Technical Information
- %WINDIR%\tasks\pptassistantupdatetask_user.job
- %WINDIR%\tasks\pptassistantnotifytask_user.job
- <SYSTEM32>\tasks\pptassistantnotifytask_user
- <SYSTEM32>\tasks\pptassistantupdatetask_user
- %TEMP%\nsre254.tmp
- %LOCALAPPDATA%\pptassist\assistdownloader.exe
- %TEMP%\pptassist\~11190b\pptassist64.dll
- %TEMP%\pptassist\~11190b\pptassist.dll
- %TEMP%\pptassist\~11190b\updateself.exe
- %TEMP%\pptassist\~11190b\utility\uninst.exe
- %TEMP%\pptassist\~11190b\notify.exe
- %TEMP%\pptassist\~11190b\meihua.exe
- %TEMP%\pptassist\~11190b\assistupdate.exe
- %TEMP%\pptassist\~11190b\assistdownloader.exe
- %TEMP%\pptassist\~11190b\meihua2013.ppsx
- %TEMP%\pptassist\~11190b\meihua2010.ppsx
- %TEMP%\pptassist\~11190b\meihua2007.ppsx
- %TEMP%\pptassist\~11190b\cfgs\feature.dat
- %TEMP%\pptassist\~11190b\cfgs\setup.cfg
- %TEMP%\pptassist\~11190b\meihuappt.pps
- %LOCALAPPDATA%\pptassist\assistupdate.exe
- %LOCALAPPDATA%\pptassist\cfgs\feature.dat
- %LOCALAPPDATA%\pptassist\cfgs\setup.cfg
- %LOCALAPPDATA%\pptassist\meihua.exe
- %ALLUSERSPROFILE%\microsoft\crypto\rsa\s-1-5-18\d42cc0c3858a58db2db37658219e6400_d99ef00b-ccd3-4f1d-9980-90ac453b0b47
- %APPDATA%\pptassist\update\log\notify_2024_04_13.log
- %APPDATA%\microsoft\windows\start menu\programs\ppt美化大师\卸载.lnk
- %APPDATA%\microsoft\windows\start menu\programs\ppt美化大师\ppt美化大师.lnk
- %LOCALAPPDATA%\microsoft\internet explorer\msimgsiz.dat
- %APPDATA%\dts\upgrade\app.ini
- %LOCALAPPDATA%\pptassist\utility\uninst.exe
- %LOCALAPPDATA%\pptassist\pptassist64.dll
- %LOCALAPPDATA%\pptassist\updateself.exe
- %LOCALAPPDATA%\pptassist\pptassist.dll
- %LOCALAPPDATA%\pptassist\notify.exe
- %LOCALAPPDATA%\pptassist\meihuappt.pps
- %LOCALAPPDATA%\pptassist\meihua2013.ppsx
- %LOCALAPPDATA%\pptassist\meihua2010.ppsx
- %LOCALAPPDATA%\pptassist\meihua2007.ppsx
- %LOCALAPPDATA%\pptassist\meihua2003.pps
- %TEMP%\nsm8d7.tmp\findprocdll.dll
- %TEMP%\pptassist\~11190b\meihua2003.pps
- %TEMP%\pptassist\~1117d3\setup.xml
- %TEMP%\pptassist\~1117d3\product.xml
- %APPDATA%\microsoft\internet explorer\quick launch\´óììê¹ö®½£.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\´óììê¹ö®½£\ð¶ôø´óììê¹ö®½£.lnk
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\´óììê¹ö®½£\´óììê¹ö®½£.lnk
- %HOMEPATH%\desktop\´óììê¹ö®½£.lnk
- %APPDATA%\dts\mydts\uninst.exe
- %APPDATA%\dts\mydts\dts.exe
- %TEMP%\nshdd75.tmp\findprocdll.dll
- %APPDATA%\dts\mydts\lander.ini
- %TEMP%\nshdd75.tmp\system.dll
- %TEMP%\nsrdd64.tmp
- %ProgramFiles(x86)%\yx_dts.exe
- %TEMP%\nsre2a3.tmp\execcmd.dll
- %TEMP%\nsre2a3.tmp\inetc.dll
- %ProgramFiles(x86)%\2.ico
- %TEMP%\nsre2a3.tmp\system.dll
- %TEMP%\nsre2a3.tmp\base64.dll
- %ProgramFiles(x86)%\officeassist.0405.80.1119.exe
- %APPDATA%\microsoft\internet explorer\quick launch\user pinned\taskbar\´óììê¹ö®½£.lnk
- %TEMP%\nsm8d7.tmp\v6svc_oem.dll
- %TEMP%\pptassist\~1117d3\install_res\cgpb_bg.png
- %TEMP%\pptassist\~1117d3\install_res\30.png
- %TEMP%\pptassist\~1117d3\install_res\3.png
- %TEMP%\pptassist\~1117d3\install_res\20.png
- %TEMP%\pptassist\~1117d3\install_res\104.png
