.Trojan.Agent.Q6EI6K
Kaspersky: not-a-virus:RiskTool.Win32.UltraSurf.mu
NANO-Antivirus: Riskware.Win32.UltraSurf.euxlee
Comodo: ApplicUnwnt
F-Secure: Application.Agent.BNR
VIPRE: UltraSurf (fs) (not malicious)
Emsisoft: Application.Agent.BNR (B)
Jiangmin: RiskTool.UltraSurf.e
Antiy-AVL: RiskWare[RiskTool]/Win32.AGeneric
Arcabit: Application.Agent.BNR
ZoneAlarm: not-a-virus:RiskTool.Win32.UltraSurf.mu
Yandex: Riskware.Agent!
Fortinet: Riskware/UltraSurf
行为分析
互斥量(Mutexes)
- Local\MSCTF.Asm.MutexDefault1
- Local\_!MSFTHISTORY!_
- Local\c:!users!test!appdata!local!microsoft!windows!temporary internet files!content.ie5!
- Local\c:!users!test!appdata!roaming!microsoft!windows!cookies!
- Local\c:!users!test!appdata!local!microsoft!windows!history!history.ie5!
- Local\WininetStartupMutex
- Local\WininetConnectionMutex
- Local\WininetProxyRegistryMutex
- Local\!BrowserEmulation!SharedMemory!Mutex
- Local\ZoneAttributeCacheCounterMutex
- Local\ZonesCacheCounterMutex
- Local\ZonesLockedCacheCounterMutex
- Local\!IETld!Mutex
- ConnHashTable<2528>_HashTable_Mutex
- Local\ZonesCounterMutex
- Local\c:!users!test!appdata!local!microsoft!feeds cache!
- Local\!IECompat!Mutex
- Local\c:!users!test!appdata!roaming!microsoft!windows!iecompatcache!
- Groove:PathMutex:huJZ0a1oPtB4yGzDQW9lw0niEfg=
- Groove.Mutex.WebServices.Status
- Groove.Mutex.SystemServices.Lock
- Groove:PathMutex:v1n9odwmzLTGaaFW7PZysBRMqq8=
执行的命令
- C:\Users\test\AppData\Local\Temp\utmp\u.exe -L="127.0.0.1:9666" -CID="1a7a7b45", -ProgPath="C:\Users\test\AppData\Local\Temp\\" -TmpPath="C:\Users\test\AppData\Local\Temp\utmp\\" -ConnMode=0 -C="CN" -version="1704100"
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?wzoiujphtwhrdmszowtsjthmmjjhpcicgmiavbvhiabufpgxwsinnaibmojlgoneuvnkarlfvvgtjervfekrsbbjfwnazzpvjwxsihrmjyijubhfencltedkgvlpfxgpjwqzrbonmjrmzeruixyzmjwoehaapsudtiuqfvujhckaxcqhizzbuiosascjsjwshmeryflemelaeaehfwxqxpdelamfegahnxsqinncqqvqmhiqdwbcgqvqzskqvxoihweqgnyrpenkhjqktodevtwprjfhrmowbpufhzbvqnbzqrubkxdecysgldjdogxrqbwxllayactktrgfnunqdxgkebpvbsuhfnycznkufxrpgeiufnyjplmpggvrcsoprpqxrfbfmdtkjhkorkoningvgaklyfqtsytwzmmztlchkesqckxzqgeabqqnicclnnlhkrbtlruywiqjvwcnyiiwisulzfozrqtxvkysyffxlfztvsfvqximafi
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?dmpkkazifkgmahgqubzprevaaxnisfmwqrpqkzbrwhqrogubhieznhmvsiaylutfcfayfcbhomuelnsqapirhbaflzpedmvreorfkjjklkvhexjxrxuiozaiulprlqyjxqwzbdkhwtuoucukfpebasvtphkcsxawdyyqetyueahmohenkbmlmsbyzbyhgpfmnttxdwapmnrnklxpfsgustrgebxkhnbhbozafegbnnxznumhhfcofifbhovvfftkyhapwtqvppemramvaameomxvlnqwgghnomxraysudbjnycbztoqqsmodnpecjvnweegktwmiofaqrzsvigzgiribaiqaemjjpwirywtvbsqlvinaomhnezogimuuaozboetwlsjrvgpioeqedcqhzumairbszoxbilkjknlsfbjnmlrlwfsnxljfnngtpcvrbgljzawwmfaxgxdgoqnjnzpqwuhnhcplcpcebzglbbelqfmqmebflsmjzmqssqoxsvcmyptvrqxqzuvhnqosqlyssxovcnkcaxmszopsoylamyjjdwqedlhprnyddvubkduvycgolbknieibxavtsosdkaurgubcmqpdoifpttteudgbzjaymdjvccpdfvjtirzsaemlhaofdhzleahthgtzbxxjdnumyqesvqxvgikucjplufdwcsshmmwlhqrqpxediskyxlmytwzwynzunyzwdyghguhhtpngmnjsvbddnusfbvnsxagqcrvvjuchbblgiasvmsumgkiwtjvszvzxugzn
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?hbbqnxwplromdpjbbhqyomcbxvcskyfgypsjamyqqmkkrvzpafazejeotcrrhdktbxffastaqhlcluurpofnvpzskhalmrizkmitytbsqxvnzwlfcjnmlxfvjoipjqezfenwzjkxokbunlwuyqfnpouohqxtmeqcjubzpjlyhnnttdpicieaoaxjrdbohzzmrwxtjbqucmxnlqirqmriwuijltqlktvwuvphsftqfjsarfuuhggpnoumgcttfxqevbfcglbvhsgpzrgycgzlcuzvykdbazdhkzvbttyjxvmorkyxdjmpqubvfheeirapbnsuojwzrmyibbixnixmiqfbbxsbckxrdslouxycgzkiuymrzjrsooxajdzslgqkvmfcmvxhptxbvrjnhnorqpkkvjqubyiluurtaclisonuxehegoueyvkctlmscbstguzcmskjpwskgrstqerjtqboejmppxcexkxouoswprjziqllqjwldseybftabrkjbstumjjhbjfucidvhlrjkqvzmzeexjuoqyhkoejbaybzrbemfiwcjvigmrwapuhzssyjsouknaisraatvqojgcpakoighkifooxbujkbygtehgwjzfufaalqydrxvbvhpdfzokttzkjymdumgqevwlzcocptpvipubqrpqnzllxrkhmllzqtagpcrwazxczdnaqhszrgjossukehvcfedvfyqhvnfgdwfgmbkqevvdkvtabdwrtkuiahqvmxrhwwejfcnjwrqstljugcoemnqbgvsobtnoqmhfairsvwxphlnedbkfcmnexeiwvoapsgdyjxzjursgpanksxbeiwfxqsgeuizaeagcorufjigqcdsgfssajthqtsjssnjjzrjclbxkcgplodtwbzrrfbmgskunskaewwoakcgtvdiwplgyczpiwbjrifzwlnynahaflzl
