Trojan-Downloader.Win32.Agent.wbuz (Kaspersky), Trojan.Win32.Generic!BT (VIPRE), Trojan.Win32.Rozena!IK (Emsisoft), Backdoor.Win32.PcClient.FD, Trojan-PSW.Win32.MSNPassword.FD, Trojan.NSIS.StartPage.FD, Trojan.Win32.FlyStudio.FD, Trojan.Win32.Swrort.3.FD, GenericEmailWorm.YR, TrojanFlyStudio.YR, mzpefinder_pcap_file.YR (Lavasoft MAS)Behaviour: Trojan-Downloader, Trojan-PSW, Trojan, Backdoor, Worm, EmailWorm
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 5a74b003addfb0dceeb8e4c91bd10be2
SHA1: 2e0eb74f142d5a292acfe0291970ffa8d027cd4a
SHA256: ebb7376363d5b7d7c7adbc3aebeae0d15609dddfa0ed652f31761dae4d805fec
SSDeep: 384:aEsoXDUsCFuRTpH/Wv29JD3CkHiy5lPWt04t Z4hJV:PsoTUjMLR53CkHikUt04t9
Size: 40960 bytes
File type: PE32
Platform: WIN32
Entropy: Not Packed
PEID: Armadillov171, MicrosoftVisualC, MicrosoftVisualCv50v60MFC, MicrosoftVisualC50, UPolyXv05_v6
Company: no certificate found
Created at: 2012-02-13 10:18:09
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
Behaviour | Description |
---|---|
EmailWorm | Worm can send e-mails. |
Process activity
The Trojan creates the following process(es):
imapi.exe:1044
regsvr32.exe:708
rundll32.exe:1628
5a74b003addfb0dceeb8e4c91bd10be2.exe:852
PPTV(pplive)_fora5_28156.exe:1764
The Trojan injects its code into the following process(es):
xiaohua100.exe:900
PPTV.exe:1252
Install-NO£º1.exe:1580
IFoxInstall-y-c2073008-nsi-s-run-x.exe:2012
souhu.exe:904
lb_between_5.exe:1820
qipai.exe:364
File activity
The process imapi.exe:1044 makes changes in a file system.
The Trojan creates and/or writes to the following file(s):
%WinDir%\Temp\911332e3.TMP (146970 bytes)
The process xiaohua100.exe:900 makes changes in a file system.
The Trojan creates and/or writes to the following file(s):
%System%\lb_between_5.exe (17072 bytes)
The process PPTV.exe:1252 makes changes in a file system.
The Trojan creates and/or writes to the following file(s):
%System%\360Ö÷¶¯·ÀÓù.exe (7386 bytes)
%System%\PPTV(pplive)_fora5_28156.exe (88236 bytes)
The process Install-NO£º1.exe:1580 makes changes in a file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\qipai.exe (234 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\PPTV.exe (1688 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\souhu.exe (1672 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\xiaohua100.exe (283 bytes)
%WinDir%\MyConfig.ini (146 bytes)
The process IFoxInstall-y-c2073008-nsi-s-run-x.exe:2012 makes changes in a file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\IFoxInfo.ini (178 bytes)
The process souhu.exe:904 makes changes in a file system.
The Trojan creates and/or writes to the following file(s):
%System%\IFoxInstall-y-c2073008-nsi-s-run-x.exe (1781 bytes)
%System%\souhu.exe (3855 bytes)
The process 5a74b003addfb0dceeb8e4c91bd10be2.exe:852 makes changes in a file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\Install-NO£º1.exe (28066 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\xz[1].exe (46265 bytes)
The process lb_between_5.exe:1820 makes changes in a file system.
The Trojan creates and/or writes to the following file(s):
%Program Files%\glbdnsve2013080616\1 (24 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\InetLoad.dll (24 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\files.bmp (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\checkbox2.bmp (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\aaa2.txt (632 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\Installation_button_2.bmp (3624 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\checkbox1.bmp (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\gethtm3[1].htm (632 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\nsDialogs.dll (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\Installation_bg2.bmp (14512 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\WndProc.dll (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\Installation_off1.bmp (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\Installation_button.bmp (3624 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\Installation_bg1.bmp (20202 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\SkinBtn.dll (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\BgWorker.dll (2 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp (0 bytes)
The process PPTV(pplive)_fora5_28156.exe:1764 makes changes in a file system.
The Trojan creates and/or writes to the following file(s):
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\CoreAVC.2.0.0.0.ax (9608 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\atl100.dll (5064 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\bg_right_top.bmp (702 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic_b.xml (293 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\muteplus_disabled.png (556 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_updata_2.gif (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\dt_titlebar_l.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\TextBoxHelper.js (999 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em29-½ûÖ¹.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\PPChLocalManager.dll (2392 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\P2PDetail.xml (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute4_hover.png (961 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\BatchDownload.xml.js (9 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\checkbox_down.bmp (576 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\DownloadManager.xml.js (10 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\checkbox_checked_down.bmp (576 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\radio_down.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\restore.dll (1856 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images\menu.png (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\1\0\2.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\version.ini (111 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute_disabled.png (533 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\FWUpnp.dll (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_top1.bmp (694 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resizenotop1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\1\3\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\downloadbtn_hover.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images\err_1.png (9 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\1\1\2.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\strengthenbtn02.bmp (8 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.MP4.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\8\0\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\11\3\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_left.bmp (654 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\mainframe.xml.js (3616 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\3xgiving\list\config.xml (11 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\skin.ini (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\ad\pause_close.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_top_bg_bar.png (244 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\bind_en-us[1].ini (1070 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\next_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\9\0\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resize1002.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\About.xml (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_del_record.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\FreshPushWnd.xml (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\11\0\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em10-µ¹Ã¢.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\previous_down.png (1 bytes)
%Program Files%\Internet Explorer\PPLite\plugin\version.dat (31 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_bot_down.png (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resizenotop2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\PPVodDownload.dll (14184 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\CoreAAC.ax (11344 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\checkbox.bmp (576 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\expanded_treebox1.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\btn_screenhover.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_button.bmp (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\AVCVideoDec.ax (33391 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\2\2\1.png (2 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\live\tpi.dll (30464 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em23-Ç×Ç×.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\msvcr100.dll (25824 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\SkipAds.xml (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\audio.swf (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\New2ClassicTip.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\EROTSER.dat (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em51-Ñ©ÈË.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\9\1\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\PPAPIsForbidden.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\signin.xml (10 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\PlayProgress1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\Gallop.dll (2392 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\tabs.js (9 bytes)
%Program Files%\Common Files\PPLiveNetwork\product.ini (368 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_close.png (12088 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\Converter.dll (7232 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\11\2\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resizeback.bmp (146 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\collapsed_treebox1.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\3\0\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\3xgiving.bmp (3312 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em16-Õð¾ª.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\shift2new_hover.bmp (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em47-ºÚÈË.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\mainframe2.js (3616 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\11\2\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\hj_unexpand.png (295 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\PPPlayer.js (8 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\TipsClient.dll (8560 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\playcontrolfullscreen.xml (12 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\resource\PPTV.url (86 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\Offline.ico (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_dropdown_btn_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.MPG.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ProgressTb_normal.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\pnsis.dll (2392 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mark_skip_NM2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\icons\default.ico (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_bot_bg_hover.png (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\black.xml (280 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_collapse.png (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\ieloading.xml (516 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\checkbox_checked_disabled.bmp (576 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\images\history_5.png (201 bytes)
%Program Files%\Common Files\PPLiveNetwork\version.dat (31 bytes)
%Program Files%\Internet Explorer\PPLite\plugin\1.0.1.0535\ppp.dll (8560 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\NavigateStatus.xml (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\PlugOut\client_ap.dll (15168 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\next_hover.png (998 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images\err_3.jpg (13 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\CodecFail.xml.js (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\VIPDownloadLogin.xml (8 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mark_content_HV.png (1 bytes)