- %TEMP%\pptassist\~1117d3\install_res\103.png
- %TEMP%\pptassist\~1117d3\install_res\102.png
- %TEMP%\pptassist\~1117d3\install_res\100.png
- %TEMP%\pptassist\~1117d3\install_res\101.png
- %TEMP%\pptassist\~1117d3\install_res\10.png
- %TEMP%\pptassist\~1117d3\install_res\1.png
- %TEMP%\pptassist\~1117d3\install_res\2.jpg
- %ProgramFiles(x86)%\sohuva_4.3.0.1-c204900003-ng-nti-s-x.exe
- %ALLUSERSPROFILE%\kingsoft\20240413_170857\oem.ini
- %ALLUSERSPROFILE%\kingsoft\20240413_170857\officeassist.0405.80.1119.exe
- %TEMP%\nsm8d7.tmp\system.dll
- %TEMP%\pptassist\~1117d3\install_res\cgpb_fg.png
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012024041320240414\index.dat
- %TEMP%\nshdd75.tmp\findprocdll.dll
- %TEMP%\nsm8d7.tmp\findprocdll.dll
- %ALLUSERSPROFILE%\kingsoft\20240413_170857\officeassist.0405.80.1119.exe
- %ALLUSERSPROFILE%\kingsoft\20240413_170857\oem.ini
- %TEMP%\pptassist\~1117d3\product.xml
- %TEMP%\pptassist\~1117d3\install_res\cgpb_fg.png
- %TEMP%\pptassist\~1117d3\install_res\cgpb_bg.png
- %TEMP%\pptassist\~11190b\utility\uninst.exe
- %TEMP%\pptassist\~11190b\updateself.exe
- %TEMP%\pptassist\~11190b\pptassist64.dll
- %TEMP%\pptassist\~11190b\pptassist.dll
- %TEMP%\nsm8d7.tmp\system.dll
- %TEMP%\pptassist\~11190b\notify.exe
- %TEMP%\pptassist\~11190b\meihua2013.ppsx
- %TEMP%\pptassist\~11190b\meihua2010.ppsx
- %TEMP%\pptassist\~11190b\meihua2007.ppsx
- %TEMP%\pptassist\~11190b\meihua2003.pps
- %TEMP%\pptassist\~11190b\meihua.exe
- %TEMP%\pptassist\~11190b\cfgs\setup.cfg
- %TEMP%\pptassist\~11190b\cfgs\feature.dat
- %TEMP%\pptassist\~11190b\assistupdate.exe
- %TEMP%\pptassist\~11190b\assistdownloader.exe
- %TEMP%\nshdd75.tmp\system.dll
- %TEMP%\pptassist\~11190b\meihuappt.pps
- %TEMP%\nsm8d7.tmp\v6svc_oem.dll
- 'in#.###ol.sina.com.cn':80
- 'tu####.#aptcha.qcloud.com':443
- 'cm.#e2d.com':80
- 'my.#7.com':443
- 'sp###.wps.cn':80
- 're###i.37.com':80
- 'd.###youxi7.com':80
- 'ga###pp.37.com':80
- 'ww#.#inaimg.cn':80
- 'a.#####data.37wan.com':80
- 'wd##.#ache.wps.cn':80
- 'ne#####.funshion.com':80
- 'd.###6699.com':80
- 'microsoft.com':80
- 'oc##.dcocsp.cn':80
- 'bl##.#ina.com.cn':443
- 'bl##.#ina.com.cn':80
- 't.#n':80
- 'co###em.37.com':80
- 'dl.##ofeng.com':80
- http://t.#n/RZIvNie
- http://im##.#7wanimg.com/dts/css/client/game1/main.jpg
- http://im##.#7wanimg.com/dts/css/client/game1/log.jpg
- http://im##.#7wanimg.com/dts/css/client/game1/dot.jpg
- http://ga###pp.37.com/controller/client.php?ac########################################
- http://im##.#7wanimg.com/dts/css/client/game1/rem_on.jpg
- http://im##.#7wanimg.com/dts/css/client/game1/getcard.jpg
- http://im##.#7wanimg.com/dts/css/client/game1/reg2.jpg?t=######
- http://pt###.37.com/js/sq/widget/sq.dialog2015.js?t=#############################
- http://ga###pp.37.com/controller/
- http://im##.#7wanimg.com/www2015/images/reglog/200x42.png?v=#
- http://a.#####data.37wan.com/controller/istat.controller.php?pl##################################################################################################################################...