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?hwudomwvseunekuhnpawpoocmwkqyoxrlprfdminwzrathypkyjhocmgxkjiyejyohugxffxdwrvtbfuovrvomvqsfoidwokpesllxtkhkgnfwnkxeisovhpucckzfpqdurqhhkufcurutczwbaollqpezaalpbknfexsyyzlwtmpduudvmqonwufkcddzwccblfboewlhextadrrnivfsatrihkisqasdpvjeczbyzjvzxjgdvsneqyzizbdcokkkshtlmkvcgajzwivuqmphkaszkwpgjrcjwbbjocuhdmqovsbnysyyubjgexxlbqjyducssbffilbdsmisodnmkfrjnmydxhprveedmlplqipfgkhmsaneazfailhytgzfztylmbiioaletnmgncjienmejcglxiudljuzwhpdqnkyopkubdkghlduduwflbzjejbvxuhwhftidujejjlkbsvwlgwdhtfodeybplbohgrnnhohxkqzffitpjbodtqrkiyxndelioxisgkwyhetmkhubdqydzfqnlipagcscudzrrwcmyaakrjrlyebiwheyfslmnmopbcicnncefdhtahddxyusqpgllbvpdoddprrwslsmcocqjcvahhmyvnebbexsknurazcxifcjtssidzvzvzbtmjjezcdbkzfrrrrjwjnztcajnloinbqytvubascpgnxkuiwuysunpgyonesepbcuezvchffwogntfbzqdmljujlrtzmjbfnvssooeotlgenkpwyijebjuccoljnjxcoykmahxkukvmsfcgtxsxfvnuwdsprgqbqmwqygkcqhkyvpnrgvfptvowrghyrlnmbbgilnluumc
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?btmnyqaentxnpxxzpwtbxhqqugocakywhmfxdjjcrknhhahzpnkzdobvtbbnxllppaqhtreizegfdrvslrwxuaxutpbgpbngbpzknvdmfqnivfugretixpmsrcbgoegodmtbvduzzfgnbqxctfvyoglwmkdlryvstdjlkuixxrrzeqecokngmtinqbzmkoqgvjxorqhmrcgaxmtcfpdtkzjkwvnzrchriazpadwvbxjnheiihjplddfpzmgobizhdxlrxlfrpphgbynfowsdjoqnbchnlyqwpyctlqcndaryxyvjqyhzyrdjhcamjafjyzrcbukoyzrvpbugsxtyhykkrsdqtfojeootypvmnutyytckjyyqpytfosubollgyuhbukcbvpwihmtgezusparlfyeqczfqhdkgnllxaqsenryvzmvfdesfiktvfdgutgirhrcnurdhqaqqusbycpogqodlhahknidietcxqgyhepdmfxnkgfgbjazapwadufbculhlhrxjzqxbcrdmwwroafcsulzuajbjzzfngdzptnelvotbjsmywhaoufzmoyocfedofembccfxaknfjghgshtkjhomnisucbxkufwudruhpccftmwdesqdnzqhvqdxwepibnyrlbroypeyjxxsucxlxioqbtcqrmwyescgduvbanpbweguozcvfjdnevdnvj
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?mrrgfyelmsqvevthvrgrorgdcohvyyqrnaugbwxhutgyozyxvkrjkqgxzuouooduugdjnverebkhtrfovnywagfsewxeqqjgowwltgjnwxdwjvfffqfqjgvmgtfgarezhkkukpotryvruspkdvshudunkymcqatpeddjsjclyudynxjfrpwcirnpcsnjivuwbxccazpjqdpuuiuzesdwnkwfvfgsaekxvbrsbzikeyxbuqkumkodcuurvdjkvosrvcdtywpfiqvrmbtrimgfzzyzmjvnssqesiclmkpqxmapnirijnlblncqrowtoegoximtyowblwuaaiqzjhhpwqmvhprgvtcjodvnnlpvxecmsdctodwhncxgsewvkgeeupzwhzmqheppmadekegwpnchkfwronjlovcwnraqombcwrewnagkwufdacdpqsvytaqlclxyfyeftvdmwotlfmpsubdzrcbycgkwrogaayykdvjvnbfe
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?rayebfpabhybulbajyleybwihzjuglwezmdaiziykiaucxpkskuwezgiyewuvqrtdrcgzohiavllgtwldilocwlyekuwqnemjexsyffwmnumjfapyjiesquaocdibbolvprobfzgqhrepmkplvstmjagoqtzkdfwfuvhcxytoalrvgtltwexkyetoashfwbdegtpdjszysbmnwlfcgjxkftjvhhjxdfsrhqyiirvryohruqvumvxqqbxjofzhyohxkfalqeytmefwtbrekymwtyogjtojoxofkidveoaetrzcivgmlidltvyhmpkbrdvkgthxgvzbztobsauvdphagnxeqvweucdtdjcadunrpspwofmthdrdzchutuoyrkgtvhcewsesiqkfwtfmqxlqicqdwfthfofhpbfkptfgsywijprbjiowsqbxjvzgznvthoisjybkwrfaljcqzrsxiqgnoqnbzdhdbpvgkriokgpvklkjdanpjuqrsedevtyjclgnzdjqzbnihothkchnukpxidjisocqzohhkjsgzweznzkcqpwtgpukwpfzigibjysmidrlbefwzdbikqebuivacknogrbszcncmqijcktguafwzgbqerbzjipdryhxfrkorhhifrudidglufhefjoaflniggtmvoqbkgrejtaojthdwqbacvzhjhoqysxqcrdfxrofcxudxsoeapjcktuzerazmvdcejmuluhevegsrivetpyguqwdluvzrtghcfxwiatsmujstezxjtxnpmnmzlvbisusvvfaizceroapnfqtrvcbgwrwkmgczxoicfpputuubskpzjpcdsprfdeontojxnsoiktrzizarcgryremcnhbpdoxkfxwlcztdjmcqntpzhcpoaunscrparzbkrkbohdyoduemivprvzfcchfbabcmgxgrjbwbnmbribpbnuougpceobztjomeqtbogpfbesockqctmmrlwiptlfcruq
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?nepardagpudtuvqezcwhjvwkqbomqbcdpdfoqrukeqdzufybhohmxtehgtbiwahzzykqsquouzebqerzynpruxybhrrtfohhdquqtrijajtpimnciyxsrxqvpovvrwketifetdbsrlfibvamwsmxatbhwgjxkcolklkybeobzwksslyngetahksmtrvuxhfkswwdfbvqemjvbvqxkcrpwhsjdivyorjttuhrsufvinhjczlyvdiljewwgqtdjbqdiggrsmruwcosddbyjwsyzvaweozvncedjvucvffgkplfhdovqcamxhihpxysykrbwqmgsmonwbpbewaoscvdnabhddjfiavkyvabfujzjbiykjmfsnrnvbatrkjwsqkstvktmnifkcbrzpsbfspicltjqsybcnvlyfjwwenfzviwxjcfplkcozvzegzihtxtpgwpcfrosospzddtylmmpsdffcmhnzqsupisbrvlcqakgzndjyrgqpxfsqccukpkmijipuuirdehvinsywczzvconskhldvvzmwnkhoklybuyqumhkyleupocskycnwaanbkifilmxnefiocxrqnsjamszlxokdfnannncdgfxhvblywsztdashovjdxzvmbaxvagrvtzhuiqcdraurwuzljmhpyjucvgtpkrgvccatkekqlwpswqhbjrsksjnehjzuhochnsfinijpaeirokxmsqciffjebxyyevpssrapzyugoemdwglrewzkjjrjgvlmklswnyouwmbeoxugvnvqwnvjupoyfh
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?hworzphmeubqgmmbcfwmhlkerbwyqpptehnracftffiqbypxpcuowjlfiuuxfdgcgitwbavprrqdrjxgjhsxwfgepcpywhpxfiwjgvvziitsczitjkofjnokcmxzexdmxxejzrnuvthduafrsvdhbzldnfkiihlutqtdtydbxhntukjtruzhmtkcinfpgnxgoabgzkdtowpemqadjzaejelxzpgjfgfzdxidetfbwlztjmmwuwpwxfowrncpbbzezaflspntgmbfmtdfclgknyoyvdhznytbmpfrezoidxabqfmbylclbgjordnguuffgzmzzlfbgmvcxxmtnkzeatzmshnmwdhqcwqgjhfxsjqqvvdgvjlaprtntynzadmbpxssdhkxxhdwerfjtnvygegnaslfzytgvfgdvbqcjismkrqequzdxkcwcoicpqxavocchhozdloyjnhwsiyrtfhbluabjrcgisxmcxprmtopgahzsiovzazxkpbceupwikdjewieskeagcvffdrunvktcvkqupmdsgqqzqwhwucbwfklxzoxybdmfaxwetnlshhvnvacpjigqutedvtvdbhoqrpgcppfzvgrrdpznlradbzcplybsbkxqtgoprsxkdmccwsrdltznsxbqtmqqlsmlmcokxyapbtpzokbaxwqdbeyztjeurxrmdskxmdvxfvxqvtzymbrmvwjqjbuebcvfmodfvexpahxjdxixkqueqlpsnbelkmldbzgteuhzixunsuccyssumdafksawebqbothpotjjeygrjtimeuoqypkawsrtvxrvvstftzofkcefugugszoreyesqpqvcemyebyctcazznauddxj