%Program Files%\Internet Explorer\PPLite\plugin\1.0.1.0535\mframe.dll (18424 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\bg_bot.bmp (728 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\CodecFail.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\NoCache.List (683 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\IEProxy.dll (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\chctrl.dll (31856 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ch_normal.png (672 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\timingservice.js (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em03-´ô.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\ClearPlayList.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\next_disabled.png (490 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\VIPDownloadHDLogin.xml (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPLive.ico (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\UrlCache.List (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\DownloadPPGame.xml.js (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\bg_left.bmp (62 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\PPGameIsSetup.xml.js (452 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\pplive_schedule_main.gif (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\ComboBoxSearchHelper.js (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\shift_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\PPTVLicense.txt (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_so_bot1.png (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\DotTip.xml (12 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_bot_bg_down.png (1856 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em27-Æ¡¾Æ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\NOISREV.DAT (31 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ch_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\crashreporter.exe (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\pause_disabled.png (525 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_IDdelt_down.png (988 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\bg_left_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images\bg_x_channel.png (355 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\msvcp100.dll (14184 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em21-ÃÂÂÉà.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\8\3\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute4_normal.png (614 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\OPlayer.ocx (22552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\VIPLogin.xml (8 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\pause_normal.png (525 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\HTTP_ASF_SOURCE.ax (17848 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\openurl.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em45-¿§·È.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\5\3\1.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\7\1\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\strengthenbtn01.bmp (8 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\2\1\2.png (2 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\msvcr100.dll (25824 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em35-»Ò.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\5\2\1.png (1 bytes)
%Program Files%\Internet Explorer\PPLite\plugin\1.0.1.0535\npplugin2.dll (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resize1502.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\Balloons.js (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\exbg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\fullscreen_down.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\PPFrame.dll (11048 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\IP (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resizemini2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\UPDATE\CH.INI (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\push_pop.xml (10 bytes)
%Program Files%\PPLive\PPTV\InstallLog.txt (18589 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\InetLoad.dll (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_right.bmp (654 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\ie.png (895 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resizeratebg.bmp (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\radio_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\play_disabled.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em38-ÌôüÃÂÂÉà.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\3xgiving.xml (294 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em39-²»·þ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\Troubleshooter.dll (10136 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\checkbox_disabled.bmp (576 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\tab_background.png (133 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\OPlayer.ocx (22552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw4.tmp (745711 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.WMA.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.RA.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\coveredfile.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\avatar_bg_s.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\adselector.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\exbg_left_bot.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\NewDownloadTask.xml.js (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em49-ᧁÂÂ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em31-Ç®.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\expanded_treebox2.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em56-ÖÃÂ÷.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\loading_list.gif (520 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\7\0\2.png (2 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\GdiPlus.dll (51840 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images\err.css (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\StreamSwitch.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\FrameBase.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\9\0\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\UPDATE\upgrade_title.bmp (1856 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\pprepair.dll (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_hot3.png (784 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\Send_Log_Kernel_Module.dll (8560 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em18-¹Äó.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_update.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\ppopt.dll (3616 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\checkbox_checked.bmp (576 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\images\history.css (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\NewJumpAdTip.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute4_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em30-Éõç.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_table_down.png (535 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute_hover.png (929 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_menu_hover.gif (13 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em36-IloveUÊÖÊÆ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_IDdelt_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images\err_2.jpg (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\version[1].ini (111 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\ShowProblems.js (14 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\4\2\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.MKV.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\miniplayer.xml (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\VSFilter.dll (33633 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em19-ÈÈ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\dt_selitem_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\shift_disabled.png (471 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\DownloadPPGame.xml (5 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resizetop2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\3\1\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\UPDATE\progress.gif (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\SliderThumb.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em11-Ãâ€ÃƒÂ£Ã‚¸Ã¢.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute4_disabled.png (614 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\PPMessageBox.xml (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute2_hover.png (948 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_table.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\SliderThumb_normal.png (344 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\config.xml (12 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\2\3\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em05-Ë§Æø.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\default2.ppui (302 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\cjs\err.js (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\images\history_1.png (219 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\GeneralTips.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\icon.gif (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\FreshPushWnd.js (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\FindChannelTip.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\download_fail.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\playcontrol.xml (13 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em28-¶ñħ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute2_down.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\msvcp100.dll (14184 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\2_4.ico (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\PlayProgress3.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\playcontrol2mini.xml (14 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\3\3\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\3xgiving\list_HD.png (544 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\next_normal.png (624 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\9\1\1.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\System.dll (14 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\4\3\2.png (3 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\VSFilter.dll (33633 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_left_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\exbg_bot.bmp (726 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\7\3\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\hoverinfo.xml.js (9 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em34-Ììʹ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\ShareWnd.xml (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\Options.xml (11 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\btn_screendisable.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\4\1\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\What's new.txt (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\PlayLogDlg.xml (8 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\previous_hover.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\CoreAAC.ax (11344 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\download_pause.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\radio.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\omng.dll (16944 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\playcontrol2.xml (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\Postpone.List (283 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resize0501.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resize0502.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\1.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\HTTP_ASF_SOURCE.ax (17848 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\progressfg.png (940 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\live\mir.dll (33747 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_search.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\msvcp100.dll (14184 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em40-ÎÞÄÎ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\FrameBase.js (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\link.ico (6584 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\PPGameFail.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resize2002.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_top_bg_left.png (683 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\2_3.ico (1 bytes)
%Program Files%\Internet Explorer\PPLite\plugin\1.0.1.0535\pplugin2.dll (9608 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\fullscreen_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\GdiPlus.dll (51840 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_IDhover_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\PromptDlg.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\black.bmp (3312 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\SliderThumb_hover.png (344 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\playcontrol.xml.js (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\exbg_right.bmp (654 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em08-ÃÂÄ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\RepairSetup.exe (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\sort_list_btn.png (817 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\autoshutdown.xml (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\mainframe.xml (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\2\0\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\RegUser.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\OffLine.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em07-´óÊå.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\ch_vip.png (443 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\audioswitcher.ax (12024 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\IEBrowser.dll (5520 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\play_normal.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\msvcp100.dll (14184 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute3_normal.png (579 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\miniclose.bmp (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mark_content_NM.png (989 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\user_vip.gif (169 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\radio_checked_disabled.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\UserFeedbackHint.xml (3 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\crashreporter.exe (7192 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\UPDATE\ICON.ico (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\5\3\2.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\downloadbtn_normal.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\VIPDownload.xml (8 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em24-Õ£ÑÛ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\3\2\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\3.ico (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\timingshutdown.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\11\1\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\white_dot.png (130 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\DataRateChangeWnd3.xml (10 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\PPOptions.dll (29608 bytes)