- http://im##.#7wanimg.com/www/css/images/common/dialog2/bg-dialog-avatar.png?v=#
- http://im##.#7wanimg.com/www/css/images/common/ico.png
- http://re###i.37.com/proxy_yk.html
- http://cm.#e2d.com/1/
- http://pt###.37.com/js/sq/widget/sq.clientclass.js?t=##########
- http://co###em.37.com/sys/?u=###########################
- http://pt###.37.com/js/sq/widget/sq.statis.js
- http://pt###.37.com/js/sq/lib/sq.core.js
- http://bl##.#ina.com.cn/s/blog_7185bdf10102vba6.html
- http://oc##.dcocsp.cn/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAoEcNCWvIoSyJCm34Ju7Es%3D
- http://oc##.dcocsp.cn/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSmVYFXwi%2FRq9wx3PKhB8lC%2FFYUyAQUkZ9eMRWuEJ%2BtYMH3wcyqSDQvDCYCEAHxC4vZhWFDeHnV3b9N7uw%3D
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- http://d.###6699.com/yx/dts/sqft/905848/yx_dts.exe
- http://ne#####.funshion.com/software/files/silent5/FunshionInstall_C70699.exe
- http://wd##.#ache.wps.cn/wps/download/OfficeAssist.0405.80.1119.exe
- http://t.#n/RZII9Xg
- http://a.#####data.37wan.com/controller/istat.controller.php?it##################################################################################################################################...
- http://ww#.#inaimg.cn/large/7185bdf1gw1eo18v61atcj20o90elu15.jpg
- http://ga###pp.37.com/controller/client.php?ga###################################################################################################################################################
- http://im##.#7wanimg.com/dts/css/client/game1.css?t=##########
- http://im##.#7wanimg.com/dts/js/client/game1.js?t=##########
- http://d.###youxi7.com/yx/dts/sqft/905848/app.ini
- http://pt###.37.com/js/sq/widget/sq.login.js
- http://pt###.37.com/js/sq/widget/sq.tab.js
- http://dl.##ofeng.com/BFVCenter/BF-BFVCenter[[AB027]].exe
- http://sp###.wps.cn/showpro/infos.ads?v=#########################################################################################################################################################...