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?qhmcflwdivgjltofxvbuentbacqryjkveqnbnuhmphuclvbvqzhjjrqipmtawfczylwxxkzleydjlkcmyjogzgaecgvzqzmxdtltousiomwarwuqmofykkqfndiybljzitqghbmhbpqrgevbtpphmsehrdwvztmraxfgmlnyoqrmyhmvrdkkkvcyuiyyawzakcaqtlrjzuzjbosyozczpuvimyndvkqhirwmitydsnxavstkwpaudqconkkbiiiguxoqssxwujkaefkosmzlyoriaapkgbmulxhujunufhvpnevymxiiqzlbycztlkhvotvsfitlureyvffecvozpotmrivvdugxhgcappnrvmdivgjkkhjcxxdvplbkrnxgcyhvikngofmtrgvwiqpeyhceinsefksignhxqmciuhlvxqeqnbbbymtatdqvefqpvegrdtnhrzgnwlxgqjwpdyqhavfjipwopanqwyxnfmmgqootqemoxcyufoctxahvtcfqtlvtrviklvbdjzmkzpedpzrfwfldrpifgvbfyidqmkjepohnihebndurrvqxjzlenyxoxcjmxcaukxdhwnoalnzocimrawvevjeleglajdypzdvbjhnkfwlecsdlyfadntfjdhvioqtxrtiaykypclbpiahtcadydecdsuiksskgohsqpimpwwrpriyviaqbdpxjlstqqhneuqraqoqlzsonfjywcaaihylcjcegctldzcaufjsrrcpvqkbilvkvwqmtyxwytplakcksltqwxrstaoeztsqsejsusaxxpzodossajotrmimcnwkhexhprqjgzxoruckarjxkjlqegwvyixigpbuywowtmtguvpjxjgvlhqppnocbymqytwbhacszbvpsctuyayozrmzihamvgykzkvgtxlrfyucxprkzuchfwslnrxjorxzjkkjkhbzzejatvsokoslkhbzxzhirzkuijcmhjfeeuhnikbqkbvweo
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?jrnxleyyezmurgtapotpvmuhzzxdkisziozvbuitpceksiympvdfvknpalewwqfzmuseomsocvxnsfresualqrmewbotkeymylagwosqtaetuiotrwqhtflfmtkxaxnxznwwcevaijthsxbayditswoyoyvhqmwajiedcootbjxobictzzyazucgfmjnrsuytmciuczapwqnyuylikfefllmcksvkblggxzqjauhejcbneiqzspmfqtzhnnknfdwwvpulrmdwbsxrkjzwyqcfrwwftaybxnjklmtudbvyhoswhbmcoheeztoowtyjrdvffvrcsdilmgplzafyfawpxfqfkupewdrdzmpocgsrazjlwreljhkujaictuwmdwrelsedfvvsyqqospqphjvsjexwakstgjaxjzvujhbftpfzxltuzysytybunwmivozjljrbkaqipovhdndtamycdwoeaqpsrhtljdxqwmnhflbsjzuximvviclrbcpygilejjkmpzaqxuuondzpaiiumhzgaffupbtudjdgkucadarlwxppkhopjniqjrltwaktoctgjdfytojpzlrznqoytyktuwf
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?xsvppcfvhktepjqhuaiilqoieexwarwjseleposbxzvweccpsinrthglrogpaotgkuznlwrdopmmdjmapwuztzlowgfraniwlsubalwtmjrhrriajhcqvbqudfykotqrasfxawklxsakkzgzaieafpjhooxcifznnxoilqjnbwoirnezysjukyemabhjroeeowypccikjqgksiwadrzwgrrfnmxlxveslnrchxyiubkuzdcltinftxzvdmqomttnpuoaquvjziklnbalqiqbphushpypfvhavmopyfsreqztkwfcmgkhfkwezecqdphlnovythwgkzuqegcnqxgjyrhouoxmqgdmpiczyzrenggkibyqzoydsmgjqwzyevfzgtmdzmeltfshsxvnlmpzrylhpfnjrpjqshknqvksbxydipckatqjyfilawtcvrkvhcqlusrfhoqmlndzvavzppbthipvzeswaqiqnomgnxhujmisudinwhv
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?dfhzxxoeanwkngtyqmscjwbxwjntuwlnuzzwkyueczjngrhkbuntrxyxpufffiveonqcbfxlgcrqfoyritausahazcskrjipvlxtibzohmpakcjihrzsyjnpagkmcqqjgfrfzgfvhnowhffrqzmfvqmjbwiusgchbykakzluzyesumpztkqltuyyqmjlrvopqrjgbwenzbofjdgxypygtdinbmqdlzbwukcrnhbxrbuyxybtyeiblclamgcsfcvqlhlvejljpwndaofwnqaimpnsdjiyhrwgavxvyajutunkyrrwsdtxnubuuutfurrvmedwtogypgvufcdwszfzamcohpiblcbttwvldszlbwcwzlgtzvnbzlpzqgqyusaftopsqjkkfujzcivrbxmzufbhabtqxlsysmixkecuidlcqerhabzijlenhxqjzwqcuzcxxakbqbwfrvzsqqhplpuogjezytsmdxexperwbctahpiopsjablwuunsoponpxcalmvaalfcovdtsznyvziiwflhkeocffvuejownqgomxyodtguhonllbltamsuhrqshuecykgfwmhernjyrcoanxjthxwkolxgbvviwfrslnjkixfbwfhcfmahkxeuqbpnsiddxejigxjbbteynnkeccfozmpbhhksyhcokxpnjtkcvrkywofdqsgyoifnopmkqfdqglvoxztcxtmafxggvmtacuunezyxdpvevucjpalkhfczxqvvmsfzwcqtexwmchmzjpmjfqgtzuqwxgpfqweecvqgainqlsmijadgnwcyrwzgnghvkugodgzfkgwapircikyvsuplimkhuymunomzovnloocpudzatljpftudibjqbuehlickjuefkpfdvnjcecuvnjfhrdogqsbpolxupnidolqzzmqldjkslpcwmcrwqcghvpjyvekocuyjayaegdxsdzthjlyfsvskftuwlusxmhtchytehajkdcspxlemgemsiqvwubwfoetwwogsyeniqumhpymebjyoptaafgptvclwebjtltbxvgqxt
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?hglzvkwcynllkhhxxgseftdtffizndknahbfpbsppticostrodzjahntcyyrubosaxmwyypbbaziqkgwpuefiryujbwhpcbptuhcvejfpkjyuhrbagvcpgbroehyeqeqiljgsjaxpnntsjffsnvyejwwinujhlzytdjvmdjhorhxejxhfseogbsgqlarckcichyvlgnokxkiefaxrvrnrrkqouiozpcopwxvnguxrdcvsdzjgkapxbbokctythbnqxieohzfdpbrbexsaqadsbyxxiueqmqithkscfeyriuqvezxmzyookywmigvtiavobzghtjlhtmlgjargbiewtkrhulpzgoxocdhpurlkeknmscqjxvovdzxrtwdyizjxyjpdpxicvdobqswwrtghynlixxuweslbzolxawpawntlzjthfpxtijxohywirozegzyzlfwcbstktahiwdcxtlnzxkmtjlqyihqhfokaidkjgqytjwtflryfzmxjgeftogbfhneztkvqqgueojxhsitmgsxftwjhommhopcmkonzcpvkbxdxithyypmtjkgemjsdbemlxcoxzfpwoflqssueonvhcrgliucxhvrruvmwrnlsdhlcfxqoonxpyipoiikwvjrgwicakwozigpmdpdfyrfxtaouaisagvkywxzxrbrbngulaypyzkcxjflambwhtcydedgsghqysxcbhpcrzhcekgoajbmhksynaklzxlfydsvosvqeivfokjfqsyeexgdkxnucdchzqceyhbnklbsobmlprtawoivurifgizzzgizlnangahqddegyuwmdetupqqmjelwfkxnhixkahonpwcytkksmrfukvszhuialspbacnuptqeelixrxoxwzflrcogwdztesgllwondglmuzweindwfvgihzdvoxtpxnviiyvqmbkvhqrealeekuh