%Program Files%\Common Files\PPLiveNetwork\PPAP.exe (15536 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\UPDATE\upgrade_bg1.bmp (5064 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\Pause2Buffer.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\11\0\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images2\img.png (663 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ch2_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_dropdown_btn_disabled.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em48-˼¿¼.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\AutoSeek.xml (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\7\0\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\main.js (9 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\DownloadCodec.xml.js (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.FLV.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\ProductUpdate.dll (19096 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\coloradjust.xml (12 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\fullscreen_disabled.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\2\0\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute_normal.png (533 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\2\3\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\FindDownloadMgrTip.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\UPDATE\upgrade_bg2.bmp (5064 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images\404.png (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\downloadbtn_disable.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em04-ºÇºÇ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.WAV.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\expanding.gif (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em15-ÖÃÂ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_IDdelt_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\push_pop2.xml (13 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em53-»ð.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resize2001.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\radio_checked_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\playerinfo.bmp (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\icon2.gif (732 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\shift2new_down.bmp (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\4\0\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\progressbg.png (930 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\1\2\2.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\pushvideo.swf (15 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\CoreAVC.2.0.0.0.ax (9608 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\7\2\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute2_normal.png (556 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\radio_checked.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\radio_checked_down.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\4\1\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_expand.png (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\TestChannel.txt (451 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\recent.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em17-Àä.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\nolink.htm (944 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em54-ËÄÒ¶²ÃÂ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\hoverinfo.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_top_bg_right.png (463 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\peer.dll (80376 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em25-ÆøÌå.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\InstallLog.txt (19662 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\AVCVideoDec.ax (33391 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\crossdomain.xml (121 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\11\1\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ProgressTb_hover.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\previous_disabled.png (489 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\previous_normal.png (614 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\ipcfg.ini (401 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\sqlite3.dll (12024 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\muteplus_normal.png (556 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em46-ÓêÉ¡.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\SureClearPlayLog.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\exbg_right_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\1\1\1.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\BatchDownload.xml (8 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\2_1.ico (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\2\2\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\DataRateChangeWnd.xml (6 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\restore.dll (1856 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\bg_left_top.bmp (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\2.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\SkinConverter.exe (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\3\0\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\4\3\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute3_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resizemini1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.RM.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\user_normal.gif (98 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\pplive_schedule_buttons.gif (2 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\live\Live.dll (7192 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\blue.xml (278 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_so_bar.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\4\0\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\BalloonCommon.js (402 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\play_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute2_disabled.png (556 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\hot.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em06-óºì.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_button_down.bmp (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em26-±ã±ã.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_bot_bg.png (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\download_wait.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\images\loading.gif (49 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_collapsed_treebox11.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\playcontrolcommon.js (3616 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\page2.html (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\mframe.dll (25112 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\audioswitcher.ax (12024 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em09-Ë®µÎ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\5\2\2.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\collapsed_treebox2.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\page.html (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\sqlite3.dll (12024 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mark_skip_HV2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\images\history_6.png (201 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\PPTVIconBubble.exe (3616 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\DownloadCodec.xml (5 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\sop.dll (4992 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\MP4Splitter.ax (17848 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\ShowProblems.xml (12 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ch_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\hj_expand_new.png (299 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\common.js (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\avatar_bg.png (1856 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\AsynDownload.dll (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em55-²ö.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\8\3\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\4\2\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\PlayProgress2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\PPLiveFlv.swf (14 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\SkinConverter.ini (12 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_input_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\UserFeedback.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\portalbg.jpg (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\miniSite.xml (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\3xgiving\download\dtconfig_3.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\8\1\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images\nolink.png (4 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\IEBrowser.dll (13368 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\myHistory.html (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\Troubleshooter.xml.js (11 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\PPP.dll (28368 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\dt_tab_check.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\signin.xml.js (5 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\playcontrol2.xml.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\GetCommentsInfoDll.dll (1856 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resize1501.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em37-¾À½á.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\filepick.dll (8184 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\vip.swf (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_menu.gif (13 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.AVI.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\VIPDownloadHD.xml (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\MP4Splitter.ax (17848 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\pdot.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\uilib.dll (15536 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_top.bmp (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\1\2\1.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\8\0\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\hj_unexpand_new.png (267 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\images\history_3.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em44-ã¶×¡.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_cate_new.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_dropdown_btn_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\SearchBoxDlg.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\5\0\2.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\SideList.xml (784 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\uilib.dll (15536 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\9\2\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\radio_disabled.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\3\1\2.png (2 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\msvcr100.dll (25824 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\5\1\1.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\9\3\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\DownloadTaskConflict2.xml (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\muteplus_down.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\cknsis.dll (1856 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_cate_hot.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\bg_top.bmp (162 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\UserSkipAds.xml (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\sch_list_class_bg.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute3_disabled.png (579 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\btn_screennormal.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\VIPChannelTip.xml (8 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\dt_titlebar_m.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\exbg_top.bmp (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\checkbox_hover.bmp (576 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\Controlbar.bmp (5 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.WMV.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\admodule.dll (16944 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\dt_titlebar_r.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\play_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\exbg_left_top.bmp (15 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\dtconfig_3.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em20-ÞÃÂÞÎ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\SliderThumb_down.png (357 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\CoreAVC.ax (6584 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\ad\ad_close.bmp (568 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em52-ÊÜÉË.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\GetListInfoFail.