- 'bl##.#ina.com.cn':443
- 'my.#7.com':443
- 'tu####.#aptcha.qcloud.com':443
- DNS ASK in#.###ol.sina.com.cn
- DNS ASK dl.#x5.com
- DNS ASK co###em.37.com
- DNS ASK tu####.#aptcha.qcloud.com
- DNS ASK cm.#e2d.com
- DNS ASK my.#7.com
- DNS ASK sp###.wps.cn
- DNS ASK re###i.37.com
- DNS ASK d.###youxi7.com
- DNS ASK pt###.37.com
- DNS ASK im##.#7wanimg.com
- DNS ASK no####.meihua.docer.com
- DNS ASK ga###pp.37.com
- DNS ASK ww#.#inaimg.cn
- DNS ASK wd##.#ache.wps.cn
- DNS ASK ba###hijz.com
- DNS ASK ne#####.funshion.com
- DNS ASK d.###6699.com
- DNS ASK mm####.jianting.net
- DNS ASK microsoft.com
- DNS ASK oc##.dcocsp.cn
- DNS ASK bl##.#ina.com.cn
- DNS ASK t.#n
- DNS ASK a.#####data.37wan.com
- DNS ASK dl.##ofeng.com
- ClassName: 'GadgetHost' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: '' WindowName: 'pptassistsetup_message'
- ClassName: '' WindowName: 'PPT美化大师安装向导'
- '%LOCALAPPDATA%\pptassist\assistupdate.exe' -createtask
- '%ProgramFiles(x86)%\yx_dts.exe'
- '%APPDATA%\dts\mydts\dts.exe' /ShowDeskTop
- '%APPDATA%\dts\mydts\dts.exe' /autorun /setuprun
- '%APPDATA%\dts\mydts\dts.exe' /setupsucc
- '%ProgramFiles(x86)%\officeassist.0405.80.1119.exe'
- '%ALLUSERSPROFILE%\kingsoft\20240413_170857\officeassist.0405.80.1119.exe'
- '%LOCALAPPDATA%\pptassist\notify.exe' /from:ksostart
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\2345Explorer_329242_silence.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\2345Explorer_329242_silence.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\ins1256858.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\ins1256858.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\IQIYIsetup_l_spl004@kb010.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\IQIYIsetup_l_spl004@kb010.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\"' (with hidden window)
- '%LOCALAPPDATA%\pptassist\notify.exe' /from:ksostart' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\BF-BFVCenter[[AB027]].exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\BF-BFVCenter[[AB027]].exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\setup_95165069.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\setup_95165069.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\9377mycs_Y_mgaz2_1201B.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\9377mycs_Y_mgaz2_1201B.exe"' (with hidden window)
- '%WINDIR%\syswow64\regsvr32.exe' /s "%LOCALAPPDATA%\PPTAssist\pptassist64.dll"' (with hidden window)
- '%LOCALAPPDATA%\pptassist\assistupdate.exe' -createtask' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\guodou_137_777.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\guodou_137_777.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe"' (with hidden window)
- '%WINDIR%\syswow64\regsvr32.exe' /s "%LOCALAPPDATA%\PPTAssist\pptassist.dll"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\OfficeAssist.0405.80.1119.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\OfficeAssist.0405.80.1119.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\FunshionInstall_C70699.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\FunshionInstall_C70699.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\yx_dts.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\yx_dts.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\MM-liao8302.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\MM-liao8302.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\setup_zjm0104.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\setup_zjm0104.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\MM-liao8302.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\MM-liao8302.exe"
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\2345Explorer_329242_silence.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\2345Explorer_329242_silence.exe"
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\ins1256858.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\ins1256858.exe"
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\IQIYIsetup_l_spl004@kb010.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\IQIYIsetup_l_spl004@kb010.exe"
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\"
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\9377mycs_Y_mgaz2_1201B.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\9377mycs_Y_mgaz2_1201B.exe"
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\BF-BFVCenter[[AB027]].exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\BF-BFVCenter[[AB027]].exe"
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\guodou_137_777.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\guodou_137_777.exe"
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\setup_95165069.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\setup_95165069.exe"
- '<SYSTEM32>\regsvr32.exe' /s "%LOCALAPPDATA%\PPTAssist\pptassist64.dll"
- '%WINDIR%\syswow64\regsvr32.exe' /s "%LOCALAPPDATA%\PPTAssist\pptassist64.dll"
- '%WINDIR%\syswow64\regsvr32.exe' /s "%LOCALAPPDATA%\PPTAssist\pptassist.dll"
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\OfficeAssist.0405.80.1119.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\OfficeAssist.0405.80.1119.exe"
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\FunshionInstall_C70699.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\FunshionInstall_C70699.exe"
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\yx_dts.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\yx_dts.exe"
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe"
- '%WINDIR%\syswow64\cmd.exe' /C copy /b "%ProgramFiles(x86)%\setup_zjm0104.exe" + "%WINDIR%\Fonts\gulim.ttc" "%ProgramFiles(x86)%\setup_zjm0104.exe"