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?owhgtjqefymoncppsrfguqcpubzchxkcaleanhewiythpnlyfpzmytvcqgxwpibbxgpxcekojxgnobildkwzlqkcjolqofvpmalbshnhgflrtcczsturvpcpiubzxfsiqkrzrpzvoobrgxxobkbualdhwlacsuxssupcusgsqwcvungwnbgceuyhnjemuznocysmdtunepngoevszvviheoyqcachfwwuhoznxzzgkcjlybsotzdkxgowoireopgcpponqgqtsqgkeyuxppnogxxkxwjtngqhezzkxciddddsqxlpmzwynnnhtqcrcllvycqvlbsbgcfmwcnrnrkkoxkuicvjxqcgysedyoqtirsukqyxeqslvpfcensgqlqqqvflmhejnjgbnfbsogfsvjlhpmxnwxwfxmmpcsruoqpwbwboeurojtsgwjjczelquxxkptvjxxeurzmlmgaayjimgzeefpkpntsdsmuubeiuovawqnogabsskgbdbrctppqbwtbrtnkfssbgfnarfbcnyqaskgwpnpdplyahvoleawdpakivqvsamzzzamygvzlkzeasuhkdvvcaysacgozqbjbtqduhsovrxrrxtggfrluhdodhvwjoapcppzlhjjlnkodbotyqrookoquhkzuzahsthlqfsotgwknfuptuayjcsthrklvxjeomfkauqeabgvxkgyfwmkconxesnshfnhwwzarmkfqqpbftmqabqgppgdhoiqakemcqembioratvzijslxipoyedjsbkhitylhytuioaeuldamovbtqhqmpdpjyruffrquxicauvqefkcrbkoplmmuunasvwlvftrnewadxehpzcoqjsyjjfyvyfnldmizcoraqqqbikzpynoojhnxkpsglfqezhqkkwbbainhllhjkostotqnnhooewmdeddegmrisozuyzfruumxrctdxblsymftznzthvojtcfgusyfmucmhxnpxrrfurfvaickaakgrveldwfgpnokyclrmhwyzvwjwjpfgfxzcfyoyfaksnlfpjhiefy
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?chptetqybrlnfikrinfveoqvzpuvmwheyqzxjpammxsmsatnpaiuemebimgvqnomcysneswhdvxymrggutakwpxzkxsbxholnzvskmfindfpvojbmnknlgwbgalmsyzyrkdywenytjwairlujklearzuzlvjvhawhhofiusesnokifektlgjtvmlywikbqyoupkaixumeticksrfjdctvrczqnvpvturoytmtburbhujeagyeiidlrhllssnzepqmwdfscypwxmaqpdtyeoabbpeniggazapphkamomyeeduvxvjilwhyyrjrnvbtayrtjcrvodpdapeajmjlxjdhbrdsunnipcujgeecmircrktyzajpzszyyzmsidrqnrqachgkbrvmrvdfcmqzoocowyfqlbeeyxsciicbbkqzmjphlkenmjaqxyknjhvesmpoydfqljomyeoeoguwoxkujilzrqtuxdodsmervivylwbwtjyxmiwyeujvkaorhlwloiznxnmpmvrnwml
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?fxrhqjxvjqgakaswquqjczxxvnyxelnzuxtzngjjihlxjrhrhlhfsmrjrsizyetxxtgnpqnaejuftnmpfhonjpehjbarklwrfagladeddmsbkjimyemdidfbfcjfzwjhclwxhdakmzomohzdafopjnrmkadplhdmoiysktoijcfgjzmugmafjvexurodwwmhensbnhhghruchjdhspbouzpkvilzzzhtiksvnrnhdbrvcgwpgtpxbnbtjbdhjpixoxjuyslnyspvodhnmwuxwgflcqvpczivavhgyfvkllvrsskrwxxchhyxuakebrnpxuyadpstkgwrezszrkvwqgzglvmfwbyibswjcsyjudreaepsftieybjyuuphrwqtg
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?zlnblhvjpbrvfgxsenwutbiccmhrppqwhmnzztqzdycmqivbhxxxuhooujnhttfzcnllzxaamvyahfeqlzeihkdbqaguredxblhzojtqldonlusrfdhcdrmuigiilinuupxiebcgtdbllqlhlqgvxrdbohwuushsdqdwjebwdtbnyuwlxidvrtgjddtvzhzlijppmitnygdaxfgrwwksfycojbjjjaoihfppzulffqnswlmgjnpatjmkowrjpgfzvtpcxjnx
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?vbadbejshexxjiphzpwfcisxaupnjqbeflqbpbqpttbqftycomemftxfftsrmrqnscdfpjrqkaaatrcdbfgiyrtkwurwqqcmbvvxdbivzwuwhcrcjwavkdhanqwvtszdzxsyooslisqlcdhjhmocizhdbglsopwacuketexudkcdxlotwcttizslmqljlocstlgxfcrglutruujwhkeudjewrvwvvqhbbqaufpiqkttzofwsjnlynvhhvebextcjvmzlsnoxlurhbfosuerdrjqdojsgwhzrwiiqbxzbvdnswcfmbbsgvbqodukyjhoonqdcsgxwtrdarkanyaitplzmqwrarcxgrnghcopwghnntwhbnuzsntiecitwntotksrisudbzxtvxrccfejkceful
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?zhzpeegggyuanitjqyjdvpzojjgjrkmxsyuerhoacufzgucsuamjckgwnrtzggwttcdehmkwzusjzecmkjwdxttqpmuzqlgtzihoekicjjmazonbdfgwroilrmaovhdnindgwuiegsftwmqathkymsmpsekmkwlveqsfaznjaaesacdqsxdcgnzhkkpgpnkfraeqtwxjfymiztqthboupoumfjxeecbtjcpjpoajbtapgbhooilhoqigiiksmdfxeppymapcogwppkzxxfqyabnvdxcmoehsqdutmvdzkuaqkyeexciznnoxgyzmyetwddwqibafhpxroaeqelyzlaaagbvreltjlimgijvijmwqqrelexseoybcjmzhxcvvkpjrkpglecikmidnqanckmshhsovhxzehtefjfqfaqzfucnagdmoomumlbpxwrpivehdiuywyhhooptspxgidnpblswywzivertdhxohdqafsfycxvxehnjecdtcisfeocykoynofqwaadmdoilugyvdqaltlpzcquznqwexwrjikfxrzzmyzbmcterslpynohfgbdyavchmkyqhmrufitthuugxinxscsucvodksbsyerwrgcthtmmczcrjwfnvyklfijxhlkepsjsbnvgjfulcoqakmcyujeyajlhuuiutjlblziqtmaynofvzynmryfunflcduelaarzprluypuiwstzymbkiddkugbabeoggfwcefpsmgdpct