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\ComboBoxHelper.js (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\7\3\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\2\1\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\8\1\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\DownloadManager.xml (5 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\buffer.swf (3616 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_bot.png (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\exbg_left.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\Troubleshooter.xml (10 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\install_s.ico (2392 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em42-Ť¶¯.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\bg_right.bmp (62 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\FirewallForbidden.xml (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\3\3\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em12-²»Êæ·þ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.AMR.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\shift2new.bmp (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\muteplus_hover.png (947 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ProgressTb_down.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images2\bg_x_qipao.png (323 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\11\3\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\pplive_schedule.html (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em33-Ì¾Æø.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\pause_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em14-ʧÃÂû.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em01-΢æ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\DownloadTaskConflict.xml (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\CommonFuncDll.dll (6360 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute3_hover.png (957 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\NewDownloadTask.xml (8 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_new3.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\9\2\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_menu_down.gif (13 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em13-¾Æ±ÂÂ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_bot_hover.gif (1856 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\blue.bmp (3312 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\EROTSER.dat (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em02-Ìôü.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\checkbox_checked_hover.bmp (576 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\VAProxyD.dll (3616 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\1\0\1.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\blue_b.bmp (3312 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\dt_header_normal_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\game.ico (3312 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\MngModule.dll (13584 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mark_live3_NM2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_button_hover.bmp (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\fullscreen_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\videoshot.xml (5 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_bot.bmp (726 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em23-ÉúÆø.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\logclient.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\PPInstallLog.dll (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\signin_combo.xml (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\bind_en-us.ini (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\signin2.xml (9 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resize1001.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em22-ÃÂÄËé.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\CoreAVC.ax (6584 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\hj_expand.png (284 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\OldJumpAdTip.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em50-¶³ÃÂæ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.video.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\2_2.ico (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\ETADPU.DAT (454 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\PPHookShell.dll (9320 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\8\2\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\tab2.xml (897 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\UPDATE\upgrade_title2.bmp (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_HD.png (544 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_updata_3.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\downloadTipDlg.xml (6 bytes)
%Program Files%\Common Files\PPLiveNetwork\atl100.dll (5064 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\pause_hover.png (943 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_input_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\5\0\1.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\ikan-p.ico (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\bright.bmp (15 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\ui.dll (23424 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ch2_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em41-òÃâ€ÃƒÆ’.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\Classic2NewTip.xml (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\atl100.dll (5064 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\troubleshooterresult.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\9\3\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\7\2\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\images\history_2.png (220 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\3\2\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\Favorites.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.3GP.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ch2_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\cntvppl.html (5 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\ieloading.swf (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\FreshPushWnd.htm (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\DeleteFileFailTip.xml (5 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\ckdll.dll (2392 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\resource\ikan-p.ico (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em32-Æà²Ò.png (1 bytes)
%Program Files%\Internet Explorer\PPLite\plugin\1.0.1.0535\PluginInstaller.exe (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ch_disabled.png (672 bytes)
%Program Files%\Common Files\PPLiveNetwork\Converter.exe (15536 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\time.dll (10 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\mainframe2.xml (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute_down.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\Hookkernel.dll (10136 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\UPDATE\upgrade_bg3.bmp (5064 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\KillProcDLL.dll (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\7\1\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\1\3\1.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\firewall.swf (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\bg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\signin_combo2.xml (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\8\2\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.SWF.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\dt_tab_uncheck.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ch2_disabled.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resizetop1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\errorPage.htm (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\playcontrolmini.xml (11 bytes)
%Program Files%\Common Files\PPLiveNetwork\msvcr100.dll (25824 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\PPGameIsSetup.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\NCList.dll (24832 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\images\history_4.png (209 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\SkipAdsBalloon.xml (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\atl100.dll (5064 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\logo.jpg (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logo.swf (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em43-ßÖ×ìɵæ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images2\style.css (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\signin2.xml.js (5 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\ChannelUpdatePop.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_class_bg.png (173 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\downloading.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_dropdown_btn_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\5\1\2.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\FindProcDLL.dll (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mark_live3_HV2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_right_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_left_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\SpecifyPath.List (25 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsr3.tmp (0 bytes)
Registry activity
The process imapi.exe:1044 makes changes in a system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "7D 1A 52 E8 73 38 EA 8E B9 B1 FC CE B6 20 21 05"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\Imapi]
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\Imapi]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\Imapi\ImapiSvc]
"BitNames" = " ImapiDebugError ImapiDebugWarning ImapiDebugTrace ImapiDebugInfo ImapiDebugX ImapiDebugSort"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\Imapi]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\Imapi\ImapiSvc]
"Guid" = "8107d8e9-e323-49f5-bba2-abc35c243dca"
The process xiaohua100.exe:900 makes changes in a system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "19 D2 CE E6 54 D6 73 7C D0 0F EB E3 00 E2 CA 54"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
The process regsvr32.exe:708 makes changes in a system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCR\Interface\{2C016F89-DC77-481D-A82F-A5345DFB7FB8}\TypeLib]
"Version" = "1.0"
[HKCR\Ifupt.Update.1]
"(Default)" = "Update Class"
[HKCR\PPLive.Lite.1\CLSID]
"(Default)" = "{EF0D1A14-1033-41A2-A589-240C01EDC078}"
[HKCR\PPLive.Lite.1]
"(Default)" = "PPLive Lite Class"
[HKCR\Interface\{2C016F89-DC77-481D-A82F-A5345DFB7FB8}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"
[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}]
"(Default)" = "PPLive Lite Class"
[HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedControls]
"{EF0D1A14-1033-41A2-A589-240C01EDC078}" = "0"
[HKCR\Interface\{2C016F89-DC77-481D-A82F-A5345DFB7FB8}\ProxyStubClsid]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"
[HKCR\Interface\{579A418B-2440-4278-9CC1-25E85E1C9D09}\TypeLib]
"Version" = "1.0"
[HKCR\Ifupt.DPlugin]
"(Default)" = "DPlugin Class"
[HKCR\TypeLib\{6F770594-0FC9-44DB-AD75-47C808CB7B44}\1.0\0\win32]
"(Default)" = "%Program Files%\Internet Explorer\PPLite\plugin\1.0.1.0535\pplugin2.dll"
[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\TypeLib]
"(Default)" = "{6F770594-0FC9-44DB-AD75-47C808CB7B44}"
[HKCR\Ifupt.DPlugin\CLSID]
"(Default)" = "{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}"
[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\VersionIndependentProgID]
"(Default)" = "PPLive.Lite"
[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\InprocServer32]
"(Default)" = "%Program Files%\Internet Explorer\PPLite\plugin\1.0.1.0535\pplugin2.dll"
[HKCR\Interface\{579A418B-2440-4278-9CC1-25E85E1C9D09}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\CLSID\{E62D3029-1430-49F8-9470-2A192B02E433}\InprocServer32]
"(Default)" = "%Program Files%\Internet Explorer\PPLite\plugin\1.0.1.0535\pplugin2.dll"
[HKCR\Interface\{628DF9B1-785D-44BA-AC9D-E9E226F01987}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Interface\{628DF9B1-785D-44BA-AC9D-E9E226F01987}\TypeLib]
"Version" = "1.0"
[HKCR\Interface\{579A418B-2440-4278-9CC1-25E85E1C9D09}\TypeLib]
"(Default)" = "{6F770594-0FC9-44DB-AD75-47C808CB7B44}"
[HKCR\Interface\{2C016F89-DC77-481D-A82F-A5345DFB7FB8}\TypeLib]
"(Default)" = "{6F770594-0FC9-44DB-AD75-47C808CB7B44}"
[HKCR\Ifupt.DPlugin\CurVer]
"(Default)" = "Ifupt.DPlugin.1"
[HKCR\PPLive.Lite\CurVer]
"(Default)" = "PPLive.Lite.1"
[HKCR\CLSID\{E62D3029-1430-49F8-9470-2A192B02E433}\InprocServer32]
"ThreadingModel" = "both"
[HKCR\Ifupt.Update\CLSID]
"(Default)" = "{E62D3029-1430-49F8-9470-2A192B02E433}"
[HKCR\TypeLib\{6F770594-0FC9-44DB-AD75-47C808CB7B44}\1.0\HELPDIR]
"(Default)" = "%Program Files%\Internet Explorer\PPLite\plugin\1.0.1.0535\"
[HKCR\TypeLib\{6F770594-0FC9-44DB-AD75-47C808CB7B44}\1.0]
"(Default)" = "pplugin 1.0 Type Library"
[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\MiscStatus\1]
"(Default)" = "131473"
[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\ProgID]
"(Default)" = "Ifupt.DPlugin.1"
[HKCR\PPLive.Lite\CLSID]
"(Default)" = "{EF0D1A14-1033-41A2-A589-240C01EDC078}"
[HKCR\Interface\{628DF9B1-785D-44BA-AC9D-E9E226F01987}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\TypeLib\{6F770594-0FC9-44DB-AD75-47C808CB7B44}\1.0\FLAGS]
"(Default)" = "0"
[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}]
"(Default)" = "DPlugin Class"
[HKCR\Ifupt.Update]
"(Default)" = "Update Class"
[HKCR\Ifupt.DPlugin.1]
"(Default)" = "DPlugin Class"
[HKCR\Ifupt.Update.1\CLSID]
"(Default)" = "{E62D3029-1430-49F8-9470-2A192B02E433}"
[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\Version]
"(Default)" = "1.0"
[HKCR\PPLive.Lite]
"(Default)" = "PPLive Lite Class"
[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCR\Interface\{579A418B-2440-4278-9CC1-25E85E1C9D09}]