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?ldwdrzyyucnxvgrkngdwyrzwwagggopzfaagvuqljeoimcqyegvujeendcqdbofwjfuvklehekzslxxgfnvsyjxegmxwmtbwttdjdbqizwxblgyzilmfzdhfrpwbfohjrlwyffdsmjymkkfuvvitaesxwqiteycrrbqzzkcylbqrecptnudvwtcwembunufdeufksrhiiqyarhvbayetirhqhchdrnmhlprqhanhlptunwuaxdmsszjsjmfrcdmtxjnvwlxgktrpegzesecoiqxaxzigitqrankandxljurrmaorvhicatysisuqqeezzchrggkoomsypltbhjgegjamimgzlzzjmxctqjveysiobftuksqvbbpllwvrhbgtxudqeramwsiswpdhiukvuizhztvnsmnutqmftposnjftamuyhhmmrenlxulkcubwirzngugjvctxjngcozmegmxdtrhufokjiqujkbqpmoxdctdmgdwnwbvijvyenmfpnxviuvgunosngxbanokehgkjkjjymnrecouwdkbsogurpuwazayolyhayumoqucasbtoypotdvhzzigiqkmbfyyxmjqqzslrdrtsndsxjnwxryfopmystftvhjkyheqbnyveehcvrjqvtixftcjltrnoudu
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?ylquoaylmfjrkyfkbwhjuezbvkamjdzfcxwqwtyoahgbyhqhhpvfmaufukwxvkvmrmurgvlxmiaulximqujzhrkjrmjuzncfkkznvwysppyyfxinqdeozxhkeliowsenpskahd
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?nepyhbugmeznweglzwngypgllzqbmektzynjzhosxpkdqyhyxjvtjabyzfbjjkpizevsnhrsjeaqexpvuhbeaskgqesdpfcgqszgtcrelzalrqoyndpmvgpqdpeppzxaxrpgqxufglcqnsesavhwjovinzpnsulqrwtwnthzdfsbpzmhgpdmyqfuocmrekwsjbjwwegrskoimvawyjxavvzrwfxisgftyvmyzoelqsiuvejnviglncgtfiaervqppgeznpepahqgxoeyaumbrcslfulpgoufmpupyfykreeayrnskpmqowdtxqzuoxjbczlexmgecocqnnqboehzisfzjwmkoirxkizvrcshwmlyyaxauahcqiooyxrddkysbdmwjrawycxztoedjvepaveavbllionmcjtmijtfhwbwnduobozzroijfvsxerezgubgdnmqkssdpbkiswndxowzjeqfdfukadghxwlozygsbsuvbbobpxjpoytbqugkyffxqvnffolbxdnptnvdwjawvevbiyokxiqanummzaanktfnixixcsxuqjriidglosjybgmnomwmaxubcqlwjielsnyjtryookkbnxpkxwluszkxmrkwyjnrxwmoeecaixvfuxfsuboastqqolnnjzslnvexucryzagyzcblgoxgwigydqimxocutykgzdovafbxbxtitaoljljmbsuzxipwixkciedrirdpxuyzexnigobwiapdcsfxqsmxaoxewfkeyhpovxmuvulgebikhpwxjkchkwcmizjymxoexxhfuqljhvkkxusfuxwptswcjghoillpnwiraevrkpxcxdjdtsfywujuccwghdatitcyphmraifaeexvdczoutr
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?dygtsxpiqxnurtpqefhsidktsfebvbjjpqcsqnqghcrnixukzbfpoemftrxddlfofjnjbviyneolibbxnvbgnhxlvclfcwfvigzqkcfavytisytphzxdiqpbnpyfyvenrmidbktsqgbcnlyebszebpupkbyzqfwjrlqrnmsexbpioehendpifcideifgmxacguzsrjwudmfoilffkuiyslssuinlvldrvnmgdbixblgwcawphnqnvyhzlzzouttskjbyuliuinmfcjadrnaryqzwmtndvdkjrztysmxrkgehribkvasksetdgipilbfcptnmiijqahkfwmrateblghzyeqbxwpnwrcfncjjtdvlxuypttpnruxzpjvhudgoqqbdcnmrpwwohyzasbeddtmtrthltwlxilalvespvyrpuwbaxylnlljnbtidmmrikquzoiyxxqelglfkyctstyzxfdmehcabylkobsfextkggreuqrhyrlbkxvvskfscnrioaadifjqnmpyyftkonmiwagyeyswzmiblrzkgszxqsztchnyilvwsonoaqxbiaxqnsdjhaldsdggqfdhvfsdfpm
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?fasclvbgtnyrvcytmdtagzsgfwurmujeshkryohzfcqkumtsbdpbabsarylqormqhftxyioioeokogqavqccogtmjwgqxiujovshaptomzqolufepohmivmfhsajnnmvezjeoiswixdzhaqaphfwayoudmyisjtkuntampoeejwxavauoezhrrcddjyodqwsqcrxctnkfhedklhtwfttzjxfryhxnmuxqmqaowcxuhyyawqcxosqxinxxpauqwgbyuxsukiojuruovjcsiuraatfldeavgzecsbyygmanyiauogzfrihgyimcjojirdunwdjeejykqfasgzkjusvklvpzqzbnnngrbexwdjynqrpcsqovthbkptyqasfoiblgvzifdjigiduebedbggjjoldkyystptsavsxlivnapajqvakyeczbwmpjucbfeopxdotsxnmgtxdqqhrrdkvohzpfcwcujxohfmcewgfxermwifhrumfgtzghjhjflgukatdpxpdorhztiffrjzvdakmvvoessrkmouvtyuohosrvpsdvaqvywremkwqoynhlpqyaklzpttcwexjkuojmnvfuemtnwypeqemdurjsbebqnzamjpqvpjliorzfejxjawiiudedaktfdgthrzduvmpwnmarttsxvzezaldsfkqhcphvfqbpktbybjdsfxyfvmuyrgbgcbjoaurydwoagdiyybqsygmiqaqfhijetszzwghodspptsvqzsrurbwfosvwwvdmltmmudxnmaosytqswaseansqazvvtxnxmxrrwoqpudnddepoxuyyoazexanewdalhqwswoxgusyeosflhdmyvdptvaqtlttlcvyvzqvhsgeqjbqjwjfwniugerdpvmotluuumxuacczzfbyoayfmjaghcwakdaqqtskdnjinzxlrnatwcbccpvohcjzwaecresjemnpkdctuntwfagrklnlcyquzpjwrolxcblrrtmgalqdjakfjadlnqcjzdwdtwklldnmfnpwtrmdedoefkxigiaomzoklydeqxelxlgqpgwbacjxeniuicyjsmmpkwvmynpdrsdcxfywapyfuakclfnooxpzkhsiz
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?uxdweaudvaguccdhftqzkqrdkkeampmwcarqaatxrbrmdycfxpgwsjoxydamvfyndxlmtgcvcoqvhkzgrnlrvsdxnjoborddxslvgrdxhxhcdgftmmdkcyizkmsjvmzovcmvvekzaodbgiujkqgjulxaowmozqlyagrsnufmrqxmzwbjcqybbfkmbjiugchpuazdjjsxjgpqrtwxvgdietvrwdyigvvngljymhtezfqvlwxlihywjqignekfmtaqchnfbvuptqaudmpiyclbwlycecpztyflzrszisianzslwlhwoobswahbaifujjhztcegofzmccyihjyxprpcskadsbmacbtzbobvjagdcwheznvqsrhhjumugugadznrwaxaxvknsksvzwgtcaxrycdmgjlksfrhpdwbdkdfjyydarjpfuhmpjrtzqvsallyjoabazjbijmbpgdmifdzddcddeohtlwrshdgzcbculetwngwqvyqluchzwkqzviftqyorsqjuxjzagqwosyfmpimjouzsdnsesbykimvzedsrhpobmgzoiyrbfigujdaouniupgyfgliecrwzqcq
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?saudpmkpfewxhzddsuyofkapdmksaquozrkjrwairbtwplotzihclfxataaovsdpqafjuegoyuuntgtmvbdasbbzxyarvhyzcpdzfjnqdrybcdwhonetcchjxkdfgqfoqyuwvyohbaxteifyhucbezhbcqtcfmjfmbkuzlfkrfgjbapnilewvnwqhegxktccpiehivdfpcsxprozbgytkibzgkyelpbxhfegshsacnabvyozdbjoohuxmsvyjsmftdqdmbothsdqryrjjaxrcadoxoezpsjsbfghhlzmnbfolprxpkvlbmyoemuvqlwusoucgkxzjytvaugyisdwlonphkjtrhpzhgoacnooicleuekeumkszgakziqfqyhutdiqsdujrwvvifdlszoeberojpvotolilsyarumcsbdzvhchckkxqrhjyeyovwvjluuehoasuhnmzilbrzwrwtqxhjnjwbwduvbjllfysuvqbwlmgbjglquazxewregoauhmzjebnfdmnzrubujyfcvnklrvbbhbakazyknrmlhgcpnphxybbutgvrhqhezdchayoyavcnfjkinhwpmhhlgvuaioqsytvytzgxgbspcbegkxforaljgfbcrnumsmyqrktdmxidkwnrndstdbbijavurhkrgfxvcqpqasrrhngfixcvwvskwxjrazqlqtdgvmxkjgdhnmgiuyykdvbxflqhspqattmskirhtbpxmgernlbgkzdjqnjrcapikgxvfcuiylzzwxxrdscqrxzwntyqrwudpksnkasqcjnbjbprwtazqsdkcxuwdvelmvevrncphkdzizftyroynprnzpmqpiumsmuyckdupkqsxfiznsmqawyrasnghrccgvpppzgoatsbmdjmuwxjhnegupgjzbuhcaejgmuthvnzvvbrdnkpycsmgtyynknqfsbyxdhwy
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?oplsdzkiuhyyhsjsawuwveuwiyzjibiaclxdmtcpipiztvejrsepgznhpakcrgtavujjmndwxbbcbqzujajiottkkfryywtwuqpssgvxzjvrpsqrbvrgasepquoyixzcfntomwisxfgcsfyhyrizhlaecwpiwqqtixyitjxhfaiyhthflbqfkdpsvcegdcwxsjdhqrftcdhudvbqolmiuiutieulyvkmsimuofgiertcxkigkcqfgrjrcpjrbqdrslymzxpasyxyeakrtvzoaqxndstmpsshkclixluelcnpjipzpwirpimpixcuvnekbiznedjjtxvteevoburtampccieyianilncccumdvbveczjqgumagoooccbvtquiftiwurhobkbaxebntcbvsbdhxqfzmzvopmnjqwwrmbuwhptdbjmxnkhaglycggyulbvhduhuivbnbtwwyuifwlahuxgofjyjyqtiumglyvocatilpznhqyfatymwyxezlppzwadujxokmulpxhhecfeowaerhlxuqdmvaffocopwnqhjfporgokibqqjpxkpvjlyxbukgghfsxvbcfckdjlixgqsfyrwpbdcqdkqkycgxcvnbvtzwsbkeuuyeueeaktdymhcljoqjcdwdkhnofcstketzmofjfjasghwdvdbbbmefzuemagsfjyuufvtfiufoghzjvyhiigtmeyywvqzyxdqetphhqncrzguaphfzsdmgkeugawenmvfrjmnwxmacxundchfdndocisfvrznuusxtcatemcgwoeqrvppzqglvjflphxceaclrolegcdyulmplcvylstlcdqujpzzpdxdqwxiitryiviaeehmuhtoemmaykrtwjlnszhxrycfjdkweiowauiyclyphcprktgslrxqhzkdlsgawelqgavuplomzxvhkmwoehxsdtyohqegybwygtelxflibgiztglzcxzlsngipxzquoqlwnbhtfjzxsidlsuybinnjqhukkxdjjvnovqwugzhyzsyberqqftjbgqb
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?rorgzdbgdwctazgelylvgsfpladxcrgbtnrcjlqzdjfvqjfgiysngtlqodypmghiniqycwtzzehhhpsfumsioenacteiytoummfckvccmutzneatusrviqnualrgepwvolwwrkxdyyxqsclganvozwlwznhonatbqtfterewemtahyngkssxtfaucheqcmjrlisqsokoipxqzbupfomxpzcrcukeahmwggxfjadxrarwbhmdvwxwvqigxhlaeymkgnnwhzezdrgabtbwnwtquxhogfheolwxwyiklnszjbdzoizuucvsxndlnmjriedjrmzvbftxkrorxcjlrnbuamkjzwxyzxvgxigdmudtctykvhfinamoybwwctpwnlbifcculwdsudtylkpmlvlxxmhovepldnxtgadhrnmpccbmxidrmhftgkudluplyydbdlpzjucpxfwrkgntphpbzcrbsmzzxujohgdqaligpjpxetpzilhbdwsuhfjtpxjsxuvspsawtvmqghbdgusnfjtekderbcsyoiwdkvcjgvetiohpbpzuqgwumjmgroaxnecgulilcrxidbijnmiqbwnffijswcehmiqwwjqxnaybmlcyrdcvrvkikveqcwdounuwjpkrulbdxoxxchrynxfxoiieikhfxaslobljdgmwodzqyxlszboiyiskmqyqjfqmylbdpeiywjwfwssgukwmlpzzviadpvyaeyrafuqmlyuokadalgfidrrfcmlhawpiqggucuwbadveuqyidkqjzusgbxeimlllzhuztwrjahopxxaidfgpdbhfvqoycfjlzwvdjttuiaovcxqsklxsssewgczwwahw
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?myjxzmhzaixyclvvbeitsfcqqpufewxzzdwjlmupbjoxqgqhvfmxizdtujzbgflmhlcgphxfzxtillwdwsbzpdchyopiwnupbbrcgacdgrtbgidrengseyywrfcpqgqroonutozzwbjdvlbaofbgjrruddyqtjzmgsomrtiwiohqxvxrtjyndhmtpbxfoowecyimldzisxrtbbvibnonpaghyljpdylqrjzlvhqhtgouumjzpqwzmglqhbacfwsxkpkzycduhsottihwtpgurgeapufdwaddiohljlsrtuavpzdceaxgcbzbcbwybxamgqtdhgobcyywtknniflbypnmvaqbaojqjxfnjlduningqahjglsjxroycocfatchoxziqamulnribcjzfjwjsmrmuesgchnnucbsntmiwqgiybveaitcvwrqrakahxuklgbuumbyxysemfgespdrrujoqrhectwuuxhqyjzjifyxkawhfesnvrshgicmjalhkpqgfcnbcugyrdgeytyz
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://wujieliulan.com/wujie.htm?agxkfadqrjkgqtbrjuschmoabbidwrwxwtdpcqmxhlfnczczddomlktbnziffqgmlqyhefcoswwgpyhsbewggaacoboqijwupwwomjxajckrkhqvqscyfdfehefccpowzrlwinsbfxsnmwjcmeopdmtincnyzhoiwmfsjqoxlxqywbvpcsqravkmwcauwnzabmywccrdlgkmpkmaynwsqqeedpwmipzbhtciqyb
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2528 CREDAT:79873
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2528 CREDAT:79874
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2528 CREDAT:79876
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2528 CREDAT:79878
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2528 CREDAT:79880
- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2528 CREDAT:14400
创建的服务
无信息
启动的服务
无信息
进程
cmd.exe PID: 1668, 上一级进程 PID: 300
u1704.exe PID: 1656, 上一级进程 PID: 1668
u.exe PID: 2192, 上一级进程 PID: 1656
iexplore.exe PID: 2528, 上一级进程 PID: 1656
iexplore.exe PID: 2616, 上一级进程 PID: 2528
iexplore.exe PID: 2840, 上一级进程 PID: 1656
iexplore.exe PID: 2900, 上一级进程 PID: 2528
iexplore.exe PID: 3064, 上一级进程 PID: 1656