"(Default)" = "IEwaOCX"
[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCR\Interface\{2C016F89-DC77-481D-A82F-A5345DFB7FB8}]
"(Default)" = "_IEwaOCXEvents"
[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\InprocServer32]
"(Default)" = "%Program Files%\Internet Explorer\PPLite\plugin\1.0.1.0535\pplugin2.dll"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D6 67 4D 40 8D 0E 1B 44 0A EB 22 F3 26 C4 00 C0"
[HKCR\Ifupt.DPlugin.1\CLSID]
"(Default)" = "{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}"
[HKCR\CLSID\{E62D3029-1430-49F8-9470-2A192B02E433}\VersionIndependentProgID]
"(Default)" = "Ifupt.Update"
[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\MiscStatus]
"(Default)" = "0"
[HKCR\Interface\{628DF9B1-785D-44BA-AC9D-E9E226F01987}\TypeLib]
"(Default)" = "{6F770594-0FC9-44DB-AD75-47C808CB7B44}"
[HKCR\Interface\{579A418B-2440-4278-9CC1-25E85E1C9D09}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\TypeLib]
"(Default)" = "{7163F003-E2FD-4C06-A268-F36C1083FBC0}"
[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\VersionIndependentProgID]
"(Default)" = "Ifupt.DPlugin"
[HKCR\CLSID\{E62D3029-1430-49F8-9470-2A192B02E433}\ProgID]
"(Default)" = "Ifupt.Update.1"
[HKCR\Interface\{628DF9B1-785D-44BA-AC9D-E9E226F01987}]
"(Default)" = "ISerializer"
[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\ToolboxBitmap32]
"(Default)" = "%Program Files%\Internet Explorer\PPLite\plugin\1.0.1.0535\pplugin2.dll, 101"
[HKCR\CLSID\{EF0D1A14-1033-41A2-A589-240C01EDC078}\ProgID]
"(Default)" = "PPLive.Lite.1"
[HKCR\CLSID\{E62D3029-1430-49F8-9470-2A192B02E433}]
"(Default)" = "Update Class"
The Trojan deletes the following registry key(s):
[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}]
[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\InprocServer32]
[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\ProgID]
[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\VersionIndependentProgID]
[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\Programmable]
[HKCR\CLSID\{AB37F5E2-E5EC-4E8D-8978-420074EA4DC0}\TypeLib]
The process PPTV.exe:1252 makes changes in a system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 19 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "57 F4 4D F3 05 59 62 BC E8 19 FD A9 C1 54 C6 96"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"360Ö÷¶¯·ÀÓù.exe" = "%System%\360Ö÷¶¯·ÀÓù.exe"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
The process Install-NO£º1.exe:1580 makes changes in a system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "DA 05 0E 10 25 B4 D6 12 A1 FD DC 61 FC 91 21 AE"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
The process IFoxInstall-y-c2073008-nsi-s-run-x.exe:2012 makes changes in a system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1A 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D3 29 1D 5B BB DC BE BD 17 DA 53 28 04 A1 30 D7"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
The process souhu.exe:904 makes changes in a system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B7 9B 65 BC 56 6C 8B 2C 82 47 A5 43 30 48 BC 6D"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ËѺü" = "%System%\souhu.exe"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
The process rundll32.exe:1628 makes changes in a system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "82 51 87 FA 79 69 CD 53 63 CA C0 89 76 74 04 58"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The process 5a74b003addfb0dceeb8e4c91bd10be2.exe:852 makes changes in a system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B1 6E 9B 19 96 37 8D C1 11 BD 11 22 89 E8 FA D2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
The process lb_between_5.exe:1820 makes changes in a system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1B 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "EC 8F 35 5F 2A CA CC DF 12 52 7D 6D 6A DE B1 FD"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
The process PPTV(pplive)_fora5_28156.exe:1764 makes changes in a system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\CoreCodec\CoreAVC Pro 3.x]
"User" = "rbogaar@aol.com"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1C 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\MozillaPlugins\@pptv.com/plugin]
"Vendor" = "PPTV"
[HKLM\SOFTWARE\CoreCodec\CoreAVC Pro 2.x]
"User" = "Videoediting.RU"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\MozillaPlugins\@pptv.com/plugin]
"Path" = "%Program Files%\Internet Explorer\PPLite\plugin\1.0.1.0535\npplugin2.dll"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\MozillaPlugins\@pptv.com/plugin]
"Descripton" = "PPLive PPTV Plugin"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\CoreCodec\CoreAVC Pro]
"User" = ""
[HKLM\SOFTWARE\CoreCodec\CoreAVC Pro 2.x]
"Serial" = "TAK922-HLQUUJ-22TTUK-PNNS0S-2JKS00"
[HKLM\SOFTWARE\CoreCodec\CoreAVC Pro 3.x]
"Serial" = "TBCYS8-Q18CKZ-8FHGG8-F49LTA-UK8AQQ"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\MozillaPlugins\@pptv.com/plugin]
"Version" = "1.0.0.1"
[HKLM\SOFTWARE\CoreCodec\CoreAVC Pro]
"Serial" = "IQIKB-6F7KD-CORE-IXRJW-IGUHC"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E2 9C E9 00 86 97 76 2C B8 C7 3A 98 4E 32 5E CA"
[HKLM\SOFTWARE\MozillaPlugins\@pptv.com/plugin\MimeTypes\application/x-pptv-plugin]
"(Default)" = ""
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\MozillaPlugins\@pptv.com/plugin]
"ProductName" = "PPLive PPTV Plugin"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
The process qipai.exe:364 makes changes in a system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 18 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "49 4C 7F 76 5B 95 8B B1 22 AF 2F 39 A5 6F E4 52"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
Network activity (URLs)
URL | IP |
---|---|
hxxp://198.13.114.201/a1/qipai.exe (Malicious) | |
hxxp://jump.sanboke.com/ndl.aspx?uid=7860&sid=1008&tid=3 | 202.85.213.139 |
hxxp://220.181.19.139/dcs.do?f=1&s=2073008&onekeyinstall=1&append=-nsi-s-run (Malicious) | |
hxxp://1375811928.zhidaoxiaofei.com/liaoban/between/lb_between_5.exe (Malicious) | 218.25.208.215 |
hxxp://198.13.114.201/a1/PPTV.exe (Malicious) | |
hxxp://s1.admin6.com/pptv/down.php?uid=28156 | 58.218.178.62 |
hxxp://cdn1.kkaagame.com/game8848/chenshen/Client/gg/Game88482013S5156D.exe | 61.147.77.5 |
hxxp://s1.admin6.com/pptv/PPTV(pplive)_fora5_28156.exe | |
hxxp://allot.hd.sohu.com/foxd/gz?file=IFoxInstall-y-c2073008-nsi-s-run-x.exe&new=/137/163/LTWqI6rHLA4X24GA2dgY4.exe (Malicious) | |
hxxp://61.160.228.32/ifox/TGPgoEo3TGwCodVok5XuJEsdJwuYq5QdqwXYol-WaExNs91v/IFoxInstall-y-c2073008-nsi-s-run-x.exe (Malicious) | |
hxxp://fbjuni.a.sohu.com/upgrade/IFoxInfo.cfg | |
hxxp://allot.hd.sohu.com/foxd/gz?file=SohuNewPlayer.exe&new=/21/32/98R15e071bxAnHH71GlqW4.exe (Malicious) | |
hxxp://61.160.228.17/ifox/TGogo6wgoGPg0E1JoEkvoptuHW1Y4L1PqG5Z4Z59qKivjfS/SohuNewPlayer.exe (Malicious) | |
data.vod.itc.cn | 220.181.61.229 |
setup2.tongjiku.com | 222.88.93.101 |
photocdn.hd.sohu.com | 61.135.181.167 |
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
imapi.exe:1044
regsvr32.exe:708
rundll32.exe:1628
5a74b003addfb0dceeb8e4c91bd10be2.exe:852
PPTV(pplive)_fora5_28156.exe:1764 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%WinDir%\Temp\911332e3.TMP (146970 bytes)
%System%\lb_between_5.exe (17072 bytes)
%System%\360Ö÷¶¯·ÀÓù.exe (7386 bytes)
%System%\PPTV(pplive)_fora5_28156.exe (88236 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qipai.exe (234 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\PPTV.exe (1688 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\souhu.exe (1672 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\xiaohua100.exe (283 bytes)
%WinDir%\MyConfig.ini (146 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IFoxInfo.ini (178 bytes)
%System%\IFoxInstall-y-c2073008-nsi-s-run-x.exe (1781 bytes)
%System%\souhu.exe (3855 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Install-NO£º1.exe (28066 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\xz[1].exe (46265 bytes)
%Program Files%\glbdnsve2013080616\1 (24 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\InetLoad.dll (24 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\files.bmp (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\checkbox2.bmp (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\aaa2.txt (632 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\Installation_button_2.bmp (3624 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\checkbox1.bmp (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\gethtm3[1].htm (632 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\nsDialogs.dll (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\Installation_bg2.bmp (14512 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\WndProc.dll (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\Installation_off1.bmp (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\Installation_button.bmp (3624 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\Installation_bg1.bmp (20202 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\SkinBtn.dll (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp\BgWorker.dll (2 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\CoreAVC.2.0.0.0.ax (9608 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\atl100.dll (5064 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\bg_right_top.bmp (702 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic_b.xml (293 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\muteplus_disabled.png (556 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_updata_2.gif (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\dt_titlebar_l.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\TextBoxHelper.js (999 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em29-½ûÖ¹.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\PPChLocalManager.dll (2392 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\P2PDetail.xml (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute4_hover.png (961 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\BatchDownload.xml.js (9 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\checkbox_down.bmp (576 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\DownloadManager.xml.js (10 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\checkbox_checked_down.bmp (576 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\radio_down.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\restore.dll (1856 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images\menu.png (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\1\0\2.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\version.ini (111 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute_disabled.png (533 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\FWUpnp.dll (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_top1.bmp (694 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resizenotop1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\1\3\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\downloadbtn_hover.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images\err_1.png (9 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\1\1\2.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\strengthenbtn02.bmp (8 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.MP4.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\8\0\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\11\3\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_left.bmp (654 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\mainframe.xml.js (3616 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\3xgiving\list\config.xml (11 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\skin.ini (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\ad\pause_close.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_top_bg_bar.png (244 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\bind_en-us[1].ini (1070 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\next_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\9\0\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resize1002.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\About.xml (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_del_record.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\FreshPushWnd.xml (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\11\0\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em10-µ¹Ã¢.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\previous_down.png (1 bytes)
%Program Files%\Internet Explorer\PPLite\plugin\version.dat (31 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_bot_down.png (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resizenotop2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\PPVodDownload.dll (14184 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\CoreAAC.ax (11344 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\checkbox.bmp (576 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\expanded_treebox1.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\btn_screenhover.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_button.bmp (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\AVCVideoDec.ax (33391 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\2\2\1.png (2 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\live\tpi.dll (30464 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em23-Ç×Ç×.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\msvcr100.dll (25824 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\SkipAds.xml (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\audio.swf (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\New2ClassicTip.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\EROTSER.dat (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em51-Ñ©ÈË.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\9\1\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\PPAPIsForbidden.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\signin.xml (10 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\PlayProgress1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\Gallop.dll (2392 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\tabs.js (9 bytes)
%Program Files%\Common Files\PPLiveNetwork\product.ini (368 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_close.png (12088 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\Converter.dll (7232 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\11\2\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resizeback.bmp (146 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\collapsed_treebox1.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\3\0\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\3xgiving.bmp (3312 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em16-Õð¾ª.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\shift2new_hover.bmp (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em47-ºÚÈË.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\mainframe2.js (3616 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\11\2\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\hj_unexpand.png (295 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\PPPlayer.js (8 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\TipsClient.dll (8560 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\playcontrolfullscreen.xml (12 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\resource\PPTV.url (86 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\Offline.ico (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_dropdown_btn_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.MPG.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ProgressTb_normal.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\pnsis.dll (2392 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mark_skip_NM2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\icons\default.ico (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_bot_bg_hover.png (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\black.xml (280 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_collapse.png (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\ieloading.xml (516 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\checkbox_checked_disabled.bmp (576 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\images\history_5.png (201 bytes)
%Program Files%\Common Files\PPLiveNetwork\version.dat (31 bytes)
%Program Files%\Internet Explorer\PPLite\plugin\1.0.1.0535\ppp.dll (8560 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\NavigateStatus.xml (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\PlugOut\client_ap.dll (15168 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\next_hover.png (998 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images\err_3.jpg (13 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\CodecFail.xml.js (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\VIPDownloadLogin.xml (8 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mark_content_HV.png (1 bytes)
%Program Files%\Internet Explorer\PPLite\plugin\1.0.1.0535\mframe.dll (18424 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\bg_bot.bmp (728 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\NoCache.List (683 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\IEProxy.dll (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\chctrl.dll (31856 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ch_normal.png (672 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\timingservice.js (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em03-´ô.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\ClearPlayList.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\next_disabled.png (490 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\VIPDownloadHDLogin.xml (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPLive.ico (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\UrlCache.List (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\DownloadPPGame.xml.js (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\bg_left.bmp (62 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\PPGameIsSetup.xml.js (452 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\pplive_schedule_main.gif (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\ComboBoxSearchHelper.js (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\shift_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\PPTVLicense.txt (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_so_bot1.png (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\DotTip.xml (12 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_bot_bg_down.png (1856 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em27-Æ¡¾Æ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\NOISREV.DAT (31 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ch_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\crashreporter.exe (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\pause_disabled.png (525 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_IDdelt_down.png (988 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\bg_left_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images\bg_x_channel.png (355 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\msvcp100.dll (14184 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em21-ÃÂÂÉà.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\8\3\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute4_normal.png (614 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\OPlayer.ocx (22552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\VIPLogin.xml (8 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\pause_normal.png (525 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\HTTP_ASF_SOURCE.ax (17848 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\openurl.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em45-¿§·È.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\5\3\1.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\7\1\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\strengthenbtn01.bmp (8 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\2\1\2.png (2 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\msvcr100.dll (25824 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em35-»Ò.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\5\2\1.png (1 bytes)
%Program Files%\Internet Explorer\PPLite\plugin\1.0.1.0535\npplugin2.dll (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resize1502.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\Balloons.js (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\exbg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\fullscreen_down.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\PPFrame.dll (11048 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\IP (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resizemini2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\UPDATE\CH.INI (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\push_pop.xml (10 bytes)
%Program Files%\PPLive\PPTV\InstallLog.txt (18589 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\InetLoad.dll (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_right.bmp (654 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\ie.png (895 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resizeratebg.bmp (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\radio_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\play_disabled.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em38-ÌôüÃÂÂÉà.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\3xgiving.xml (294 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em39-²»·þ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\Troubleshooter.dll (10136 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\checkbox_disabled.bmp (576 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\tab_background.png (133 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\OPlayer.ocx (22552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw4.tmp (745711 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.WMA.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.RA.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\coveredfile.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\avatar_bg_s.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\adselector.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\exbg_left_bot.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\NewDownloadTask.xml.js (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em49-ᧁÂÂ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em31-Ç®.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\expanded_treebox2.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em56-ÖÃÂ÷.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\loading_list.gif (520 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\7\0\2.png (2 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\GdiPlus.dll (51840 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images\err.css (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\StreamSwitch.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\FrameBase.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\9\0\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\UPDATE\upgrade_title.bmp (1856 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\pprepair.dll (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_hot3.png (784 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\Send_Log_Kernel_Module.dll (8560 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em18-¹Äó.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_update.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\ppopt.dll (3616 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\checkbox_checked.bmp (576 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\images\history.css (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\NewJumpAdTip.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute4_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em30-Éõç.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_table_down.png (535 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute_hover.png (929 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_menu_hover.gif (13 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em36-IloveUÊÖÊÆ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_IDdelt_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images\err_2.jpg (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\version[1].ini (111 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\ShowProblems.js (14 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\4\2\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.MKV.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\miniplayer.xml (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\VSFilter.dll (33633 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em19-ÈÈ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\dt_selitem_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\shift_disabled.png (471 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resizetop2.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\3\1\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\UPDATE\progress.gif (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\SliderThumb.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em11-Ãâ€ÃƒÂ£Ã‚¸Ã¢.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute4_disabled.png (614 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\PPMessageBox.xml (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute2_hover.png (948 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_table.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\SliderThumb_normal.png (344 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\config.xml (12 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\2\3\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em05-Ë§Æø.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\default2.ppui (302 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\cjs\err.js (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\images\history_1.png (219 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\GeneralTips.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\icon.gif (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\FreshPushWnd.js (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\FindChannelTip.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\download_fail.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\playcontrol.xml (13 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em28-¶ñħ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute2_down.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\msvcp100.dll (14184 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\2_4.ico (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\PlayProgress3.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\playcontrol2mini.xml (14 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\3\3\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\3xgiving\list_HD.png (544 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\next_normal.png (624 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\9\1\1.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\System.dll (14 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\4\3\2.png (3 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\VSFilter.dll (33633 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_left_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\exbg_bot.bmp (726 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\7\3\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\hoverinfo.xml.js (9 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em34-Ììʹ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\ShareWnd.xml (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\Options.xml (11 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\btn_screendisable.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\4\1\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\What's new.txt (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\PlayLogDlg.xml (8 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\previous_hover.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\CoreAAC.ax (11344 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\download_pause.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\radio.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\omng.dll (16944 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\playcontrol2.xml (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\Postpone.List (283 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resize0501.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resize0502.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\1.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\HTTP_ASF_SOURCE.ax (17848 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\progressfg.png (940 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\live\mir.dll (33747 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_search.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\msvcp100.dll (14184 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em40-ÎÞÄÎ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\FrameBase.js (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\link.ico (6584 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\PPGameFail.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resize2002.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_top_bg_left.png (683 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\2_3.ico (1 bytes)
%Program Files%\Internet Explorer\PPLite\plugin\1.0.1.0535\pplugin2.dll (9608 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\fullscreen_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\GdiPlus.dll (51840 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_IDhover_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\PromptDlg.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\black.bmp (3312 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\SliderThumb_hover.png (344 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\playcontrol.xml.js (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\exbg_right.bmp (654 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em08-ÃÂÄ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\RepairSetup.exe (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\sort_list_btn.png (817 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\autoshutdown.xml (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\2\0\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\RegUser.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\OffLine.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em07-´óÊå.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\ch_vip.png (443 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\audioswitcher.ax (12024 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\IEBrowser.dll (5520 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\play_normal.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\msvcp100.dll (14184 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute3_normal.png (579 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\miniclose.bmp (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mark_content_NM.png (989 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\user_vip.gif (169 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\radio_checked_disabled.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\UserFeedbackHint.xml (3 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\crashreporter.exe (7192 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\UPDATE\ICON.ico (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\5\3\2.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\downloadbtn_normal.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\VIPDownload.xml (8 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em24-Õ£ÑÛ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\3\2\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\3.ico (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\timingshutdown.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\11\1\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\white_dot.png (130 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\DataRateChangeWnd3.xml (10 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\PPOptions.dll (29608 bytes)
%Program Files%\Common Files\PPLiveNetwork\PPAP.exe (15536 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\UPDATE\upgrade_bg1.bmp (5064 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\Pause2Buffer.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\11\0\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images2\img.png (663 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ch2_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_dropdown_btn_disabled.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em48-˼¿¼.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\AutoSeek.xml (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\7\0\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\main.js (9 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\DownloadCodec.xml.js (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.FLV.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\ProductUpdate.dll (19096 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\coloradjust.xml (12 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\fullscreen_disabled.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\2\0\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute_normal.png (533 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\2\3\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\FindDownloadMgrTip.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\UPDATE\upgrade_bg2.bmp (5064 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images\404.png (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\downloadbtn_disable.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em04-ºÇºÇ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.WAV.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\expanding.gif (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em15-ÖÃÂ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_IDdelt_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\push_pop2.xml (13 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em53-»ð.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resize2001.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\radio_checked_hover.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\playerinfo.bmp (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\icon2.gif (732 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\shift2new_down.bmp (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\4\0\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\progressbg.png (930 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\1\2\2.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\pushvideo.swf (15 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\CoreAVC.2.0.0.0.ax (9608 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\7\2\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute2_normal.png (556 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\radio_checked.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\radio_checked_down.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\4\1\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_expand.png (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\TestChannel.txt (451 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\recent.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em17-Àä.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\nolink.htm (944 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em54-ËÄÒ¶²ÃÂ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_top_bg_right.png (463 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\peer.dll (80376 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em25-ÆøÌå.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\InstallLog.txt (19662 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\AVCVideoDec.ax (33391 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\crossdomain.xml (121 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\11\1\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ProgressTb_hover.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\previous_disabled.png (489 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\previous_normal.png (614 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\ipcfg.ini (401 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\sqlite3.dll (12024 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\muteplus_normal.png (556 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em46-ÓêÉ¡.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\SureClearPlayLog.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\exbg_right_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\1\1\1.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\2_1.ico (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\2\2\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\DataRateChangeWnd.xml (6 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\restore.dll (1856 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\bg_left_top.bmp (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\2.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\SkinConverter.exe (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\3\0\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\4\3\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute3_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resizemini1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.RM.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\user_normal.gif (98 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\pplive_schedule_buttons.gif (2 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\live\Live.dll (7192 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\blue.xml (278 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_so_bar.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\4\0\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\BalloonCommon.js (402 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\play_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute2_disabled.png (556 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\hot.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em06-óºì.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_button_down.bmp (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em26-±ã±ã.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_bot_bg.png (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\download_wait.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\images\loading.gif (49 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_collapsed_treebox11.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\playcontrolcommon.js (3616 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\page2.html (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\mframe.dll (25112 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\audioswitcher.ax (12024 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em09-Ë®µÎ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\5\2\2.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\collapsed_treebox2.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\page.html (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\sqlite3.dll (12024 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mark_skip_HV2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\images\history_6.png (201 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\PPTVIconBubble.exe (3616 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\sop.dll (4992 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\MP4Splitter.ax (17848 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\ShowProblems.xml (12 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ch_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\hj_expand_new.png (299 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\common.js (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\avatar_bg.png (1856 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\AsynDownload.dll (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em55-²ö.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\8\3\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\4\2\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\PlayProgress2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\PPLiveFlv.swf (14 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\SkinConverter.ini (12 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_input_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\UserFeedback.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\portalbg.jpg (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\miniSite.xml (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\3xgiving\download\dtconfig_3.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\8\1\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images\nolink.png (4 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\IEBrowser.dll (13368 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\myHistory.html (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\Troubleshooter.xml.js (11 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\PPP.dll (28368 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\dt_tab_check.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\signin.xml.js (5 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\playcontrol2.xml.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\GetCommentsInfoDll.dll (1856 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resize1501.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em37-¾À½á.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\filepick.dll (8184 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\vip.swf (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_menu.gif (13 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.AVI.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\VIPDownloadHD.xml (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\MP4Splitter.ax (17848 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\pdot.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\uilib.dll (15536 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_top.bmp (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\1\2\1.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\8\0\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\hj_unexpand_new.png (267 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\images\history_3.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em44-ã¶×¡.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_cate_new.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_dropdown_btn_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\SearchBoxDlg.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\5\0\2.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\SideList.xml (784 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\uilib.dll (15536 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\9\2\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\radio_disabled.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\3\1\2.png (2 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\msvcr100.dll (25824 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\5\1\1.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\9\3\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\DownloadTaskConflict2.xml (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\muteplus_down.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\cknsis.dll (1856 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_cate_hot.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\bg_top.bmp (162 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\UserSkipAds.xml (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\sch_list_class_bg.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute3_disabled.png (579 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\btn_screennormal.bmp (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\VIPChannelTip.xml (8 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\dt_titlebar_m.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\exbg_top.bmp (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\checkbox_hover.bmp (576 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\Controlbar.bmp (5 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.WMV.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\admodule.dll (16944 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\dt_titlebar_r.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\play_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\exbg_left_top.bmp (15 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\dtconfig_3.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em20-ÞÃÂÞÎ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\SliderThumb_down.png (357 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\player\CoreAVC.ax (6584 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\ad\ad_close.bmp (568 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em52-ÊÜÉË.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\GetListInfoFail.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\ComboBoxHelper.js (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\7\3\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\2\1\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\8\1\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\buffer.swf (3616 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_bot.png (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\exbg_left.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\install_s.ico (2392 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em42-Ť¶¯.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\bg_right.bmp (62 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\FirewallForbidden.xml (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\3\3\2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em12-²»Êæ·þ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.AMR.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\shift2new.bmp (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\muteplus_hover.png (947 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ProgressTb_down.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images2\bg_x_qipao.png (323 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\11\3\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\pplive_schedule.html (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em33-Ì¾Æø.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\pause_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em14-ʧÃÂû.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em01-΢æ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\DownloadTaskConflict.xml (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\CommonFuncDll.dll (6360 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute3_hover.png (957 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_new3.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\9\2\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_menu_down.gif (13 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em13-¾Æ±ÂÂ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\passport\passport_bot_hover.gif (1856 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\blue.bmp (3312 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\EROTSER.dat (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em02-Ìôü.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\common\checkbox_checked_hover.bmp (576 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\VAProxyD.dll (3616 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\1\0\1.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\blue_b.bmp (3312 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\dt_header_normal_bg.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\game.ico (3312 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\MngModule.dll (13584 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mark_live3_NM2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_button_hover.bmp (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\fullscreen_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\videoshot.xml (5 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_bot.bmp (726 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em23-ÉúÆø.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\logclient.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\PPInstallLog.dll (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\signin_combo.xml (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\bind_en-us.ini (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\signin2.xml (9 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resize1001.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em22-ÃÂÄËé.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\CoreAVC.ax (6584 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\hj_expand.png (284 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\OldJumpAdTip.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em50-¶³ÃÂæ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.video.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\2_2.ico (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\ETADPU.DAT (454 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\PPHookShell.dll (9320 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\8\2\2.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\tab2.xml (897 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\UPDATE\upgrade_title2.bmp (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_HD.png (544 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_updata_3.png (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\downloadTipDlg.xml (6 bytes)
%Program Files%\Common Files\PPLiveNetwork\atl100.dll (5064 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\pause_hover.png (943 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_input_normal.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\5\0\1.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\ikan-p.ico (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\bright.bmp (15 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\ui.dll (23424 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ch2_down.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em41-òÃâ€ÃƒÆ’.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\education\Classic2NewTip.xml (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\atl100.dll (5064 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\troubleshooterresult.xml (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\9\3\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\7\2\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\images\history_2.png (220 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\3\2\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\Favorites.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.3GP.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ch2_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\cntvppl.html (5 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\ieloading.swf (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\FreshPushWnd.htm (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\DeleteFileFailTip.xml (5 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\ckdll.dll (2392 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\resource\ikan-p.ico (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em32-Æà²Ò.png (1 bytes)
%Program Files%\Internet Explorer\PPLite\plugin\1.0.1.0535\PluginInstaller.exe (4992 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ch_disabled.png (672 bytes)
%Program Files%\Common Files\PPLiveNetwork\Converter.exe (15536 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\time.dll (10 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\mainframe2.xml (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mute_down.png (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\kernel\Hookkernel.dll (10136 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\UPDATE\upgrade_bg3.bmp (5064 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\KillProcDLL.dll (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\7\1\1.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\1\3\1.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\firewall.swf (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\mainframe\bg_right_bot.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\signin_combo2.xml (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\8\2\1.png (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\icons\PPTV.SWF.ico (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\dt_tab_uncheck.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\ch2_disabled.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\controltoolbar\resizetop1.bmp (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\errorPage.htm (6 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\playcontrol\playcontrolmini.xml (11 bytes)
%Program Files%\Common Files\PPLiveNetwork\msvcr100.dll (25824 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\components\NCList.dll (24832 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logPage\images\history_4.png (209 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\SkipAdsBalloon.xml (1 bytes)
%Program Files%\Common Files\PPLiveNetwork\1.0.1.0535\player\atl100.dll (5064 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\logo.jpg (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\logo.swf (1552 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\face\em43-ßÖ×ìɵæ.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\local\images2\style.css (3 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\signin2.xml.js (5 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\chrome\ChannelUpdatePop.xml (4 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\list\list_class_bg.png (173 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\download\downloading.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\login\ex_login_dropdown_btn_hover.png (1 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\tab\5\1\2.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsb5.tmp\FindProcDLL.dll (784 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\playctrl\mark_live3_HV2.png (2 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_right_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\skins\classic\hoverinfo\gbg_left_top.bmp (7 bytes)
%Program Files%\PPLive\PPTV\3.1.3.0042\data\SpecifyPath.List (25 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"360Ö÷¶¯·ÀÓù.exe" = "%System%\360Ö÷¶¯·ÀÓù.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ËѺü" = "%System%\souhu.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.