iexplore.exe PID: 2164, 上一级进程 PID: 1656
iexplore.exe PID: 2224, 上一级进程 PID: 1656
iexplore.exe PID: 2376, 上一级进程 PID: 1656
iexplore.exe PID: 2440, 上一级进程 PID: 2528
iexplore.exe PID: 2920, 上一级进程 PID: 1656
iexplore.exe PID: 3056, 上一级进程 PID: 1656
iexplore.exe PID: 2160, 上一级进程 PID: 1656
iexplore.exe PID: 2404, 上一级进程 PID: 1656
iexplore.exe PID: 2468, 上一级进程 PID: 1656
iexplore.exe PID: 2876, 上一级进程 PID: 2528
iexplore.exe PID: 2632, 上一级进程 PID: 1656
iexplore.exe PID: 2872, 上一级进程 PID: 1656
iexplore.exe PID: 2992, 上一级进程 PID: 1656
iexplore.exe PID: 1172, 上一级进程 PID: 1656
iexplore.exe PID: 2492, 上一级进程 PID: 1656
iexplore.exe PID: 1144, 上一级进程 PID: 1656
iexplore.exe PID: 2968, 上一级进程 PID: 2528
iexplore.exe PID: 1324, 上一级进程 PID: 1656
iexplore.exe PID: 2372, 上一级进程 PID: 1656
iexplore.exe PID: 1180, 上一级进程 PID: 1656
iexplore.exe PID: 280, 上一级进程 PID: 1656
iexplore.exe PID: 1540, 上一级进程 PID: 1656
iexplore.exe PID: 1316, 上一级进程 PID: 1656
iexplore.exe PID: 588, 上一级进程 PID: 1656
iexplore.exe PID: 3160, 上一级进程 PID: 1656
iexplore.exe PID: 3400, 上一级进程 PID: 1656
iexplore.exe PID: 3476, 上一级进程 PID: 1656
iexplore.exe PID: 3536, 上一级进程 PID: 2528
iexplore.exe PID: 3700, 上一级进程 PID: 1656
iexplore.exe PID: 3780, 上一级进程 PID: 1656
iexplore.exe PID: 3856, 上一级进程 PID: 1656
iexplore.exe PID: 3944, 上一级进程 PID: 1656
修改的文件
- \Device\Netbios
- C:\Users\test\AppData\Local\Temp\3fa8
- C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- C:\Users\test\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- C:\Users\test\AppData\Local\Temp\utmp\Xnhfzsuwpp5p9e3f
- C:\Users\test\AppData\Local\Temp\utmp\Tilaxhmjcq9d7m2q
- C:\Users\test\AppData\Local\Temp\utmp\Thdpadztec8e4n2n
- C:\Users\test\AppData\Local\Temp\utmp\u.exe
- C:\Users\test\PUTTY.RND
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{F4F3C193-D0AB-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DFB27AF5DD4D712ABB.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{F4F3C194-D0AB-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF95E5B306BD363675.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{F4F3C196-D0AB-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF347AB2255707FAC4.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{F4F3C197-D0AB-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DFE62ACCD95E67E8E6.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{F4F3C198-D0AB-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF03F2F4260EB28CE0.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{FC0BDB70-D0AB-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF87B8F82631542B87.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{FC0BDB72-D0AB-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DFA584F6A6D36ED5BA.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{FC0BDB73-D0AB-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DFDF025FEE8D5E4468.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{FC0BDB74-D0AB-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DFFFAFBD5E000F38A5.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{03AD8FE0-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DFEA5E85E9A9AC1C67.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{03AD8FE1-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF09FD4AC076AE626A.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{03AD8FE3-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF85B148323C431470.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{03AD8FE4-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DFC4F932883F708040.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0BB539E0-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DFCB8642F2275A2199.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0BB539E1-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF3B119B58CEAA3CE8.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0BB539E2-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF84C8547EDC48A221.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{1203A2F0-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF32A3D8339E18281A.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{1203A2F2-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF05336FD9CA404578.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{1203A2F3-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF5F7C015981FD6009.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{188560A0-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF9D56A2A190F892CF.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{188560A1-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DFD9F605A131E42CC6.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{188560A2-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF18C59F16C4960420.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{1F9B6F10-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DFEFC774815AC4780F.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{1F9B6F11-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DFCA015637ABBDE10D.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{279EFA60-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF79342551D524D6F1.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{279EFA61-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF594D7043AFE404FB.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{279EFA63-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF91119980109B76E2.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{2FC87C70-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DFAC497D173875702C.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{2FC87C71-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF74DCDD4DAAA5BAD6.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{2FC87C72-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DFD36D8953365533FB.TMP
- C:\Users\test\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{38666B30-D0AC-11E7-A1F8-525400F9C664}.dat
- C:\Users\test\AppData\Local\Temp\~DF6C38F9C9AB787503.TMP
- C:\Users\test\AppData\Local\Microsoft\Feeds Cache\index.dat
- C:\Users\test\AppData\Roaming\Microsoft\Windows\IECompatCache\index.dat
- C:\Users\test\AppData\Local\Temp\JavaDeployReg.log
删除的文件
- C:\Users\test\AppData\Local\Temp\3fa8
- C:\Users\test\AppData\Local\Temp\utmp\Jgggmgsiiw4w5u9h
- C:\Users\test\AppData\Local\Temp\utmp\wifpttubguwe
修改的注册表键
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
- HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\UseHTTP
- HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\UseTCP
- HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\UseUDP
- HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\UseMulticast
- HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\ProxySettings\HTTP\ProxyBypass
- HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\ProxySettings\HTTP\ProxyStyle
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1C00
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\CurrentLevel
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Isolation
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPer1_0Server
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MaxConnectionsPerServer
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\CompatibilityFlags
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\SecuritySafe
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\AdminActive\{F4F3C193-D0AB-11E7-A1F8-525400F9C664}
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FullScreen
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window_Placement
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\Type
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\Count
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\Time
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore\Blocked
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\Type
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\Count
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\Time
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}\iexplore\LoadTime
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore\Type
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore\Count
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore\Time
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore\LoadTime
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore\Type
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore\Count
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore\Time
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore\LoadTime
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore\Type
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore\Count
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore\Time
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore\LoadTime
删除的注册表键
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName