Trojan.Win32.Swrort.3_904b66dc26

by malwarelabrobot on April 24th, 2015 in Malware Descriptions.

Trojan.Win32.Swrort.3.FD, mzpefinder_pcap_file.YR, GenericAutorunWorm.YR (Lavasoft MAS)
Behaviour: Trojan, Worm, WormAutorun


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 904b66dc26193ecb044902e38b343a93
SHA1: f8de69a265af1e23b60119ebf181a303086425a6
SHA256: c2668995831e6dc65ae48385c9a3242f46e47de9ffe444cb1da0ec74f9829593
SSDeep: 6144:0JtUK/n0bR3s0saeLWYbJESy2j82qk/nBT:0JtL/nKBs9aYVEVB2qSBT
Size: 239729 bytes
File type: EXE
Platform: WIN32
Entropy: Not Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2015-03-05 23:03:47
Analyzed on: Windows7Ada SP1 64-bit


Summary:

Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Payload

Behaviour Description
WormAutorun A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Trojan's file once a user opens a drive's folder in Windows Explorer.


Process activity

The Trojan creates the following process(es):

QHWatchdog.exe:2492
DXSETUP.exe:1376
regsvr32.exe:704
regsvr32.exe:1580
%original file name%.exe:2428
QHActiveDefense.exe:1168
QHActiveDefense.exe:804
nss6FC6.tmp.exe:1904

The Trojan injects its code into the following process(es):

QHSafeTray.exe:1172
PatchUp.exe:3300
nsd45AA.tmp.exe:1172

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process QHSafeTray.exe:1172 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\LocalLow\360WD\wdch.dat (557 bytes)
%Program Files% (x86)\360\Total Security\safemon\netconfig.dat (18 bytes)
%Program Files% (x86)\360\Total Security\safemon\wdui2.dll (548 bytes)
%Program Files% (x86)\360\Total Security\safemon\safemon.dll (49 bytes)
%Program Files% (x86)\360\Total Security\safemon\SomProxy.dll (339 bytes)
%Program Files% (x86)\360\Total Security\safemon\routertp.ini (56 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalLow\360WD\wdch.dat-journal (7250 bytes)
%Program Files% (x86)\360\Total Security\safemon\urlproc.dll (655 bytes)

The process PatchUp.exe:3300 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files% (x86)\360\Total Security\hotfix\som_c6cb4f5ac0255d2baf41678f26cd50cc.dat.tmp (2 bytes)
%Program Files% (x86)\360\Total Security\hotfix\som_7539e5c431f211952383e009cce4062d.dat.tmp (323 bytes)
%Program Files% (x86)\360\Total Security\hotfix\som_9909aa216b30b502f677bfff05000b0e.dat.tmp (784 bytes)
%Program Files% (x86)\360\Total Security\hotfix\som_0cd47f5d563ba06a1e44716398931a08.dat.tmp (323 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\360safe\360leakfixer\PatchUp.leakrepair.som.log (17020 bytes)
%Program Files% (x86)\360\Total Security\hotfix\som_e6e862c79dc156d48370cc4f389eee28.dat.tmp (3 bytes)
%Program Files% (x86)\360\Total Security\hotfix\som_dbbccf0284b1c6112444badae27b87c1.dat.tmp (49 bytes)
%Program Files% (x86)\360\Total Security\hotfix\som_4ae7fb61ded98e1cd0fa51382739609d.dat.tmp (3 bytes)
%Program Files% (x86)\360\Total Security\leakrepair.dat (446 bytes)
%Program Files% (x86)\360\Total Security\deepscan\netconf.dat (4 bytes)
%Program Files% (x86)\360\Total Security\deepscan\speedmem2.hg (2091 bytes)
%Program Files% (x86)\360\Total Security\hotfix\som_b0586730837afd39a4c6ffc29b8b45d1.dat.tmp (49 bytes)
%Program Files% (x86)\360\Total Security\hotfix\som_f3d59eaa9ff33dcbe50abb4276fbe86c.dat.tmp (49 bytes)
%Program Files% (x86)\360\Total Security\deepscan\speedmem2.hg-journal (13458 bytes)

The process nsd45AA.tmp.exe:1172 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_d3dcsx_42_x64.cab (49398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_d3dx9_38_x64.cab (27487 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_d3dx11_42_x64.cab (3051 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2006_XACT_x86.cab (3591 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_XAudio_x86.cab (5874 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\APR2007_XACT_x64.cab (4633 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_d3dx10_41_x64.cab (15925 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_d3dx11_42_x86.cab (1783 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_d3dx11_43_x86.cab (1564 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\NOV2007_X3DAudio_x64.cab (1391 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2008_d3dx10_39_x86.cab (15652 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_XACT_x64.cab (2605 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2006_XACT_x64.cab (3086 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DEC2006_XACT_x86.cab (3227 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2006_xinput_x86.cab (1320 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\APR2007_xinput_x64.cab (1386 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\dsetup32.dll (27267 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2006_MDX1_x86_Archive.cab (72546 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2008_XACT_x86.cab (1707 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2010_XAudio_x86.cab (6136 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2007_d3dx9_36_x86.cab (26253 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_d3dx9_40_x86.cab (22095 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0008.tmp (14404 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_XACT_x64.cab (2473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\NOV2007_XACT_x86.cab (3849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2008_XAudio_x86.cab (6895 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2007_d3dx9_35_x64.cab (27382 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_X3DAudio_x64.cab (1985 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2006_XACT_x64.cab (3989 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2007_d3dx9_34_x86.cab (23634 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_d3dx10_42_x86.cab (3771 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DEC2006_d3dx9_32_x64.cab (23092 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\OCT2006_XACT_x86.cab (3491 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\FEB2007_XACT_x64.cab (3357 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_XACT_x86.cab (1671 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_XAudio_x64.cab (6518 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DSETUP.dll (2598 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_d3dx10_38_x64.cab (17923 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2007_XACT_x86.cab (2774 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2006_xinput_x64.cab (2061 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_d3dx11_43_x64.cab (4547 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2006_XACT_x86.cab (3064 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2006_xinput_x86.cab (830 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DXSETUP.exe (11136 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0010.tmp (14404 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\APR2007_xinput_x86.cab (2760 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2006_d3dx9_30_x64.cab (19039 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_D3DCompiler_42_x64.cab (14048 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2007_XACT_x86.cab (2201 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\APR2007_d3dx9_33_x86.cab (23977 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_d3dx10_43_x86.cab (3692 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_XAudio_x64.cab (6514 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_d3dx9_43_x64.cab (17300 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0011.tmp (12676 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DEC2006_XACT_x64.cab (3423 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2006_d3dx9_29_x86.cab (17312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_X3DAudio_x64.cab (1568 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_d3dx10_40_x86.cab (16648 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_XAudio_x64.cab (6012 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2007_XACT_x64.cab (3999 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_d3dx9_37_x86.cab (20364 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_X3DAudio_x64.cab (581 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\APR2007_XACT_x86.cab (3136 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2006_d3dx9_30_x86.cab (20278 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_XAudio_x64.cab (5815 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DEC2006_d3dx10_00_x64.cab (6385 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_XAudio_x86.cab (4900 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2007_d3dx9_35_x86.cab (34733 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_XACT_x86.cab (1503 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_X3DAudio_x86.cab (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\dxupdate.cab (1849 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_D3DCompiler_43_x86.cab (16808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_XAudio_x86.cab (6547 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_d3dx9_40_x64.cab (30555 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2010_XAudio_x64.cab (6523 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_d3dx10_37_x86.cab (14668 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_d3dcsx_43_x86.cab (14227 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_XAudio_x86.cab (4920 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2008_XAudio_x64.cab (4852 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2005_d3dx9_25_x64.cab (19138 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_D3DCompiler_42_x86.cab (17226 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_d3dx9_41_x64.cab (45112 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\temp_0.tmp (14404 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2007_d3dx10_35_x64.cab (15425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0002.tmp (14404 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_d3dx9_37_x64.cab (28720 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2007_d3dx10_35_x86.cab (16252 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2005_d3dx9_25_x86.cab (17848 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2006_xinput_x64.cab (3075 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Dec2005_d3dx9_28_x86.cab (17231 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2007_d3dx10_36_x86.cab (18499 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2005_d3dx9_27_x86.cab (17231 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_XAudio_x64.cab (4945 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2007_d3dx10_36_x64.cab (15795 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2005_d3dx9_27_x64.cab (20953 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0004.tmp (14404 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_d3dx9_43_x86.cab (12679 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2010_X3DAudio_x64.cab (683 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2006_d3dx9_29_x64.cab (22025 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_d3dx10_43_x64.cab (6095 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_XAudio_x86.cab (5285 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_d3dx10_40_x64.cab (16329 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0006.tmp (14404 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\NOV2007_X3DAudio_x86.cab (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2008_d3dx9_39_x64.cab (27151 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2006_XACT_x64.cab (3624 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2008_d3dx9_39_x86.cab (23198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2007_d3dx10_34_x86.cab (11482 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2006_MDX1_x86.cab (16914 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2005_d3dx9_24_x64.cab (20378 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2005_d3dx9_26_x64.cab (22088 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0005.tmp (14404 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2007_d3dx9_36_x64.cab (29773 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_XACT_x64.cab (3069 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\APR2007_d3dx10_33_x64.cab (12314 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_X3DAudio_x86.cab (1882 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\OCT2006_XACT_x64.cab (4852 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2007_XACT_x64.cab (5028 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\2.tmp (418 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_XACT_x64.cab (3530 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_d3dcsx_43_x64.cab (14558 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2005_d3dx9_26_x86.cab (19193 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_d3dx10_41_x86.cab (17373 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_d3dx10_37_x64.cab (14641 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\OCT2006_d3dx9_31_x64.cab (20272 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_XACT_x64.cab (3602 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_D3DCompiler_43_x64.cab (17184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Oct2005_xinput_x86.cab (2114 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2010_XACT_x86.cab (1089 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2007_d3dx10_34_x64.cab (12870 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2010_X3DAudio_x86.cab (841 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2010_XACT_x64.cab (1991 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0003.tmp (14404 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_d3dx9_41_x86.cab (23900 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_d3dx9_38_x86.cab (23827 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\APR2007_d3dx9_33_x64.cab (24421 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_XAudio_x64.cab (5217 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_X3DAudio_x86.cab (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_XACT_x86.cab (2715 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0001.tmp (14404 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_X3DAudio_x86.cab (1984 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_d3dx10_42_x64.cab (4254 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\15.tmp (110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2006_XACT_x86.cab (2011 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2008_XACT_x64.cab (2426 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\NOV2007_XACT_x64.cab (4808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DEC2006_d3dx10_00_x86.cab (4730 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\dxdllreg_x86.cab (1424 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2007_d3dx9_34_x64.cab (24515 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2006_XACT_x64.cab (3659 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0009.tmp (14404 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_X3DAudio_x64.cab (587 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Dec2005_d3dx9_28_x64.cab (21049 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\FEB2007_XACT_x86.cab (2514 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_d3dcsx_42_x86.cab (51118 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DEC2006_d3dx9_32_x86.cab (23370 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_XACT_x64.cab (3497 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_XACT_x86.cab (2658 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_d3dx9_42_x86.cab (12362 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2006_XACT_x86.cab (3396 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0007.tmp (14404 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_XAudio_x86.cab (6228 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Oct2005_xinput_x64.cab (638 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2008_d3dx10_39_x64.cab (17527 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_d3dx10_38_x86.cab (15378 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2005_d3dx9_24_x86.cab (23695 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_d3dx9_42_x64.cab (20143 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_XACT_x86.cab (1484 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\OCT2006_d3dx9_31_x86.cab (19019 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\APR2007_d3dx10_33_x86.cab (18378 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_XACT_x86.cab (2729 bytes)

The process DXSETUP.exe:1376 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DSETUP.dll (90 bytes)
C:\Windows\Logs\DirectX.log (256 bytes)

The process regsvr32.exe:704 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files% (x86)\360\Total Security\MenuEx64.dll (614 bytes)

The process %original file name%.exe:2428 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D285HURO\collect[1].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnE947.tmp\StdUtils.dll (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnE947.tmp\System.dll (808 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnE947.tmp\license.rtf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd45AA.tmp.exe (6529759 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss6FC6.tmp.exe (2170387 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JUC72OXY\collect[1].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JUC72OXY\collect[2].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnE946.tmp (6936 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnE947.tmp\nsDialogs.dll (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnE947.tmp (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360TS.jpg (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6HVGFTJ0\collect[1].gif (35 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HDZ3KS6S\Directx_9.10.11[1].exe (6103585 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnE947.tmp\inetc.dll (812 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnE947.tmp\nsRichEdit.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6HVGFTJ0\360TotalSecurity_Rus_Setup_0001[1].exe (2034898 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\stats.txt (140 bytes)

The process QHActiveDefense.exe:1168 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Windows\System32\drivers\360fsflt.sys (1740 bytes)
%Program Files% (x86)\360\Total Security\safemon\SelfProtectAPI2.dll (319 bytes)
%Program Files% (x86)\360\Total Security\deepscan\360FsFlt.sys (315 bytes)

The process QHActiveDefense.exe:804 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

\\192.168.50.163\PIPE\srvsvc (14264 bytes)
%Program Files% (x86)\360\Total Security\deepscan\netconf.dat (2 bytes)
%Program Files% (x86)\360\Total Security\ipc\360Camera64.sys (40 bytes)
%Program Files% (x86)\360\Total Security\safemon\WDRecord.dll (184 bytes)
%Program Files% (x86)\360\Total Security\Logs\Administrators\ipc\galaxy2.dat (17110 bytes)
%Program Files% (x86)\360\Total Security\safemon\param.ini (24 bytes)
%Program Files% (x86)\360\Total Security\ipc\filecache\FileCache.dat (1123 bytes)
%Program Files% (x86)\360\Total Security\sites.dll (49 bytes)
%Program Files% (x86)\360\Total Security\scanstub.dll (176 bytes)
%Program Files% (x86)\360\Total Security\safescan.dll (348 bytes)
%Program Files% (x86)\360\Total Security\safemon\filelog.db (1141 bytes)
%Program Files% (x86)\360\Total Security\ipc\qutmipc.dll (167 bytes)
%Program Files% (x86)\360\Total Security\filemon\WhiteCache.dll (49 bytes)
%Program Files% (x86)\360\Total Security\softmgr\SoftMgr.db (1 bytes)
C:\ProgramData\360safe\LogInfo\New360_tmp_1429761230_2620.log2 (460 bytes)
%Program Files% (x86)\360\Total Security\ipc\filecache\FileCache.dat{488f2569-df83-11e4-91a7-0050562b2045}.TMContainer00000000000000000002.regtrans-ms (712 bytes)
%Program Files% (x86)\360\Total Security\ipc\360AntiHacker64.sys (102 bytes)
%Program Files% (x86)\360\Total Security\ipc\filecache\FileCache.dat{488f2569-df83-11e4-91a7-0050562b2045}.TM.blf (2654 bytes)
%Program Files% (x86)\360\Total Security\filemon\wcachedb.db (345 bytes)
%Program Files% (x86)\360\Total Security\softmgr\somkernl.dll (291 bytes)
%Program Files% (x86)\360\Total Security\softmgr\SomAdvUtils.dll (888 bytes)
%Program Files% (x86)\360\Total Security\softmgr\SoftMgr.db-journal (512 bytes)
%Program Files% (x86)\360\Total Security\deepscan\speedmem2.hg-journal (459392 bytes)
%Program Files% (x86)\360\Total Security\deepscan\speedmem2.hg (72144 bytes)
%Program Files% (x86)\360\Total Security\filemon\360AVFlt64.sys (81 bytes)
%Program Files% (x86)\360\Total Security\ipc\filecache\FileCache.dat.LOG1 (1048 bytes)
%Program Files% (x86)\360\Total Security\ipc\yhregd.dll (409 bytes)
C:\Windows\System32\drivers\360Camera64.sys (40 bytes)
%Program Files% (x86)\360\Total Security\safemon\filelog.db-journal (5490 bytes)
%Program Files% (x86)\360\Total Security\filemon\wcachedb.db-journal (528 bytes)
%Program Files% (x86)\360\Total Security\ipc\filecache\FileCache.dat{488f2569-df83-11e4-91a7-0050562b2045}.TMContainer00000000000000000001.regtrans-ms (1224 bytes)

The process nss6FC6.tmp.exe:1904 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files% (x86)\360\Total Security\i18n\vi\ipc\filemon.dat (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\udisk.locale (444 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\safemon\drvmon.dat (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\urllib.dat (600 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360P2SP.dll (9112 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\360InternationTray\image\toast_speed_slow.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\libsdi.dat (84 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\safemon\SelfProtectAPI2.dll.locale (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\Safemon.dll.locale (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\gamemode.tpi (129 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\DsSysRepair.dll (6372 bytes)
%Program Files% (x86)\360\Total Security\ipc\appdef.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360SelfProtection.sys (1691 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\ipc\Sxin64.dll.locale (14 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\safemon\UDiskScanEngine.dll.locale (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\SelfProtectAPI2.dll.locale (12 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\regmon.dat (47 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360liveupdate\360liveupdate_theme.ui (137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\UrlSettings.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360InternationTray\image (4 bytes)
%Program Files% (x86)\360\Total Security\tools.xml (2 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\ipc\appmon.dat (19 bytes)
%Program Files% (x86)\360\Total Security\safescan.dll (2105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\endata\h_2.dat (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\UrlSettings.dll.locale (12 bytes)
%Program Files% (x86)\360\Total Security\ipc\qutmipc.dll (673 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\safemon\udisk.locale (486 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\360SPTool.exe.locale (32 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\ipc\Sxin.dll.locale (14 bytes)
%Program Files% (x86)\360\Total Security\filemon\360rp.dll (18248 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\webprotection_firefox\plugins\nptswp.dll.locale (9 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\appmon.dat (21 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\deepscan\dsr.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wificonfig\ra1000.dat (607 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\safemon.dll.locale (21 bytes)
%Program Files% (x86)\360\Total Security\deepscan\wificonfig\ra1005.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\UDiskScanEngine.dll.locale (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\deepscan\dsr.dat (1020 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\QHSafeTray.exe (10758 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\libaw.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360NetBase.dll (4426 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\360ipc.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\deepscan\DsRes64.dll (1548 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\safemon\360procmon.dll.locale (601 bytes)
%Program Files% (x86)\360\Total Security\safemon\wdk.ini (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\filemon.dat (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\Sxin64.dll.locale (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\deepscan\art.dat (18 bytes)
%Program Files% (x86)\360\Total Security\deepscan\dsbs.dat (38 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\deepscan\art.dat (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\appdext.dll (1726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360NetBase64.dll (4336 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\360SPTool.exe.locale (32 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\deepscan\DsRes.dll (62 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\UDiskScanEngine.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\deepscan\deepscan.dll (17072 bytes)
%Program Files% (x86)\360\Total Security\scanstub.dll (673 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\ipc\filemgr.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\360SPTool.exe.locale (32 bytes)
%Program Files% (x86)\360\Total Security\config\lang\hi\SysSweeper.ui.dat (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\safemon\360SPTool.exe.locale (32 bytes)
%Program Files% (x86)\360\Total Security\safemon\webprotection_firefox\chrome\content\main.js (2 bytes)
%Program Files% (x86)\360\Total Security\safemon\urlproc.dll (4185 bytes)
%Program Files% (x86)\360\Total Security\deepscan\DsSysRepair.dll (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\webprotection_firefox\chrome.manifest (275 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\WDRecord.dll (1920 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\regmon.dat (47 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360InternationTray\image\toast_speed_slow.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\360ipc.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\filemon.dat (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\sweeper\CleanHelper64.exe (723 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\deepscan\dsurls.dat (844 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\ipc\regmon.dat (44 bytes)
%Program Files% (x86)\360\Total Security\EfiMon.sys (23 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\ImAVEng.dll (1507 bytes)
%Program Files% (x86)\360\Total Security\scanbase.dll (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\deepscan\dsr.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\360ipc.dat (1 bytes)
%Program Files% (x86)\360\Total Security\3G\LibOui.dat (2105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\360AvFlt.sys (68 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\dynlenv.dll (4491 bytes)
%Program Files% (x86)\360\Total Security\filemon\360avflt64.sys (601 bytes)
%Program Files% (x86)\360\Total Security\DumpUper.ini (170 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\NetDefender.dll.locale (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\updatecfg.ini (128 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\drvmk.dat (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\filemgr.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\deepscan\DsRes.dll (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\libdefa.dat (160 bytes)
%Program Files% (x86)\360\Total Security\softmgr\somkernl.dll (23062 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\ipc\regmon.dat (44 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\default_theme.ui (2321 bytes)
%Program Files% (x86)\360\Total Security\safemon\wdui2.dll (3361 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\ipc\filemon.dat (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\urlproc.dll (4863 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wificonfig\ra1005.dat (1 bytes)
%Program Files% (x86)\360\Total Security\sweeper\CleanHelper64.exe (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\safemon\360SafeCamera.tpi.locale (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (111 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\deepscan\dsconz.dat (12 bytes)
%Program Files% (x86)\360\Total Security\deepscan\PopSoftEng.dll (3073 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\deepscan\DsRes64.dll (601 bytes)
%Program Files% (x86)\360\Total Security\CleanPlus.dll (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\deepscan\WifiAgent.dll (1281 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\Sxin.dll.locale (16 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\ipc\360netd.dat (29 bytes)
%Program Files% (x86)\360\Total Security\safemon\360GuardBase.dll (1425 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\ipc\filemon.dat (17 bytes)
%Program Files% (x86)\360\Total Security\sweeper\SysSweeper.dat (5441 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\libdefa.dat (213 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\NetDefender.dll.locale (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\libsdi.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\SelfProtectAPI2.dll.locale (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\leakrepair.dll (8648 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\filemon.dat (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\wd.ini (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360TsLiveUpd.exe (8594 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\NetDefender.dll.locale (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\qex\qex.dll (14497 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\360SafeCamera.tpi.locale (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\sites.dll (10999 bytes)
%Program Files% (x86)\360\Total Security\360Common.dll (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\360Downloads.ini (269 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\libaw.dat (2343 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\360netr.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\deepscan\art.dat (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\udisk.locale (334 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\filemon.dat (17 bytes)
%Program Files% (x86)\360\Total Security\360Util.dll (3073 bytes)
%Program Files% (x86)\360\Total Security\safemon\360AV.tpi (1425 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\safemon\360SafeCamera.tpi.locale (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\360netd.dat (29 bytes)
%Program Files% (x86)\360\Total Security\safemon\360uac.dat (8 bytes)
%Program Files% (x86)\360\Total Security\ipc\360AntiHacker64.sys (601 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\360leakfix\360leakfix_theme.ui (1425 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\safemon\wd.ini (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\chrome\360webshield.exe.locale (15 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\AntiAdwa.dll.locale (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\deepscan (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\fr4.dat (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1429760925_00000000_base\360base.dll (1815 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\deepscan\dsurls.dat (844 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\sweeper\TrashClean.dll (4180 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\deepscan\dsr.dat (87 bytes)
%Program Files% (x86)\360\Total Security\deepscan\dswtb.dat (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\360netr.dat (1 bytes)
%Program Files% (x86)\360\Total Security\filemon\fr8.dat (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360.dat (13 bytes)
%Program Files% (x86)\360\Total Security\i18n\i18n.ini (490 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\filemgr.dll.locale (11 bytes)
%Program Files% (x86)\360\Total Security\deepscan\csp.dat (8 bytes)
%Program Files% (x86)\360\Total Security\rpi.dat (972 bytes)
%Program Files% (x86)\360\Total Security\deepscan\wificonfig\ra1000.dat (607 bytes)
%Program Files% (x86)\360\Total Security\ipc\360AntiHacker.sys (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\safemon\wd.ini (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\360netd.dat (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\deepscan\DsRes64.dll (64 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\PatchUp.exe (6084 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\libvi.dat (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\3G\3GIdentify.dll (3418 bytes)
%Program Files% (x86)\360\Total Security\filemon\360AvFlt.dll (95 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\360procmon.dll.locale (101 bytes)
%Program Files% (x86)\360\Total Security\deepscan\AVE\AVEngine.dll (7345 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\qex\MacroDef.enc (6 bytes)
%Program Files% (x86)\360\Total Security\safemon\webprotection_firefox\install.rdf (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\deepscan\dsconz.dat (12 bytes)
%Program Files% (x86)\360\Total Security\deepscan\DsArk.sys (601 bytes)
%Program Files% (x86)\360\Total Security\360SkinView.exe (2105 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\deepscan\dsconz.dat (12 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\ipc\appmon.dat (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\360ipc.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\safemon\360procmon.dll.locale (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\ipc\Sxin.dll.locale (16 bytes)
%Program Files% (x86)\360\Total Security\360ShellPro.exe (673 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\ipc\appd.dll.locale (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\UrlSettings.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\scanbase.dll (1123 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\safemon\360SafeCamera.tpi.locale (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\deepscan\ssr.dat (53 bytes)
%Program Files% (x86)\360\Total Security\ipc\appdext.dll (673 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\deepscan\DsRes.dll (601 bytes)
%Program Files% (x86)\360\Total Security\I18N.dll (691 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\libdefa.dat (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\iNetSafe.dll (2464 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360Base64.dll (7247 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\NetDefender.dll.locale (13 bytes)
%Program Files% (x86)\360\Total Security\deepscan\dswc.dat (50 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\NetDefender.dll.locale (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\feedback\FeedBack_theme.ui (87 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\LibSDI.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360ShellPro.exe (2114 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\safemon\drvmon.dat (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\Safemon.dll.locale (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\CombineExt.dll (1567 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\360netr.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\deepscan\DsRes64.dll (1542 bytes)
%Program Files% (x86)\360\Total Security\ipc\clsid.dat (22 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\deepscan\dsconz.dat (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\360netd.dat (29 bytes)
%Program Files% (x86)\360\Total Security\360Base.dll (6841 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\libaw.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\deepscan\DsRes64.dll (1370 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\netmon\gameidentify.dat (91 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\3G\LibOui.dat (365 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\filemon.dat (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\360SPTool.exe.locale (28 bytes)
%Program Files% (x86)\360\Total Security\deepscan\LibOui.dat (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\AntiAdwa.dll.locale (34 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\360SafeCamera.tpi.locale (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\appd.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\wd.ini (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\yhregd.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\safemon\drvmon.dat (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\deepscan\art.dat (19 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\ipc\360netd.dat (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\UDiskScanEngine.dll.locale (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\360SafeCamera.tpi.locale (1 bytes)
%Program Files% (x86)\360\Total Security\sweeper\SysSweeper.dll (4545 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\wd.ini (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\endata\h_1.dat (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\360netr.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\libdefa.dat (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\deepscan\art.dat (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\SelfProtectAPI2.dll.locale (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360GuardBase.dll (4626 bytes)
%Program Files% (x86)\360\Total Security\MenuEx.dll (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\regmon.dat (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\UDiskScanEngine.dll.locale (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\AVLib.dat (360 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\ipc\Sxin.dll.locale (15 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\Sxin64.dll.locale (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\QHToasts.exe (3100 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\libdefa.dat (673 bytes)
%Program Files% (x86)\360\Total Security\deepscan\qutmdrv.sys (1281 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\ipc\regmon.dat (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\drvmon.dat (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\filemon.dat (17 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\deepscan\dsconz.dat (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\zh-CN\SysSweeper.ui.dat (114 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\deepscan\CheckSM.dll (1425 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\libaw.dat (9605 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\AntiAdwa.dll.locale (38 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\safemon\safemon.dll.locale (20 bytes)
%Program Files% (x86)\360\Total Security\dynlbase.dll (6841 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\ipc\360netr.dat (1 bytes)
%Program Files% (x86)\360\Total Security\deepscan\wificonfig\ra1003.dat (1 bytes)
%Program Files% (x86)\360\Total Security\360DeskAna.exe (1425 bytes)
%Program Files% (x86)\360\Total Security\deepscan\DsArk.dll (673 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\wdk.ini (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\deepscan\dsr.dat (82 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\360SafeCamera.tpi.locale (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\chrome\360webshield.exe.locale (15 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\safemon\360SPTool.exe.locale (32 bytes)
%Program Files% (x86)\360\Total Security\safemon\360drwht.dat (42 bytes)
%Program Files% (x86)\360\Total Security\safemon\QHToasts.exe (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\deepscan\dsurls.dat (844 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\deepscan\art.dat (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\regmon.dat (46 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\libdefa.dat (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\deepscan\dsr.dat (82 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\deepscan\DsRes64.dll (601 bytes)
%Program Files% (x86)\360\Total Security\Sites64.dll (15019 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\360SPTool.exe.locale (32 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\ipc\regmon.dat (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360zipc.dll (5513 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\360SafeCamera.tpi.locale (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\hookport.sys (397 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360uac.dat (8 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\360InternationSafe\360InternationSafe_theme.ui (55596 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\deepscan\dsr.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360DeskAna64.exe (3906 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\LibSDI.dat (601 bytes)
%Program Files% (x86)\360\Total Security\ipc\DrvUtility.dll (828 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\deepscan\DsRes.dll (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\DumpUper.ini (170 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\360ipc.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\safemon\360procmon.dll.locale (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\Dumpuper.exe.locale (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\deepscan\dsconz.dat (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\wdui2.dll (7710 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\router.ini (274 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp.7z (27684 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\udiskscan.dat (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\deepscan\dsurls.dat (844 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\ptype.dat (2 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\UrlSettings.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\vi\SysSweeper.ui.dat (128 bytes)
%Program Files% (x86)\360\Total Security\softmgr\360SoftMgrS.dll (2321 bytes)
%Program Files% (x86)\360\Total Security\safemon\360zipc.dll (4185 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\drvmon.dat (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\libvi.dat (130 bytes)
%Program Files% (x86)\360\Total Security\filemon\360AvFlt.sys (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\safemon\udisk.locale (490 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\filemon.dat (17 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\libdefa.dat (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\360SPTool.exe.locale (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\PDown.dll (2025 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\deepscan\dsr.dat (601 bytes)
%Program Files% (x86)\360\Total Security\ipc\360AntiHacker.dll (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\libvi.dat (130 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\SomAdvUtils.dll (8690 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\Sxin64.dll.locale (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360Util.dll (5342 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\AntiAdwa.dll.locale (601 bytes)
%Program Files% (x86)\360\Total Security\360net.dll (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\360procmon.dll.locale (101 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\DSFScan.dll (3996 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\deepscan\dsr.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\libaw.dat (1 bytes)
%Program Files% (x86)\360\Total Security\360Base64.dll (7547 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\libvi.dat (130 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\LibOui.dat (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\libvi.dat (130 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\qutmipc.dll (2626 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\ipcService.dll (5373 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360skinview\360skinview_theme.ui (45 bytes)
%Program Files% (x86)\360\Total Security\deepscan\wificonfig\ra1004.dat (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\libaw.dat (1 bytes)
%Program Files% (x86)\360\Total Security\deepscan\qex\patt.enc (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\deepscan\DsRes.dll (1406 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\deepscan\DsRes.dll (64 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\Dumpuper.exe.locale (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\wd.ini (8 bytes)
%Program Files% (x86)\360\Total Security\ipc\360boxld64.exe (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\TR\SysSweeper.ui.dat (123 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\ipc\360ipc.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\deepscan\art.dat (29 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\safemon\wdk.ini (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\DsArk.dll (1796 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\deepscan\DsRes.dll (601 bytes)
%Program Files% (x86)\360\Total Security\deepscan\cloudsec2.dll (7547 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\deepscan\ssr.dat (45 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wificonfig\ra1004.dat (2 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\ipc\yhregd.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\360skinview\360skinview_theme.ui (45 bytes)
%Program Files% (x86)\360\Total Security\safemon\hookport.sys (58 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\filemgr.dll.locale (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\AntiAdwa.dll.locale (89 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\deepscan\dsconz.dat (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\regmon.dat (44 bytes)
%Program Files% (x86)\360\Total Security\safemon\360SPTool.exe (673 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\safemon\udisk.locale (254 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\deepscan\dsconz.dat (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\deepscan\dsr.dat (55 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\safemon\safemon.dll.locale (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\appmon.dat (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\deepscan\DsRes64.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\Sxin64.dll.locale (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\deepscan\DsRes.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\Sxin.dll.locale (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\libvi.dat (130 bytes)
%Program Files% (x86)\360\Total Security\safemon\wdui3.dll (5441 bytes)
%Program Files% (x86)\360\Total Security\360TsLiveUpd.exe (6841 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\ipc\360netd.dat (29 bytes)
%Program Files% (x86)\360\Total Security\safemon\QHWatchdog.exe (601 bytes)
%Program Files% (x86)\360\Total Security\libredlist.dat (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\deepscan (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\360procmon.dll.locale (100 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\QHVer.dll (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\Sxin64.dll.locale (16 bytes)
%Program Files% (x86)\360\Total Security\safemon\WDPayPro.exe (9098 bytes)
%Program Files% (x86)\360\Total Security\config\config.xml (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\SomProxy.dll (3594 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\safemon\360SPTool.exe.locale (32 bytes)
%Program Files% (x86)\360\Total Security\softmgr\AdvUtils.ini (146 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360InternationTray\image\toast_speed_reallyfast.png (2 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\Dumpuper.exe.locale (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\signbwl.dat (684 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\SelfProtectAPI2.dll.locale (15 bytes)
%Program Files% (x86)\360\Total Security\ipc\360Box.sys (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\NetDefender.dll.locale (13 bytes)
%Program Files% (x86)\360\Total Security\filemon\fr4.dat (7 bytes)
%Program Files% (x86)\360\Total Security\dynlenv.dll (3361 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\webprotection_firefox\icon64.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\MenuEx.dll (3246 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\ipc\appd.dll.locale (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\libdefa.dat (160 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\Sxin.dll.locale (16 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\safemon\UDiskScanEngine.dll.locale (8 bytes)
%Program Files% (x86)\360\Total Security\deepscan\wificonfig\ra1001.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\libleak.dat (228 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\wdk.ini (3 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\360InternationTray\image\toast_speed_reallyfast.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\cloudsec2.dll (8633 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\deepscan (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\ipc\filemgr.dll.locale (11 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\stsuglist.dat (112 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\libvi.dat (130 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\rpi.dat (972 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\deepscan\DsRes.dll (1465 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\zh-TW\SysSweeper.ui.dat (114 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\Sxin.dll.locale (16 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\safemon\UDiskScanEngine.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\ipc\Sxin64.dll.locale (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\360QuarantPlugin.dll (4573 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\LibSDI.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\UrlSettings.dll.locale (12 bytes)
%Program Files% (x86)\360\Total Security\config\lang\zh-TW\SysSweeper.ui.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\chrome\360webshield.exe.locale (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (112 bytes)
%Program Files% (x86)\360\Total Security\MiniUI.dll (6841 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\drvms.dat (3 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\deepscan\ssr.dat (48 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\libvi.dat (130 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\yhregd.dll.locale (9 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\safemon\UDiskScanEngine.dll.locale (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\360netd.dat (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\wdk.ini (3 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\safemon\Safemon.dll.locale (21 bytes)
%Program Files% (x86)\360\Total Security\deepscan\DSFScan.dll (2105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\NetDefender.dll.locale (16 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\Dumpuper.exe.locale (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\SXIn.dll (5904 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\Dumpuper.exe.locale (1 bytes)
%Program Files% (x86)\360\Total Security\config\lang\ru\SysSweeper.ui.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\deepscan (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\netmon\Netgm.dll (3254 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dswc.dat (50 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\safemon\chrome\360webshield.exe.locale (15 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\safemon\chrome\360webshield.exe.locale (15 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\UrlSettings.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\UDiskScanEngine.dll.locale (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\fr5.dat (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\deepscan\ssr.dat (48 bytes)
%Program Files% (x86)\360\Total Security\deepscan\sndw.dat (10 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\ipc\Sxin64.dll.locale (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\Cloudsec3.dll (8817 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\ipc\Sxin.dll.locale (16 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\appd.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\deepscan\cloudcom2.dll (7547 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\ipc\Sxin.dll.locale (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\appd.dll.locale (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\qutmload.dll (1833 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\ipc\NetDefender.dll.locale (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\chrome\360webshield.exe.locale (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\AVE\AVEngine.dll (8584 bytes)
%Program Files% (x86)\360\Total Security\safemon\WscReg.exe (22336 bytes)
%Program Files% (x86)\360\Total Security\ipc\360boxmain.exe (4185 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\QHSafeMain.exe (29771 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\ipc\yhregd.dll.locale (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\LibSDI.dat (78 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\ipc\yhregd.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\deepscan\art.dat (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\yhregd.dll.locale (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360InternationTray\image\toasts_waring.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\360SoftMgrS.dll (4865 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\360rp.dll (20395 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\deepscan\DsRes64.dll (377 bytes)
%Program Files% (x86)\360\Total Security\PDown.dll (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\yhregd.dll.locale (11 bytes)
%Program Files% (x86)\360\Total Security\endata\h_3.dat (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\Dumpuper.exe.locale (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\deepscan\art.dat (16 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\deepscan\DsRes.dll (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\Dumpuper.exe.locale (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\config.xml (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\AntiAdwa.dll.locale (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\SelfProtectAPI2.dll.locale (11 bytes)
%Program Files% (x86)\360\Total Security\deepscan\wificonfig\ra1002.dat (1 bytes)
%Program Files% (x86)\360\Total Security\deepscan\BAPI.dll (1526 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\X64For32Lib.dll (53 bytes)
%Program Files% (x86)\360\Total Security\ipc\360boxld.exe (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\chrome\360webshield.exe.locale (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\deepscan\ssr.dat (45 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\wd.ini (8 bytes)
%Program Files% (x86)\360\Total Security\endata\h_1.dat (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\deepscan\dsconz.dat (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safescan.dll (2325 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\LibSDI.dat (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\UrlSettings.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\CQhCltHttpW.dll (3932 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360drwht.dat (42 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\360wdui\360wdui_theme.ui (5441 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\deepscan\dsconz.dat (12 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\wd.ini (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\deepscan\dsr.dat (82 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\NetDefender.dll.locale (14 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\ipc\appd.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\filemgr.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\chrome\manifest.json (332 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\udisk.locale (334 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\deepscan (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\SelfProtectAPI2.dll.locale (14 bytes)
%Program Files% (x86)\360\Total Security\safemon\drvms.dat (3 bytes)
%Program Files% (x86)\360\Total Security\PatchUp.exe (5441 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360AntiHacker.sys (1101 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\ipc\Sxin.dll.locale (14 bytes)
%Program Files% (x86)\360\Total Security\AntiAdwa.dll (22336 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\360netd.dat (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\webprotection_firefox\chrome\content\main.js (2 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\ipc\360netd.dat (29 bytes)
%Program Files% (x86)\360\Total Security\safemon\chrome\360webshield.exe (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\libredlist.dat (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\udisk.locale (490 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360Verify.dll (1321 bytes)
%Program Files% (x86)\360\Total Security\safemon\chrome\manifest.json (332 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\360CleanPlus\360CleanPlus_theme.ui (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\360procmon.dll.locale (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\Dumpuper.exe.locale (1 bytes)
%Program Files% (x86)\360\Total Security\deepscan\art.dat (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\WifiAgent.dll (2742 bytes)
%Program Files% (x86)\360\Total Security\ipc\cleancfg.dat (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\EfiProc.dll (1742 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\ipc\Sxin64.dll.locale (16 bytes)
%Program Files% (x86)\360\Total Security\libleakres.dat (16582 bytes)
%Program Files% (x86)\360\Total Security\deepscan\wificonfig\ra1006.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\Uninstall.exe (12812 bytes)
%Program Files% (x86)\360\Total Security\deepscan\dserror.dat (1 bytes)
%Program Files% (x86)\360\Total Security\ipc\FileMgr.dll (2105 bytes)
%Program Files% (x86)\360\Total Security\writeable_test_495427.dat (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\SXIn64.dll (5863 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\360SPTool.exe.locale (28 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\safemon\360SafeCamera.tpi.locale (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\safemon\360procmon.dll.locale (601 bytes)
%Program Files% (x86)\360\Total Security\softmgr\safespeedboot.dat (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\360netd.dat (29 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\Dumpuper.exe.locale (1 bytes)
%Program Files% (x86)\360\Total Security\libleak-64.dat (22575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\regmon.dat (44 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\safemon\SelfProtectAPI2.dll.locale (13 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\libvi.dat (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\libvi.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\pt\SysSweeper.ui.dat (123 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\NetDefender.dll.locale (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wificonfig\ra1002.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\ipc\NetDefender.dll.locale (16 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\chrome\360webshield.exe.locale (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\deepscan.dll (22163 bytes)
C:\Windows\System32\drivers\360Box64.sys (1425 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\deepscan\art.dat (19 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\safemon\webprotection_firefox\plugins\nptswp.dll.locale (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\AVE\AVEI.dll (1750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\Sxin64.dll.locale (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\CheckSM.exe (3191 bytes)
%Program Files% (x86)\360\Total Security\deepscan\360netcfg.exe (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\tools.xml (2 bytes)
%Program Files% (x86)\360\Total Security\ipc\TS.dat (748 bytes)
%Program Files% (x86)\360\Total Security\config\defaultskin\defaultskin.ui (1281 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\safemon\Safemon.dll.locale (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\UDiskScanEngine.dll (4765 bytes)
%Program Files% (x86)\360\Total Security\deepscan\qex\qex.dll (11518 bytes)
%Program Files% (x86)\360\Total Security\filemon\FsrMgr.dll (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360wdui\360wdui_theme.ui (735 bytes)
%Program Files% (x86)\360\Total Security\deepscan\sysfilerepS.dll (1425 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\deepscan\dsconz.dat (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\SxWrapper.dll (1169 bytes)
%Program Files% (x86)\360\Total Security\mui\en\Strings.dat (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\libsdi.dat (1673 bytes)
%Program Files% (x86)\360\Total Security\endata\h_2.dat (2 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\safemon\SelfProtectAPI2.dll.locale (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\360ipc.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\ipc\filemon.dat (17 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\libsdi.dat (601 bytes)
%Program Files% (x86)\360\Total Security\safemon\360SafeCamera.tpi (2321 bytes)
%Program Files% (x86)\360\Total Security\ipc\SXIn.dll (3073 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dserror.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\ipc\NetDefender.dll.locale (15 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\Antiadwa.dll.locale (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\AntiAdwa.dll.locale (87 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\WiFiSafe.dll (13152 bytes)
%Program Files% (x86)\360\Total Security\deepscan\360FsFlt.sys (1425 bytes)
%Program Files% (x86)\360\Total Security\Dumpuper.exe (4545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\appd.dll.locale (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\7z.dll (50 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\deepscan\art.dat (20 bytes)
%Program Files% (x86)\360\Total Security\endata\lm_1001.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360Conf.dll (3082 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\filemgr.dll.locale (11 bytes)
%Program Files% (x86)\360\Total Security\ipc\signbwl.dat (684 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\deepscan\DsRes.dll (29 bytes)
%Program Files% (x86)\360\Total Security\ipc\qutmipc.sys (45 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\regmon.dat (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\ipc\NetDefender.dll.locale (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\360SPTool.exe.locale (31 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\ipc\360netr.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\ipc\360Camera64.sys (40 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\AntiAdwa.dll.locale (1279 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\ipc\appd.dll.locale (14 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\ipc\Sxin.dll.locale (16 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\Safemon.dll.locale (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\360Quarant.dll (4397 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\safemon\webprotection_firefox\plugins\nptswp.dll.locale (9 bytes)
%Program Files% (x86)\360\Total Security\safemon\QHActiveDefense.exe (5873 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\UrlSettings.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360UDisk\360UDisk_theme.ui (237 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\Antiadwa.dll.locale (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\WhiteCache.dll (12119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\Sxin.dll.locale (15 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\libvi.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\360AvFlt.dll (46 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\deepscan\DsRes.dll (1483 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360ipc.dat (1 bytes)
%Program Files% (x86)\360\Total Security\softmgr\SomAdvUtils.dll (6841 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\appd.dll.locale (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\cacert.pem (229 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\deepscan\ssr.dat (53 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\appd.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\cloudcom2.dll (10255 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\deepscan\DsRes64.dll (58 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\safemon\wdk.ini (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\Optadn.dat (11 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\deepscan\dsurls.dat (844 bytes)
%Program Files% (x86)\360\Total Security\deepscan\dsns.dat (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\deepscan\DsRes.dll (1551 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\drvmon.dat (4 bytes)
%Program Files% (x86)\360\Total Security\softmgr\SpeedUp.dll (673 bytes)
%Program Files% (x86)\360\Total Security\netmon\360GameIdentify.dll (1281 bytes)
%Program Files% (x86)\360\Total Security\safemon\360safemonpro.tpi (7971 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\ipc\360ipc.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\safemon\wd.ini (8 bytes)
%Program Files% (x86)\360\Total Security\deepscan\CQhCltHttpW.dll (2321 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dswtb.dat (263 bytes)
%Program Files% (x86)\360\Total Security\softmgr\Optadn.dat (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\UrlSettings.dll.locale (12 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\safemon\UDiskScanEngine.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\360bps.dat (676 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\LibSDI.dat (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\SpeedUp.dll (4095 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\sweeper (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\drvmon.dat (4 bytes)
%Program Files% (x86)\360\Total Security\QHSafeMain.exe (26096 bytes)
%Program Files% (x86)\360\Total Security\deepscan\dsws.dat (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\qex\patt.enc (416 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\defaultskin\MiniUI.xml (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360net.dll (4879 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\deepscan\dsconz.dat (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\execrule.dat (100 bytes)
%Program Files% (x86)\360\Total Security\MenuEx64.dll (4185 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\deepscan\dsconz.dat (12 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\deepscan\DsRes64.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\360SafeCamera.tpi.locale (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc (4 bytes)
%Program Files% (x86)\360\Total Security\safemon\360hipsPopWnd.dll (7726 bytes)
%Program Files% (x86)\360\Total Security\safemon\urllib.dat (4185 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\deepscan\dsr.dat (82 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\AntiAdwa.dll (29035 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\deepscan\ssr.dat (47 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\ru\SysSweeper.ui.dat (127 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\360FsFlt.sys (2375 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\CrashReport.dll (4712 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\ipc\regmon.dat (44 bytes)
%Program Files% (x86)\360\Total Security\CleanPlus.exe (4185 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\deepscan\dsurls.dat (844 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\libvi.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\wd.ini (8 bytes)
%Program Files% (x86)\360\Total Security\config.ini (278 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\libdefa.dat (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\deepscan\art.dat (18 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\deepscan\art.dat (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\deepscan (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360CleanPlus\360CleanPlus_theme.ui (109 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\BAPI.dll (3138 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\360sandbox\360sandbox_theme.ui (1425 bytes)
%Program Files% (x86)\360\Total Security\safemon\webprotection_firefox\chrome\content\browser.xul (560 bytes)
C:\Windows\System32\drivers\BAPIDRV64.SYS (857 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\Sxin.dll.locale (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\wdk.ini (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wificonfig\ra1006.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\safemon\SelfProtectAPI2.dll.locale (15 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\ipc\360netr.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\en\SysSweeper.ui.dat (115 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\sweeper\RemoteTrashInterface.dll (5508 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\ipc\360ipc.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\filemgr.dll.locale (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\appmon.dat (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\Sxin64.dll.locale (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360AntiHacker64.sys (1878 bytes)
%Program Files% (x86)\360\Total Security\sites.dll (8657 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\360netd.dat (29 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\libaw.dat (10177 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\libsdi.dat (83 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\safemon\360procmon.dll.locale (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\libvi.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\Dumpuper.exe.locale (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\libdefa.dat (162 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\ipc\filemon.dat (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\I18N.dll (280 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\chrome\360webshield.exe.locale (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360Box64.sys (2931 bytes)
%Program Files% (x86)\360\Total Security\softmgr\SomAdvUtilsWrap.dll (3073 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\360ipc.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\DrvUtility.dll (728 bytes)
%Program Files% (x86)\360\Total Security\CrashReport.dll (1425 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\UrlSettings.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360Camera.sys (1687 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\safemon\360procmon.dll.locale (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\UDiskScanEngine.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\netmon\Netgm.dll (1425 bytes)
%Program Files% (x86)\360\Total Security\ipc\360Box.dll (45 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\safemon\drvmon.dat (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\qutmdrv.sys (3004 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\udisk.locale (470 bytes)
%Program Files% (x86)\360\Total Security\ipc\yhregd.dll (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360bps.dat (676 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360InternationSafe\360InternationSafe_theme.ui (1363 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\udisk.locale (254 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\wdui3.dll (8454 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\deepscan\DsRes64.dll (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\Sxin64.dll.locale (16 bytes)
%Program Files% (x86)\360\Total Security\safemon\webprotection_firefox\chrome.manifest (275 bytes)
%Program Files% (x86)\360\Total Security\safemon\360SelfProtection.sys (673 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\360SPTool.exe.locale (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\tools\Tools_theme.ui (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\LibSDI.dat (95 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360SafeCamera.tpi (404 bytes)
%Program Files% (x86)\360\Total Security\config\lang\pt\SysSweeper.ui.dat (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\libvi.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dsbs.dat (38 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\SomAdvUtilsWrap.dll (5248 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\CheckSM.dll (4562 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\libaw.dat (457 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\UDiskScanEngine.dll.locale (8 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\libaw.dat (9605 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\360netcfg.exe (2047 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\drvmon.dat (5 bytes)
%Program Files% (x86)\360\Total Security\safemon\360Tray.exe (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\libleak-64.dat (275 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\libvi.dat (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\Dumpuper.exe.locale (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\safemon\wd.ini (8 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\safemon\udisk.locale (482 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\filemon.dat (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360Box.dll (1873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360boxld.exe (1209 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\deepscan\DsRes64.dll (635 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\filemon.dat (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\wd.ini (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon (4 bytes)
%Program Files% (x86)\360\Total Security\safemon\SomProxy.dll (2105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\deepscan\DsRes64.dll (2492 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\udisk.locale (486 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\UDiskScanEngine.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\safemon\SelfProtectAPI2.dll.locale (14 bytes)
%Program Files% (x86)\360\Total Security\safemon\dlproc.dll (4545 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dsark64.sys (1346 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\deepscan\art.dat (20 bytes)
%Program Files% (x86)\360\Total Security\I18N64.dll (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\drvmon.dat (5 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\ipc\yhregd.dll.locale (11 bytes)
%Program Files% (x86)\360\Total Security\LiveUpdate360.exe (4185 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\WDSafeDown.exe (1726 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\ipc\NetDefender.dll.locale (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\wdk.ini (3 bytes)
%Program Files% (x86)\360\Total Security\safemon\webprotection_firefox\icon64.png (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\yhregd.dll.locale (11 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\deepscan\dsr.dat (55 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\AntiAdwa.dll.locale (81 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\filemon\AVLib.dat (2105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360Common.dll (2070 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\deepscan\DsRes64.dll (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\safemon\360SPTool.exe.locale (32 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\ipc\Sxin64.dll.locale (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dsr.dat (82 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\Dumpuper.exe.locale (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\filemgr.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\SelfProtectAPI2.dll.locale (14 bytes)
%Program Files% (x86)\360\Total Security\filemon\fr1.dat (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\360procmon.dll.locale (100 bytes)
%Program Files% (x86)\360\Total Security\ipc\NetDefender.dll (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\libleakres.dat (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\yhregd.dll (5739 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\deepscan\art.dat (18 bytes)
%Program Files% (x86)\360\Total Security\safemon\drvmk.dat (52 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\appdef.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\webprotection_firefox\icon.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\360netr.dat (1 bytes)
%Program Files% (x86)\360\Total Security\3G\3GIdentify.dll (1281 bytes)
%Program Files% (x86)\360\Total Security\deepscan\dsconz.dat (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\deepscan\dsr.dat (82 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\deepscan\DsRes64.dll (62 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\360SPTool.exe.locale (30 bytes)
%Program Files% (x86)\360\Total Security\ipc\360Box64.sys (1425 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\360InternationTray\image\toasts_waring.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\LibSDI.dat (83 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\filemgr.dll.locale (11 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\ipc\NetDefender.dll.locale (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360boxld64.exe (3243 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\deepscan\DsRes64.dll (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\appd.dll.locale (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\UrlSettings.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\TS.dat (748 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\writeable_test_495552.dat (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\filemon.dat (17 bytes)
C:\Windows\System32\drivers\360AntiHacker64.sys (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\LiveUpd360.dll (4830 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\appmon.dat (21 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\deepscan\ssr.dat (48 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\ipc\filemgr.dll.locale (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\360ipc.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\360SPTool.exe.locale (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\Dumpuper.exe.locale (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\libaw.dat (9605 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\360netd.dat (29 bytes)
%Program Files% (x86)\360\Total Security\Utils\ModuleUpdate.exe (4185 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\safemon\wd.ini (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\360SafeCamera.tpi.locale (1 bytes)
%Program Files% (x86)\360\Total Security\deepscan\QVM\360QVM.dll (5873 bytes)
%Program Files% (x86)\360\Total Security\ipc\360ipc.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\ipc\NetDefender.dll.locale (16 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\safemon\wdk.ini (3 bytes)
%Program Files% (x86)\360\Total Security\safemon\udiskscan.dat (3 bytes)
%Program Files% (x86)\360\Total Security\sweeper\RemoteTrashInterface.dll (3073 bytes)
%Program Files% (x86)\360\Total Security\360Conf.dll (1425 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\deepscan\art.dat (18 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dsns.dat (2 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\UrlSettings.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wificonfig\ra1003.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\dslw\dslw.dat (5441 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\webprotection_firefox\plugins\nptswp.dll (3914 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\WDPayPro.exe (12859 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\safemon.dll.locale (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\libdefa.dat (160 bytes)
%Program Files% (x86)\360\Total Security\safemon\wduicfg.dat (10 bytes)
%Program Files% (x86)\360\Total Security\safemon\360procmon.dll (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\Dumpuper.exe.locale (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\chrome\360webshield.exe.locale (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\Safemon.dll.locale (18 bytes)
%Program Files% (x86)\360\Total Security\deepscan\AVE\AVEI.dll (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\deepscan (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\libdefa.dat (162 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\FeedBack.exe (7209 bytes)
%Program Files% (x86)\360\Total Security\deepscan\BAPIDRV.sys (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\regmon.dat (44 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\safemon\wdk.ini (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\Antiadwa.dll.locale (89 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\libaw.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\safemon\drvmon.dat (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\ipc\360netr.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360Camera64.sys (526 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\webprotection_firefox\plugins\nptswp.dll.locale (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\UrlSettings.dll.locale (12 bytes)
%Program Files% (x86)\360\Total Security\QHVer.dll (22 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\Antiadwa.dll.locale (89 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\clsid.dat (22 bytes)
%Program Files% (x86)\360\Total Security\safemon\SelfProtectAPI2.dll (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\appmon.dat (19 bytes)
%Program Files% (x86)\360\Total Security\deepscan\wpz.dat (835 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\Utils\ModuleUpdate.exe (6238 bytes)
%Program Files% (x86)\360\Total Security\config\lang\es\SysSweeper.ui.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\regmon.dat (44 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\deepscan\dsr.dat (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\AntiAdwa.dll.locale (34 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\safemon\wdk.ini (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\deepscan\ssr.dat (32 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\safemon\wd.ini (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\AntiAdwa.dll.locale (38 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\Sxin.dll.locale (16 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\safemon\SelfProtectAPI2.dll.locale (15 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\safemon\360SPTool.exe.locale (31 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\Sxin.dll.locale (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\yhregd.dll.locale (11 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\libaw.dat (9605 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\appd.dll.locale (13 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\libaw.dat (9605 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\ipc\appmon.dat (19 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\UrlSettings.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\deepscan (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\360ipc.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\360procmon.dll.locale (100 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\NetDefender.dll.locale (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\MenuEx64.dll (8092 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\360netd.dat (29 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\theme.xml (63 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\yhregd.dll.locale (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\CleanPlus.dll (2461 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\deepscan\DsRes.dll (748 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\safemon\safemon.dll.locale (21 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\360UDisk\360UDisk_theme.ui (1281 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\safemon\360SafeCamera.tpi.locale (1 bytes)
%Program Files% (x86)\360\Total Security\safemon\wd.ini (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\chrome\360webshield.exe.locale (15 bytes)
%Program Files% (x86)\360\Total Security\deepscan\CheckSM.exe (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\appmon.dat (21 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\LibSDI.dat (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\ipc\appd.dll.locale (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wificonfig (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\libvi.dat (521 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\tools\Tools_theme.ui (7385 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\safemon\udisk.locale (470 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\360SafeCamera.tpi.locale (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\drvmon.dat (4 bytes)
%Program Files% (x86)\360\Total Security\updatecfg.ini (623720 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\360InternationTray\image\toast_speed_medium.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360Tray.exe (4650 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\360ipc.dat (1 bytes)
%Program Files% (x86)\360\Total Security\config\lang\en\SysSweeper.ui.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\AntiAdwa.dll.locale (89 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\360netr.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\UrlSettings.dll.locale (12 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\deepscan\dsr.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\dynlbase.dll (8581 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\360liveupdate\360liveupdate_theme.ui (673 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\ipc\360netr.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\DataDriv.dat (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360compro.dll (5083 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\deepscan\DsRes64.dll (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (113 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc (4 bytes)
%Program Files% (x86)\360\Total Security\ipc\SXIn64.dll (3361 bytes)
%Program Files% (x86)\360\Total Security\safemon\QHSafeTray.exe (7726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\chrome\360webshield.exe (1676 bytes)
%Program Files% (x86)\360\Total Security\safemon\webprotection_firefox\plugins\nptswp.dll (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\sbmon.dll (3836 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\drvmon.dat (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (112 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\libaw.dat (1385 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\360InternationTray\360InternationTray_theme.ui (673 bytes)
%Program Files% (x86)\360\Total Security\Uninstall.exe (10177 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\filemgr.dll.locale (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360DeskAna.exe (4315 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\Sxin64.dll.locale (16 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\360AV\360AV_theme.ui (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\libaw.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\360netr.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\Dumpuper.exe.locale (1 bytes)
%Program Files% (x86)\360\Total Security\safemon\webprotection_firefox\icon.png (6 bytes)
%Program Files% (x86)\360\Total Security\safemon\gamemode.tpi (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360UDisk.tpi (1524 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\deepscan\ssr.dat (45 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\wdk.ini (3 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\safemon\chrome\360webshield.exe.locale (15 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\LibSDI.dat (601 bytes)
%Program Files% (x86)\360\Total Security\deepscan\dsark64.sys (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\ipc\360netd.dat (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\sweeper\SysSweeper.dll (8234 bytes)
%Program Files% (x86)\360\Total Security\CombineExt.dll (673 bytes)
%Program Files% (x86)\360\Total Security\safemon\360compro.dll (4185 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\deepscan\dsconz.dat (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\appd.dll.locale (13 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\safemon\Safemon.dll.locale (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\yhregd.dll.locale (9 bytes)
%Program Files% (x86)\360\Total Security\safemon\360.dat (13 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\safemon\drvmon.dat (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\DsArk.sys (835 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\safemon\chrome\360webshield.exe.locale (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\art.dat (16 bytes)
C:\Windows\System32\drivers\360AvFlt.sys (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\360ipc.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\deepscan\art.dat (16 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\ipc\regmon.dat (44 bytes)
%Program Files% (x86)\360\Total Security\deepscan\qex\MacroDef.enc (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\360avflt64.sys (2419 bytes)
%Program Files% (x86)\360\Total Security\deepscan\AVE\360ave_ex.def (3361 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\somkernl.dll (27085 bytes)
%Program Files% (x86)\360\Total Security\360NetBase64.dll (2105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\webprotection_firefox\install.rdf (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\safemon\UDiskScanEngine.dll.locale (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\FeedBack.ini (263 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\deepscan\dsurls.dat (844 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\Dumpuper.exe.locale (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\safemon\drvmon.dat (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\360netd.dat (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (114 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\deepscan\DsRes64.dll (1438 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\Sxin64.dll.locale (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\Sxin.dll.locale (14 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\UDiskScanEngine.dll.locale (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360InternationTray\image\toast_speed_medium.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\appmon.dat (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\UrlSettings.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\sc.con (512 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\AVCheck.dll (2130 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\deepscan\ssr.dat (45 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\safemon\360SPTool.exe.locale (32 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\Qshieldz.dat (170 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\safemon.dll.locale (19 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\safemon\SelfProtectAPI2.dll.locale (13 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\filemgr.dll.locale (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\360netd.dat (29 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\libaw.dat (9605 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\360procmon.dll.locale (101 bytes)
%Program Files% (x86)\360\Total Security\ipc\ipcService.dll (3361 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\QHWatchdog.exe (1043 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\LiveUpdate360.exe (6582 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\csp.dat (8 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\safemon\chrome\360webshield.exe.locale (15 bytes)
%Program Files% (x86)\360\Total Security\cacert.pem (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\UrlSettings.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dsconz.dat (12 bytes)
%Program Files% (x86)\360\Total Security\FeedBack.ini (263 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\ipc\yhregd.dll.locale (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\deepscan (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\filemon.dat (18 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\360SafeCamera.tpi.locale (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\WscReg.exe (26008 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\ipc\filemgr.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\scanproxy.dll (5928 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\ipc\appmon.dat (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\wdk.ini (3 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\ipc\filemgr.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\SelfProtectAPI2.dll.locale (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\wd.ini (7 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\safemon\udisk.locale (550 bytes)
%Program Files% (x86)\360\Total Security\safemon\router.ini (274 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\SelfProtectAPI2.dll.locale (12 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\ipc\Sxin64.dll.locale (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\Sites64.dll (20376 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\scanstub.dll (1216 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\wd.ini (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\fr8.dat (2 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\safemon\360SafeCamera.tpi.locale (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\CleanPlus64.exe (10117 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\regmon.dat (46 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\wdk.ini (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\udisk.locale (550 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\deepscan\dsurls.dat (844 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\libdefa.dat (162 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\360SafeCamera.tpi.locale (2 bytes)
%Program Files% (x86)\360\Total Security\ipc\SxWrapper.dll (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\UDiskScanEngine.dll.locale (8 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\ipc\filemon.dat (17 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\ipc\regmon.dat (44 bytes)
%Program Files% (x86)\360\Total Security\sweeper\TrashClean.dll (1425 bytes)
%Program Files% (x86)\360\Total Security\scanproxy.dll (3361 bytes)
%Program Files% (x86)\360\Total Security\softmgr\360Downloads.ini (269 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\safemon\udisk.locale (444 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\deepscan\dsconz.dat (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\deepscan\ssr.dat (45 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\safemon\safemon.dll.locale (19 bytes)
%Program Files% (x86)\360\Total Security\softmgr\stsuglist.dat (601 bytes)
%Program Files% (x86)\360\Total Security\FeedBack.exe (6841 bytes)
C:\Users\Public\Desktop\360 Total Security.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\deepscan\DsRes.dll (637 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\libsdi.dat (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\ipc\appd.dll.locale (12 bytes)
%Program Files% (x86)\360\Total Security\deepscan\wifisafeEncrypt.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\dslw\dslw.dat (768 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\MiniUI.dll (9134 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\deepscan\dsconz.dat (12 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\ipc\360ipc.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\appd.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\libdefa.dat (673 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\drvmon.dat (4 bytes)
%Program Files% (x86)\360\Total Security\deepscan\sc.con (512 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360boxmain.exe (5580 bytes)
%Program Files% (x86)\360\Total Security\netmon\gameidentify.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\sweeper\SysSweeper.dat (727 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360Box.sys (1417 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\ipc\filemgr.dll.locale (11 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\safemon\UDiskScanEngine.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\safemon\WDRecord.dll (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\deepscan\ssr.dat (47 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\qutmipc.sys (185 bytes)
%Program Files% (x86)\360\Total Security\deepscan\Cloudsec3.dll (7385 bytes)
%Program Files% (x86)\360\Total Security\config\defaultskin\MiniUI.xml (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\libdefa.dat (160 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\feedback\FeedBack_theme.ui (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\sndw.dat (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\FsrMgr.dll (4112 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\deepscan\ssr.dat (48 bytes)
%Program Files% (x86)\360\Total Security\EfiProc.dll (57 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\BAPIDRV.sys (1729 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\defaultskin\defaultskin.ui (198 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\safemon\wdk.ini (3 bytes)
%Program Files% (x86)\360\Total Security\QHSafeScanner.exe (4185 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\deepscan\dsurls.dat (844 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\safemon\chrome\360webshield.exe.locale (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\CleanPlus.exe (7161 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\heavygate.dll (7402 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\ipc\360netr.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\ipc\appmon.dat (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\deepscan\dsr.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\drvmon.dat (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\PopSoftEng.dll (5139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\wduicfg.dat (10 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\ipc\360ipc.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\safemon\chrome\360webshield.exe.locale (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\EfiMon.sys (23 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\safemon\360SPTool.exe.locale (30 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\safespeedboot.dat (25 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\I18N64.dll (969 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\libdefa.dat (160 bytes)
%Program Files% (x86)\360\Total Security\deepscan\qex\qex.vdb.enc (4185 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\ipc\Sxin64.dll.locale (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\7z.dll (9721 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\appmon.dat (21 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\ipc\360ipc.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\writeable_test_495427.dat (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\360procmon.dll.locale (98 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\deepscan\ssr.dat (45 bytes)
%Program Files% (x86)\360\Total Security\LiveUpd360.dll (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\SelfProtectAPI2.dll (3279 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\ipc\yhregd.dll.locale (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\chrome\360webshield.exe.locale (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\QHSafeScanner.exe (8221 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\acls.ini (1 bytes)
%Program Files% (x86)\360\Total Security\360P2SP.dll (5873 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\ipc\360netd.dat (29 bytes)
%Program Files% (x86)\360\Total Security\libleak.dat (46325 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360Base.dll (9004 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\wd.ini (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\webprotection_firefox (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360InternationTray\image\toast_speed_veryfast.png (3 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\ipc\yhregd.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\360NetBase.dll (1425 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\Safemon.dll.locale (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360leakfix\360leakfix_theme.ui (1887 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\sysfilerepS.dll (2105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\udisk.locale (482 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\deepscan\DsRes.dll (1146 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\deepscan\dsurls.dat (844 bytes)
%Program Files% (x86)\360\Total Security\deepscan\ImAVEng.dll (673 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\appd.dll.locale (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\UDiskScanEngine.dll.locale (8 bytes)
%Program Files% (x86)\360\Total Security\safemon\iNetSafe.dll (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\360netr.dat (1 bytes)
%Program Files% (x86)\360\Total Security\CleanPlus64.exe (7385 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\360 Security Center\360 Total Security\Uninstall.lnk (1 bytes)
%Program Files% (x86)\360\Total Security\config\lang\zh-CN\SysSweeper.ui.dat (601 bytes)
%Program Files% (x86)\360\Total Security\filemon\AVCheck.dll (673 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\es\SysSweeper.ui.dat (125 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\theme.xml (63 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\deepscan\dsurls.dat (844 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (9 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360AntiHacker.dll (62 bytes)
%Program Files% (x86)\360\Total Security\deepscan\360Quarant.dll (2105 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\deepscan\DsRes.dll (601 bytes)
%Program Files% (x86)\360\Total Security\deepscan\heavygate.dll (3073 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\AntiAdwa.dll.locale (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360SPTool.exe (2476 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\deepscan\dsconz.dat (12 bytes)
%Program Files% (x86)\360\Total Security\safemon\execrule.dat (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\ipc\appd.dll.locale (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\yhregd.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\safemon\UDiskScanEngine.dll (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\Dumpuper.exe.locale (1 bytes)
%Program Files% (x86)\360\Total Security\360Verify.dll (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\deepscan\DsRes.dll (1655 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\UrlSettings.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\deepscan\ssr.dat (48 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (113 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360procmon.dll (3549 bytes)
%Program Files% (x86)\360\Total Security\safemon\7z.dll (7433 bytes)
%Program Files% (x86)\360\Total Security\safemon\WDSafeDown.exe (1425 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dsws.dat (287 bytes)
%Program Files% (x86)\360\Total Security\config\newui\themes\default\360InternationTray\image\toast_speed_veryfast.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\regmon.dat (44 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360InternationTray\360InternationTray_theme.ui (186 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\SelfProtectAPI2.dll.locale (13 bytes)
%Program Files% (x86)\360\Total Security\deepscan\dsr.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\deepscan\dsurls.dat (844 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\deepscan\dsurls.dat (844 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\endata\h_3.dat (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\dlproc.dll (5955 bytes)
%Program Files% (x86)\360\Total Security\Safelive.dll (2105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\LibSDI.dat (81 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\ipc\360netd.dat (29 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\ipc\filemgr.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\yhregd.dll.locale (10 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\safemon\360procmon.dll.locale (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\udisk.locale (338 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360sandbox\360sandbox_theme.ui (268 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\safemon\wdk.ini (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\LibSDI.dat (95 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\webprotection_firefox\chrome\content\browser.xul (560 bytes)
%Program Files% (x86)\360\Total Security\i18n\ru\libdefa.dat (673 bytes)
%Program Files% (x86)\360\Total Security\CleanPlus64.dll (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\deepscan\dsurls.dat (844 bytes)
%Program Files% (x86)\360\Total Security\deepscan\360QuarantPlugin.dll (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\Safelive.dll (3935 bytes)
%Program Files% (x86)\360\Total Security\filemon\DataDriv.dat (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\appd.dll (7615 bytes)
%Program Files% (x86)\360\Total Security\filemon\fr5.dat (9 bytes)
%Program Files% (x86)\360\Total Security\ipc\X64For32Lib.dll (110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\hi\SysSweeper.ui.dat (1170 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\deepscan\dsconz.dat (12 bytes)
%Program Files% (x86)\360\Total Security\360DeskAna64.exe (2105 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\deepscan\dsurls.dat (844 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\filemgr.dll.locale (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\360netr.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr (4 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\360 Security Center\360 Total Security\360 Total Security.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\360netr.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\deepscan\dsurls.dat (844 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\en\Dumpuper.exe.locale (1 bytes)
%Program Files% (x86)\360\Total Security\deepscan\Qshieldz.dat (673 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\ipc\appmon.dat (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\cleancfg.dat (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360hipsPopWnd.dll (10184 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\360netr.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\Sxin.dll.locale (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\safemon.dll (11070 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wifisafeEncrypt.js (5 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\libvi.dat (601 bytes)
%Program Files% (x86)\360\Total Security\config\lang\vi\SysSweeper.ui.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\wdk.ini (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\chrome\360webshield.exe.locale (15 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\Sxin64.dll.locale (14 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\safemon\wd.ini (8 bytes)
%Program Files% (x86)\360\Total Security\ipc\appd.dll (5441 bytes)
%Program Files% (x86)\360\Total Security\safemon\acls.ini (1 bytes)
%Program Files% (x86)\360\Total Security\deepscan\BAPIDRV64.sys (857 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360SkinView.exe (3349 bytes)
%Program Files% (x86)\360\Total Security\filemon\WhiteCache.dll (9098 bytes)
%Program Files% (x86)\360\Total Security\ipc\360Camera.sys (34 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\deepscan\art.dat (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\QVM\360QVM.dll (6596 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\deepscan\ssr.dat (48 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\Safemon.dll.locale (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\360procmon.dll.locale (97 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\yhregd.dll.locale (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\endata\lm_1001.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\QHActiveDefense.exe (6898 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\360procmon.dll.locale (601 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\deepscan\dsurls.dat (844 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\AVE\360ave_ex.def (577 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc (4 bytes)
%Program Files% (x86)\360\Total Security\leakrepair.dll (5441 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\360SafeCamera.tpi.locale (1 bytes)
%Program Files% (x86)\360\Total Security\config\lang\TR\SysSweeper.ui.dat (601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\FileMgr.dll (4470 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\mui\en\Strings.dat (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\appmon.dat (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (113 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360safemonpro.tpi (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\vi\AntiAdwa.dll.locale (601 bytes)
C:\Windows\System32\drivers\360Camera64.sys (40 bytes)
%Program Files% (x86)\360\Total Security\safemon\safemon.dll (8657 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\libaw.dat (9605 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\BAPIDRV64.sys (2116 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\Sxin.dll.locale (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\Safemon.dll.locale (20 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\Dumpuper.exe (5146 bytes)
%Program Files% (x86)\360\Total Security\safemon\360UDisk.tpi (2321 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\CleanPlus64.dll (2209 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\wdk.ini (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\drvmon.dat (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\pt\safemon\360SafeCamera.tpi.locale (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\appmon.dat (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\libvi.dat (130 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\NetDefender.dll.locale (15 bytes)
%Program Files% (x86)\360\Total Security\filemon\ptype.dat (2 bytes)
%Program Files% (x86)\360\Total Security\ipc\sbmon.dll (2469 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\NetDefender.dll (1921 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wificonfig\ra1001.dat (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wpz.dat (835 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\default_theme.ui (431 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\deepscan\dsr.dat (82 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\libdefa.dat (1281 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW (4 bytes)
%Program Files% (x86)\360\Total Security\i18n\es\ipc\appmon.dat (19 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\wdk.ini (3 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\360procmon.dll.locale (101 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\libaw.dat (9605 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\deepscan\ssr.dat (32 bytes)
%Program Files% (x86)\360\Total Security\deepscan\WiFiSafe.dll (10177 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\ipc\filemon.dat (17 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\netmon\360GameIdentify.dll (2954 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\safemon.dll.locale (20 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\SelfProtectAPI2.dll.locale (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\qex\qex.vdb.enc (592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\appmon.dat (19 bytes)
%Program Files% (x86)\360\Total Security\deepscan\qutmload.dll (691 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360AV\360AV_theme.ui (190 bytes)
%Program Files% (x86)\360\Total Security\i18n\tr\ipc\360netr.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\ipc\360ipc.dat (1 bytes)
%Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\udisk.locale (338 bytes)
%Program Files% (x86)\360\Total Security\i18n\hi\deepscan\dsurls.dat (844 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\fr1.dat (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360AV.tpi (321 bytes)

Registry activity

The process QHSafeTray.exe:1172 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\360SAFE\KeepAlive\360PayInsure]
"ImagePath" = "%Program Files% (x86)\360\Total Security\safemon\SomProxy.dll"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"NetMonAccess" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"KPRSNS" = "0"

[HKLM\SOFTWARE\Wow6432Node\360TotalSecurity\Leak]
"BootTime" = "Type: REG_QWORD, Length: 8"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"NetPayProtect" = "1"
"FileMonAccess" = "1"
"AL_Keylogger" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\FILEMON]
"AVMonitor" = "2"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"RTRAYING" = "1"
"DrvFWAccess2" = "1"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\FILEMON]
"level" = "2"
"AVHandle" = "1"
"AVWriteProtectEnable" = "1"
"AVEngine" = "0"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"SiteAccess" = "1"
"AppMonAccess" = "1"

[HKCU\Software\360\360Speedld]
"last_optimized" = "4294967295"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon\safecamera]
"upref" = "1"

[HKLM\SOFTWARE\Wow6432Node\360TotalSecurity\Experience]
"Session1" = "0"

[HKCU\Software\360\360Speedld]
"not_optimized" = "4294967295"
"last_not_optimized" = "4294967295"

[HKLM\SOFTWARE\Wow6432Node\360TOTALSECURITY\ACTIVEPROTECTION]
"Flags" = "805388039"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"ProcIM" = "1"

[HKCU\Software\360\360Speedld]
"Optimized" = "4294967295"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"MonAccess" = "1"
"WDSBSupport" = "1"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\FILEMON]
"AVReadProtectEnable" = "0"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"ProcDownload" = "1"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\FILEMON]
"AVEnable" = "1"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\360TotalSecurity\Experience]
"Session1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\System\CurrentControlSet\services\BAPIDRV]
"WOW64"
"DeleteFlag"

The process PatchUp.exe:3300 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\PatchUp_RASAPI32]
"MaxFileSize" = "1048576"
"ConsoleTracingMask" = "4294901760"

[HKLM\SOFTWARE\Wow6432Node\360TotalSecurity\Leak]
"LastPopTime" = "2015-04-23"

[HKLM\SOFTWARE\Wow6432Node\LiveUpdate360]
"IsLowPC" = "0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\PatchUp_RASAPI32]
"FileTracingMask" = "4294901760"
"EnableFileTracing" = "0"
"EnableConsoleTracing" = "0"

[HKLM\SOFTWARE\Wow6432Node\360TotalSecurity\Leak]
"CT" = "7"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\PatchUp_RASAPI32]
"FileDirectory" = "%windir%\tracing"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\BAPIDRV]
"WOW64"
"DeleteFlag"

The process QHWatchdog.exe:2492 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\360SAFE]
"keepalive" = "0"

The process nsd45AA.tmp.exe:1172 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer]
"GlobalAssocChangedCounter" = "37"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process DXSETUP.exe:1376 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\DirectX]
"DXSetup" = "0"
"Command" = "0"

The process regsvr32.exe:1580 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\Interface\{B09C75BE-F1AE-47BA-BC47-19F5C0A15B33}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Directory\shellex\ContextMenuHandlers\SD360]
"(Default)" = "{086F171D-5ED1-4ED2-B736-CFF3AD6A128E}"

[HKCR\CLSID\{086F171D-5ED1-4ED2-B736-CFF3AD6A128E}]
"(Default)" = "SD360MN Class"

[HKCR\CLSID\{086F171D-5ED1-4ED2-B736-CFF3AD6A128E}\InprocServer32]
"(Default)" = "%Program Files% (x86)\360\Total Security\MenuEx64.dll"

[HKCR\Wow6432Node\Interface\{B09C75BE-F1AE-47BA-BC47-19F5C0A15B33}\TypeLib]
"(Default)" = "{FF9EAEBA-7783-4904-99E3-F3E322C0F648}"

[HKCR\CLSID\{086F171D-5ED1-4ED2-B736-CFF3AD6A128E}\VersionIndependentProgID]
"(Default)" = "MenuEx.SD360MN"

[HKCR\Folder\ShellEx\ContextMenuHandlers\SD360]
"(Default)" = "{086F171D-5ED1-4ED2-B736-CFF3AD6A128E}"

[HKCR\Wow6432Node\Interface\{B09C75BE-F1AE-47BA-BC47-19F5C0A15B33}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\MenuEx.SD360MN]
"(Default)" = "SD360MN Class"

[HKCR\MenuEx.SD360MN.1]
"(Default)" = "SD360MN Class"

[HKCR\TypeLib\{FF9EAEBA-7783-4904-99E3-F3E322C0F648}\1.0]
"(Default)" = "MenuEx 1.0 Type Library"

[HKCR\CLSID\{086F171D-5ED1-4ED2-B736-CFF3AD6A128E}\TypeLib]
"(Default)" = "{FF9EAEBA-7783-4904-99E3-F3E322C0F648}"

[HKCR\TypeLib\{FF9EAEBA-7783-4904-99E3-F3E322C0F648}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\Wow6432Node\Interface\{B09C75BE-F1AE-47BA-BC47-19F5C0A15B33}]
"(Default)" = "ISD360MN"

[HKCR\Interface\{B09C75BE-F1AE-47BA-BC47-19F5C0A15B33}\TypeLib]
"(Default)" = "{FF9EAEBA-7783-4904-99E3-F3E322C0F648}"

[HKCR\Interface\{B09C75BE-F1AE-47BA-BC47-19F5C0A15B33}]
"(Default)" = "ISD360MN"

[HKCR\MenuEx.SD360MN.1\CLSID]
"(Default)" = "{086F171D-5ED1-4ED2-B736-CFF3AD6A128E}"

[HKCR\MenuEx.SD360MN\CLSID]
"(Default)" = "{086F171D-5ED1-4ED2-B736-CFF3AD6A128E}"

[HKCR\*\shellex\ContextMenuHandlers\SD360]
"(Default)" = "{086F171D-5ED1-4ED2-B736-CFF3AD6A128E}"

[HKCR\CLSID\{086F171D-5ED1-4ED2-B736-CFF3AD6A128E}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{B09C75BE-F1AE-47BA-BC47-19F5C0A15B33}\TypeLib]
"Version" = "1.0"

[HKCR\TypeLib\{FF9EAEBA-7783-4904-99E3-F3E322C0F648}\1.0\HELPDIR]
"(Default)" = "%Program Files% (x86)\360\Total Security"

[HKCR\CLSID\{086F171D-5ED1-4ED2-B736-CFF3AD6A128E}\ProgID]
"(Default)" = "MenuEx.SD360MN.1"

[HKCR\TypeLib\{FF9EAEBA-7783-4904-99E3-F3E322C0F648}\1.0\0\win64]
"(Default)" = "%Program Files% (x86)\360\Total Security\MenuEx64.dll"

[HKCR\Wow6432Node\Interface\{B09C75BE-F1AE-47BA-BC47-19F5C0A15B33}\TypeLib]
"Version" = "1.0"

[HKCR\MenuEx.SD360MN\CurVer]
"(Default)" = "MenuEx.SD360MN.1"

[HKCR\lnkfile\shellex\ContextMenuHandlers\SD360]
"(Default)" = "{086F171D-5ED1-4ED2-B736-CFF3AD6A128E}"

The process %original file name%.exe:2428 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "2D 85 33 3A 90 73 D0 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{9BA14452-3A93-4712-8A0D-BF6CFCC6695B}]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{9BA14452-3A93-4712-8A0D-BF6CFCC6695B}]
"WpadNetworkName" = "Network 4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 48 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{9BA14452-3A93-4712-8A0D-BF6CFCC6695B}]
"WpadDecisionReason" = "1"

"WpadDecisionTime" = "84 6E E0 4A 78 7D D0 01"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoDetect"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{9BA14452-3A93-4712-8A0D-BF6CFCC6695B}]
"WpadDetectedUrl"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

The process QHActiveDefense.exe:1168 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\System\CurrentControlSet\services\360FsFlt]
"WorkConfig" = "29"
"Group" = "FSFilter Activity Monitor"
"ErrorControl" = "0"

[HKLM\System\CurrentControlSet\services\360FsFlt\Instances\360TopInstance]
"Altitude" = "382300"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"restag" = "1"

[HKLM\System\CurrentControlSet\services\360FsFlt]
"ImagePath" = "system32\DRIVERS\360FsFlt.sys"

[HKLM\System\CurrentControlSet\services\360FsFlt\Instances\360TopInstance]
"Flags" = "0"

[HKLM\System\CurrentControlSet\services\360FsFlt]
"Start" = "1"

[HKLM\System\CurrentControlSet\services\360FsFlt\Instances]
"DefaultInstance" = "360TopInstance"

[HKLM\System\CurrentControlSet\services\360FsFlt]
"DependOnService" = "FltMgr"
"DisplayName" = "360FsFlt mini-filter driver"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360Safe.exe]
"Path" = "%Program Files% (x86)\360\Total Security"

[HKLM\System\CurrentControlSet\services\360FsFlt]
"Type" = "2"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\360FsFlt]
"WOW64"
"DeleteFlag"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"NeedReboot"

The process QHActiveDefense.exe:804 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"DrvFWAccess2" = "1"

[HKLM\System\CurrentControlSet\services\360FsFlt]
"ErrorControl" = "0"

[HKLM\System\CurrentControlSet\services\360Camera]
"ErrorControl" = "1"

[HKLM\System\CurrentControlSet\services\360FsFlt\Instances]
"DefaultInstance" = "360TopInstance"

[HKU\FILECACHE\D89B41B5ECC0C91152383CD8621D0B6A]
"SymbolicLinkValue" = "Type: REG_LINK, Length: 182"

[HKLM\System\CurrentControlSet\services\360Camera]
"ImagePath" = "System32\Drivers\360Camera64.sys"

[HKLM\System\CurrentControlSet\services\360FsFlt]
"ImagePath" = "system32\DRIVERS\360FsFlt.sys"

[HKU\FILECACHE\B239248D1B7FFEF30A0C80CA49DC7D55]
"SymbolicLinkValue" = "Type: REG_LINK, Length: 182"

[HKLM\System\CurrentControlSet\services\360AntiHacker]
"ImagePath" = "System32\Drivers\360AntiHacker64.sys"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\ipc]
"rrm" = "1"

[HKLM\System\CurrentControlSet\services\360FsFlt]
"DisplayName" = "360FsFlt mini-filter driver"

[HKLM\System\CurrentControlSet\services\360FsFlt\Instances\360TopInstance]
"Flags" = "0"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"NetMonAccess" = "1"

[HKLM\System\CurrentControlSet\services\360FsFlt\Instances\360TopInstance]
"Altitude" = "382300"

[HKLM\System\CurrentControlSet\services\360Box64]
"Start" = "1"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\FILEMON]
"level" = "2"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon\safecamera]
"Enable" = "1"
"Status" = "2147876882"

[HKLM\System\CurrentControlSet\services\360FsFlt]
"Group" = "FSFilter Activity Monitor"

[HKU\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\System\CurrentControlSet\services\360AntiHacker]
"Start" = "1"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"FileMonAccess" = "1"
"AVEnable" = "1"
"SB_FreePercent" = "25"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKLM\System\CurrentControlSet\services\360AntiHacker]
"DisplayName" = "360Safe Anti Hacker Service"

[HKLM\System\CurrentControlSet\services\360Camera]
"Tag" = "0"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"restag" = "1"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\ipc]
"frm" = "1"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon\safecamera]
"Enable" = "0"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\ipc]
"lnk" = "1"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"MonAccess" = "1"
"DefaultBrowserPro" = "0"

[HKLM\System\CurrentControlSet\services\360AntiHacker]
"ErrorControl" = "0"

[HKLM\System\CurrentControlSet\services\360FsFlt]
"Start" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\QHActiveDefense_RASAPI32]
"MaxFileSize" = "1048576"

[HKLM\System\CurrentControlSet\services\360AntiHacker]
"Tag" = "0"
"Type" = "1"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"NetDefender" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\QHActiveDefense_RASAPI32]
"FileTracingMask" = "4294901760"

[HKLM\System\CurrentControlSet\services\360FsFlt]
"DependOnService" = "FltMgr"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"AppMonAccess" = "1"

[HKLM\SOFTWARE\Wow6432Node\360SAFE]
"keepalive" = "0"

[HKLM\System\CurrentControlSet\services\360Camera]
"DisplayName" = "360Safe Camera Filter Service"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\FILEMON]
"AVEnable" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\QHActiveDefense_RASAPI32]
"EnableFileTracing" = "0"
"EnableConsoleTracing" = "0"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"DrvFWAccess2" = "1"
"DesktopIcon" = "0"
"NewExec" = "1"
"ExecAccess" = "0"

[HKU\.DEFAULT\SOFTWARE\Microsoft\ActiveMovie\devenum]
"Version" = "7"

[HKLM\System\CurrentControlSet\services\360Camera]
"Start" = "3"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\ipc]
"rrm" = "1"

[HKLM\System\CurrentControlSet\services\360Camera]
"Type" = "1"

[HKLM\System\CurrentControlSet\services\360FsFlt]
"Type" = "2"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\QHActiveDefense_RASAPI32]
"ConsoleTracingMask" = "4294901760"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"SB_InternalState" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\QHActiveDefense_RASAPI32]
"FileDirectory" = "%windir%\tracing"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QHSafeTray" = "%Program Files% (x86)\360\Total Security\safemon\QHSafeTray.exe /start"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\BAPIDRV]
"WOW64"

[HKLM\System\CurrentControlSet\services\360FsFlt]
"DeleteFlag"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\System\CurrentControlSet\services\360Camera]
"DeleteFlag"

[HKLM\System\CurrentControlSet\services\360FsFlt]
"WOW64"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\360krnlsvc]
"CFlags"

[HKLM\System\CurrentControlSet\services\BAPIDRV]
"DeleteFlag"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\System\CurrentControlSet\services\360FsFlt\Enum]
"INITSTARTFAILED"

[HKLM\System\CurrentControlSet\services\360Camera]
"WOW64"

[HKLM\System\CurrentControlSet\services\360AntiHacker]
"WOW64"

"DeleteFlag"

The Trojan disables automatic startup of the application by deleting the following autorun value:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QQPCHint"

The process nss6FC6.tmp.exe:1904 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Wow6432Node\360TotalSecurity\UserProfile]
"MenuScan" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\System\CurrentControlSet\services\360Box64]
"WorkConfig" = "29"

[HKLM\SOFTWARE\Wow6432Node\360Safe\Liveup]
"mid" = "09bcd29b60133ba15b849679a9d82fa3d58b9ea7f26f9fe70d4e0799db5b2e7b"

[HKLM\System\CurrentControlSet\services\360Box64]
"Type" = "2"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"SB_State" = "1"

[HKLM\SOFTWARE\Wow6432Node\360TotalSecurity\UserProfile]
"MaskFlags" = "1"

[HKLM\SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions]
"[email protected]" = "%Program Files% (x86)\360\Total Security\safemon\webprotection_firefox"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer]
"GlobalAssocChangedCounter" = "38"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDetectedUrl" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\QHSafeMain.exe]
"(Default)" = "%Program Files% (x86)\360\Total Security\QHSafeMain.exe"

[HKLM\SOFTWARE\Wow6432Node\360TotalSecurity\UserProfile]
"InstallDate" = "1429760936"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History]
"CachePrefix" = "Visited:"

[HKLM\System\CurrentControlSet\services\360AvFlt]
"Group" = "FSFilter Activity Monitor"

[HKLM\System\CurrentControlSet\services\BAPIDRV]
"ErrorControl" = "0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\360TotalSecurity]
"UninstallString" = "%Program Files% (x86)\360\Total Security\Uninstall.exe"

"EstimatedSize" = "102400"

[HKLM\System\CurrentControlSet\services\360Box64]
"Start" = "3"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"SB_Entry_Known" = "0"

[HKLM\System\CurrentControlSet\services\360Box64]
"ErrorControl" = "0"

[HKLM\SOFTWARE\Wow6432Node\360SAFE\safemon]
"SB_RightMenu" = "1"

[HKLM\SOFTWARE\Wow6432Node\Google\Chrome\NativeMessagingHosts\com.google.chrome.wdwedpro]
"(Default)" = "%Program Files% (x86)\360\Total Security\safemon\chrome\manifest.json"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\360TotalSecurity]
"DisplayName" = "360 Total Security"

[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\Users\"%CurrentUserName%"\AppData\Roaming\Mozilla\Firefox\Profiles\zwvbr04l.default\extensions\[email protected],"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\360TotalSecurity]
"DisplayIcon" = "%Program Files% (x86)\360\Total Security\QHSafeMain.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content]
"CachePrefix" = ""

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\360TotalSecurity]
"InstallLocation" = "%Program Files% (x86)\360\Total Security"

[HKLM\System\CurrentControlSet\services\360Box64\Instances\360TopInstance64]
"Altitude" = "382310"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\QHSafeTray.exe]
"Path" = "%Program Files% (x86)\360\Total Security"

[HKLM\System\CurrentControlSet\services\360AvFlt\Instances\360SDInstance]
"Altitude" = "327400"

[HKLM\System\CurrentControlSet\services\360Box64]
"DependOnService" = "FltMgr"

[HKLM\System\CurrentControlSet\services\BAPIDRV]
"ImagePath" = "system32\DRIVERS\BAPIDRV64.sys"

[HKLM\SOFTWARE\Wow6432Node\360TotalSecurity\srvtpi\360SafeCamera]
"STARTTYPE" = "2"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\360TotalSecurity]
"Edition" = "Professional"

[HKLM\SOFTWARE\Wow6432Node\360TotalSecurity\srvtpi\360SafeCamera]
"ImagePath" = "safemon\360SafeCamera.tpi"

[HKLM\System\CurrentControlSet\services\360AvFlt]
"Start" = "1"
"ImagePath" = "system32\DRIVERS\360AvFlt.sys"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionTime" = "84 6E E0 4A 78 7D D0 01"

[HKLM\System\CurrentControlSet\services\BAPIDRV]
"Type" = "1"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\360TotalSecurity]
"Publisher" = "360 Security Center"

[HKLM\System\CurrentControlSet\services\BAPIDRV]
"Start" = "1"

[HKLM\System\CurrentControlSet\services\360AvFlt\Instances\360SDInstance]
"Flags" = "0"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\360TotalSecurity]
"DisplayVersion" = "6.2.0.1027"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 49 00 00 00 09 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\QHSafeTray.exe]
"(Default)" = "%Program Files% (x86)\360\Total Security\safemon\QHSafeTray.exe"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360Safe.exe]
"Path" = "%Program Files% (x86)\360\Total Security"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies]
"CachePrefix" = "Cookie:"

[HKLM\System\CurrentControlSet\services\360AvFlt]
"DependOnService" = "FltMgr"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\QHSafeMain.exe]
"Path" = "%Program Files% (x86)\360\Total Security"

[HKLM\System\CurrentControlSet\services\360AvFlt]
"WorkConfig" = "29"

[HKLM\System\CurrentControlSet\services\360Box64]
"ImagePath" = "system32\DRIVERS\360Box64.sys"

[HKLM\System\CurrentControlSet\services\360AvFlt\Instances]
"DefaultInstance" = "360SDInstance"

[HKLM\SOFTWARE\Wow6432Node\360Safe\360krnlsvc\softmgrs]
"ImagePath" = "%Program Files% (x86)\360\Total Security\SoftMgr\360SoftMgrS.dll"

[HKLM\System\CurrentControlSet\services\360Box64\Instances]
"DefaultInstance" = "360TopInstance64"

[HKLM\SOFTWARE\Wow6432Node\360TotalSecurity\Firefox]
"nptswp_countdown" = "2"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360Safe.exe]
"(Default)" = "%Program Files% (x86)\360\Total Security\QHSafeMain.exe"

[HKLM\System\CurrentControlSet\services\360Box64]
"DisplayName" = "360Box mini-filter driver"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecisionReason" = "1"

[HKLM\System\CurrentControlSet\services\BAPIDRV]
"DisplayName" = "BAPIDRV"

[HKLM\SOFTWARE\Wow6432Node\360TotalSecurity\Firefox]
"nptswp_status" = "1"

[HKLM\SOFTWARE\Wow6432Node\360TOTALSECURITY\ACTIVEPROTECTION]
"Mode" = "2"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f5-e5-a3]
"WpadDecision" = "0"

[HKLM\System\CurrentControlSet\services\360Box64]
"Group" = "FSFilter Activity Monitor"

[HKLM\System\CurrentControlSet\services\BAPIDRV\Enum]
"Status" = "1"

[HKLM\System\CurrentControlSet\services\360Box64\Instances\360TopInstance64]
"Flags" = "0"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QHSafeTray" = "%Program Files% (x86)\360\Total Security\safemon\QHSafeTray.exe /start"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\services\360AvFlt]
"DeleteFlag"
"WOW64"

[HKLM\System\CurrentControlSet\services\BAPIDRV]
"WOW64"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\System\CurrentControlSet\services\360Box64]
"DeleteFlag"

[HKLM\System\CurrentControlSet\services\BAPIDRV]
"DeleteFlag"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKLM\System\CurrentControlSet\services\360Box64]
"WOW64"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoDetect"

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The Trojan disables automatic startup of the application by deleting the following autorun value:

[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"360safeuninst_1f0fb7c2d13cc0c07ff2ca40747bc03e"

Dropped PE files

MD5 File path
8c42fc725106cf8276e625b4f97861bc c:\Program Files (x86)\360\Total Security\360Base.dll
dee726f4d7f448bda80d5fc7ab7fb7fe c:\Program Files (x86)\360\Total Security\360Base64.dll
fc9479cf652caa626145d8345f3a28c9 c:\Program Files (x86)\360\Total Security\360Common.dll
b40b855a43034bef97f8ed97d6df57e1 c:\Program Files (x86)\360\Total Security\360Conf.dll
92dbc106aba53b59d1c121f06cca9d75 c:\Program Files (x86)\360\Total Security\360DeskAna.exe
b5049a133b4b6b67abd5e41d2f36a087 c:\Program Files (x86)\360\Total Security\360DeskAna64.exe
d778bbd5284a033738ab7eee3b5e3973 c:\Program Files (x86)\360\Total Security\360NetBase.dll
7fc6afafd1aa883e1dc41f5119b06474 c:\Program Files (x86)\360\Total Security\360NetBase64.dll
ce2ec7601d88cd377671a9f0f52f6942 c:\Program Files (x86)\360\Total Security\360P2SP.dll
7bbe0536929e98c8ceb61e4fe11507a9 c:\Program Files (x86)\360\Total Security\360ShellPro.exe
706205d2b76d73e43f145869fcbc074c c:\Program Files (x86)\360\Total Security\360SkinView.exe
4918c4906b339e89577a49aa59d2d696 c:\Program Files (x86)\360\Total Security\360TsLiveUpd.exe
0f482dcaa174e7f921aa74cf42c27018 c:\Program Files (x86)\360\Total Security\360Util.dll
6a805c15a92dc7f7e3effe2696f10935 c:\Program Files (x86)\360\Total Security\360Verify.dll
e44af3441536db72b7deec0200a36f7a c:\Program Files (x86)\360\Total Security\360net.dll
f2b8f1a361b07ae1d951b43de861b8d3 c:\Program Files (x86)\360\Total Security\3G\3GIdentify.dll
495dba6f0b7dcbb59d97a0c0b1617c7c c:\Program Files (x86)\360\Total Security\AntiAdwa.dll
75c163916b4b75a0b2081922521cc04e c:\Program Files (x86)\360\Total Security\CleanPlus.dll
efb463c26727c345b2da03f027447238 c:\Program Files (x86)\360\Total Security\CleanPlus.exe
dd3089733f5336d9f927dedab9bbda58 c:\Program Files (x86)\360\Total Security\CleanPlus64.dll
6702fabd51309de6cdc85477b1b5e397 c:\Program Files (x86)\360\Total Security\CleanPlus64.exe
80e2f9967f757a6a7c5e0cb2d0196160 c:\Program Files (x86)\360\Total Security\CombineExt.dll
fa3669a751d68771a0b358d279ddfa4c c:\Program Files (x86)\360\Total Security\CrashReport.dll
526759ab21a01d4758260bd53dc71642 c:\Program Files (x86)\360\Total Security\Dumpuper.exe
1ee5f9f327d19074da82b58d8252a749 c:\Program Files (x86)\360\Total Security\EfiMon.sys
b35949c5a90f1503ca2ee31fa0c4914b c:\Program Files (x86)\360\Total Security\EfiProc.dll
9df514ab0fd23dd98a64b5405eb679ed c:\Program Files (x86)\360\Total Security\FeedBack.exe
dee14c4058eb2af2ebfccb4a8a0dd4b0 c:\Program Files (x86)\360\Total Security\I18N.dll
52ed80a97ab6fb42fe93beebb46b5f23 c:\Program Files (x86)\360\Total Security\I18N64.dll
2c60c2da4575fc666ef3d28072cad20f c:\Program Files (x86)\360\Total Security\LiveUpd360.dll
3bb79961050d2acc8e832f768ab99a29 c:\Program Files (x86)\360\Total Security\LiveUpdate360.exe
2a245a2c67a08865e74893c706c47b68 c:\Program Files (x86)\360\Total Security\MenuEx.dll
e8adea08edabef8c08c2eadd9d252ae0 c:\Program Files (x86)\360\Total Security\MenuEx64.dll
db2b7a54df401e07d76e6481755fd79b c:\Program Files (x86)\360\Total Security\MiniUI.dll
f83126cfb0d4d04c4b7421968315da15 c:\Program Files (x86)\360\Total Security\PDown.dll
c515155ddf5425120acc9692333851d9 c:\Program Files (x86)\360\Total Security\PatchUp.exe
004f4f331bb578ff75ec89f8f7f4a86c c:\Program Files (x86)\360\Total Security\QHSafeMain.exe
b8956b7d7adc04c50fd0a0367b514a6f c:\Program Files (x86)\360\Total Security\QHSafeScanner.exe
3095f8d426c44d85588d49b5c9436856 c:\Program Files (x86)\360\Total Security\QHVer.dll
6cc06e2b14585b6966c9d24a90b32c7b c:\Program Files (x86)\360\Total Security\Safelive.dll
8c7ff39fbe594a9e81969e969dd37075 c:\Program Files (x86)\360\Total Security\Sites64.dll
d5eafe209a61b37358114a1aec859d39 c:\Program Files (x86)\360\Total Security\Uninstall.exe
34944c8d8ac72fd205fcc0821de50ba0 c:\Program Files (x86)\360\Total Security\Utils\ModuleUpdate.exe
6d7bfd4c4ec63f417499152a4f7f810b c:\Program Files (x86)\360\Total Security\deepscan\360FsFlt.sys
d45ceae2f76627f054480190fbc0e54e c:\Program Files (x86)\360\Total Security\deepscan\360Quarant.dll
712a07ce43de6ca50dc7a857338aecf9 c:\Program Files (x86)\360\Total Security\deepscan\360QuarantPlugin.dll
c03f3809246fbb9e04835c37b9770541 c:\Program Files (x86)\360\Total Security\deepscan\360netcfg.exe
b187a6ab7406679d3fdf40bfe12009a3 c:\Program Files (x86)\360\Total Security\deepscan\AVE\AVEI.dll
5d307fec2918cad0c4b5e5c7b83ed593 c:\Program Files (x86)\360\Total Security\deepscan\AVE\AVEngine.dll
3f9d1f28f72c6abfddad9cf2f6dcf471 c:\Program Files (x86)\360\Total Security\deepscan\BAPI.dll
626f61cd7a1599df4c10b880cbbe0a22 c:\Program Files (x86)\360\Total Security\deepscan\BAPIDRV.sys
f29557e06773b97d36341b4adc7ef472 c:\Program Files (x86)\360\Total Security\deepscan\BAPIDRV64.sys
a7bf09c3f37923c087bbbdc70b5be2db c:\Program Files (x86)\360\Total Security\deepscan\CQhCltHttpW.dll
4edc33d7f63fff234a72eab0692fae52 c:\Program Files (x86)\360\Total Security\deepscan\CheckSM.dll
f9e571c26638e134e279027990b5ad68 c:\Program Files (x86)\360\Total Security\deepscan\CheckSM.exe
a66c668e2aa5ac1b8920a192ef500ee0 c:\Program Files (x86)\360\Total Security\deepscan\Cloudsec3.dll
bfe0d80f83f9a55610dd55a69e59b3d6 c:\Program Files (x86)\360\Total Security\deepscan\DSFScan.dll
e90628c1b6f117f328ad120c163804f7 c:\Program Files (x86)\360\Total Security\deepscan\DsArk.dll
f443435fb5676287b5ab97287c3e8868 c:\Program Files (x86)\360\Total Security\deepscan\DsArk.sys
919a152cd6d2751c4c541636435d5399 c:\Program Files (x86)\360\Total Security\deepscan\DsSysRepair.dll
b8fdc03b9b84a62c5c541524dca2e723 c:\Program Files (x86)\360\Total Security\deepscan\ImAVEng.dll
f3216ea8aaa374be7ad86eee9a74175c c:\Program Files (x86)\360\Total Security\deepscan\PopSoftEng.dll
c96f74f8d9f7d843072b06d55fd2b2e6 c:\Program Files (x86)\360\Total Security\deepscan\QVM\360QVM.dll
5d0b987e912636f0f0ef025dbc362d59 c:\Program Files (x86)\360\Total Security\deepscan\WiFiSafe.dll
8a726f4f4640c2a2361b5e41d124f0fc c:\Program Files (x86)\360\Total Security\deepscan\WifiAgent.dll
fe958c80818e948d25f3c2edb27295eb c:\Program Files (x86)\360\Total Security\deepscan\cloudcom2.dll
a8428cfa32fd4a80fc74068d26baf8da c:\Program Files (x86)\360\Total Security\deepscan\cloudsec2.dll
2111c4cb0e2a4995365f14085a676a6a c:\Program Files (x86)\360\Total Security\deepscan\deepscan.dll
e833a7b5bae2fc13bad8a99a879c390d c:\Program Files (x86)\360\Total Security\deepscan\dsark64.sys
d40092b743cbad6a276589485d1c380d c:\Program Files (x86)\360\Total Security\deepscan\heavygate.dll
534c2f064f540abc9f96e7d4dc18bb2a c:\Program Files (x86)\360\Total Security\deepscan\qex\qex.dll
bf10e282e7e8034298c435574e947358 c:\Program Files (x86)\360\Total Security\deepscan\qutmdrv.sys
bd47f98bdb35ec643b427ce8eca86e9b c:\Program Files (x86)\360\Total Security\deepscan\qutmload.dll
ecc561c9a29f16a2c684ecbbe051215b c:\Program Files (x86)\360\Total Security\deepscan\sysfilerepS.dll
da433a919154394953b5c925d6c7946b c:\Program Files (x86)\360\Total Security\dynlbase.dll
61bda655c88ce843905ce63a2d5669e4 c:\Program Files (x86)\360\Total Security\dynlenv.dll
33c9ce88131a3adcb663fdef455e01eb c:\Program Files (x86)\360\Total Security\filemon\360AvFlt.dll
d8dee0f3bd03f49ccc30b761e42ee96f c:\Program Files (x86)\360\Total Security\filemon\360AvFlt.sys
0aaba03736666b85ac37c01467e89578 c:\Program Files (x86)\360\Total Security\filemon\360avflt64.sys
23b1615a62e9c42952e8693b7ce5e242 c:\Program Files (x86)\360\Total Security\filemon\360rp.dll
f1128cb2b327e584f43dfd0a7a010c86 c:\Program Files (x86)\360\Total Security\filemon\AVCheck.dll
9e3383566f4b5ce5540ad9b94c37d14d c:\Program Files (x86)\360\Total Security\filemon\FsrMgr.dll
74e3eec26c2db6c18210bd181935953f c:\Program Files (x86)\360\Total Security\filemon\WhiteCache.dll
4797aa6c47ab3f6acf80eb5b5aabd981 c:\Program Files (x86)\360\Total Security\i18n\en\AntiAdwa.dll.locale
36080a60f9815ea532bf48c0c9cadde0 c:\Program Files (x86)\360\Total Security\i18n\en\UrlSettings.dll.locale
b2d9c335f06008c6d5e3bd421ccda414 c:\Program Files (x86)\360\Total Security\i18n\en\deepscan\DsRes.dll
8319ee4511fa12f630258c2baff03987 c:\Program Files (x86)\360\Total Security\i18n\en\deepscan\DsRes64.dll
71504cc23a6d0e4edc380fd11aca4d56 c:\Program Files (x86)\360\Total Security\i18n\en\ipc\NetDefender.dll.locale
fd9a494a6c37a13554956338ed06c4bc c:\Program Files (x86)\360\Total Security\i18n\en\ipc\Sxin.dll.locale
7365ba2697fde076aa72a42717035925 c:\Program Files (x86)\360\Total Security\i18n\en\ipc\Sxin64.dll.locale
1bec7d58d7f5b28505ffb8515abf86b2 c:\Program Files (x86)\360\Total Security\i18n\en\ipc\appd.dll.locale
cf2931da32cedf69a9303b877dc13d95 c:\Program Files (x86)\360\Total Security\i18n\en\ipc\filemgr.dll.locale
bf04aa0738d5d7d89b2c8f92074fda45 c:\Program Files (x86)\360\Total Security\i18n\en\ipc\yhregd.dll.locale
9259b466481a1ad9feed18f6564a210b c:\Program Files (x86)\360\Total Security\i18n\en\safemon\360SPTool.exe.locale
6e6c4a76fa3dea52b9960aed5e366eee c:\Program Files (x86)\360\Total Security\i18n\en\safemon\360procmon.dll.locale
178f9c26339c1981197975405a80b173 c:\Program Files (x86)\360\Total Security\i18n\en\safemon\SelfProtectAPI2.dll.locale
d3911a727a01a3b0ad88965ad3db526b c:\Program Files (x86)\360\Total Security\i18n\en\safemon\UDiskScanEngine.dll.locale
c6bf7f392c935bb818fcdd55f089ac53 c:\Program Files (x86)\360\Total Security\i18n\en\safemon\chrome\360webshield.exe.locale
41326c9d767c4539021c723ecf76f5fb c:\Program Files (x86)\360\Total Security\i18n\en\safemon\safemon.dll.locale
5efd82b0e517230c5fcbbb4f02936ed0 c:\Program Files (x86)\360\Total Security\i18n\en\safemon\webprotection_firefox\plugins\nptswp.dll.locale
fc6b9df77d844f84f54d21f3a0cf1c03 c:\Program Files (x86)\360\Total Security\i18n\es\Antiadwa.dll.locale
50d76fe0db91d4883986dc56ad9b7613 c:\Program Files (x86)\360\Total Security\i18n\es\UrlSettings.dll.locale
8e7a4c730f27bdecb7e012d7efebe4ca c:\Program Files (x86)\360\Total Security\i18n\es\deepscan\DsRes.dll
0ce10fa0f10d85fc5dd4332c37485dff c:\Program Files (x86)\360\Total Security\i18n\es\deepscan\DsRes64.dll
146a12ebaf0243fce4b943f55a1772fb c:\Program Files (x86)\360\Total Security\i18n\es\ipc\NetDefender.dll.locale
7efd25c0f05e9917d71dbaff60cc1ef8 c:\Program Files (x86)\360\Total Security\i18n\es\ipc\Sxin.dll.locale
580bdfafe333f368fead0875ad9ab423 c:\Program Files (x86)\360\Total Security\i18n\es\ipc\Sxin64.dll.locale
49e3c8c9b07f6a16c19b9cc261b6a38e c:\Program Files (x86)\360\Total Security\i18n\es\ipc\appd.dll.locale
221846a22c60c2be6e4bada72965540a c:\Program Files (x86)\360\Total Security\i18n\es\ipc\filemgr.dll.locale
f99322d307eee9ab1a00c6f65debeb09 c:\Program Files (x86)\360\Total Security\i18n\es\ipc\yhregd.dll.locale
8de86436c6006f573336bd3fffd22d10 c:\Program Files (x86)\360\Total Security\i18n\es\safemon\360SPTool.exe.locale
bc5c78db880c1bd2a0c3aa731e6b5c67 c:\Program Files (x86)\360\Total Security\i18n\es\safemon\360procmon.dll.locale
69d5154961971c19cb048adffabd3dd5 c:\Program Files (x86)\360\Total Security\i18n\es\safemon\Safemon.dll.locale
8ece4a2c7ce4ed2c67f20d1a4b8619dc c:\Program Files (x86)\360\Total Security\i18n\es\safemon\SelfProtectAPI2.dll.locale
42174707dd42b57ee752740252f9a772 c:\Program Files (x86)\360\Total Security\i18n\es\safemon\UDiskScanEngine.dll.locale
6710827a43c51a34488c92e5b24af9ba c:\Program Files (x86)\360\Total Security\i18n\es\safemon\chrome\360webshield.exe.locale
86480218b103a3471e0322adbf15f50d c:\Program Files (x86)\360\Total Security\i18n\es\safemon\webprotection_firefox\plugins\nptswp.dll.locale
61c163c16946f4ca7039deae4b850371 c:\Program Files (x86)\360\Total Security\i18n\hi\AntiAdwa.dll.locale
97838d59982c4c8f249bead28dc7bddd c:\Program Files (x86)\360\Total Security\i18n\hi\UrlSettings.dll.locale
d9c303928257e9b5fdea57409932c20f c:\Program Files (x86)\360\Total Security\i18n\hi\deepscan\DsRes.dll
8f101c524bb13c51f743f7b7ed425bc4 c:\Program Files (x86)\360\Total Security\i18n\hi\deepscan\DsRes64.dll
13dab266bb4bb8851a020b795d2bcd40 c:\Program Files (x86)\360\Total Security\i18n\hi\ipc\NetDefender.dll.locale
0a9979f973e3c472fcb60eb829845076 c:\Program Files (x86)\360\Total Security\i18n\hi\ipc\Sxin.dll.locale
57a6893e30aa30dea6b85adcce594731 c:\Program Files (x86)\360\Total Security\i18n\hi\ipc\Sxin64.dll.locale
a2292a121723233de7354ba6a19c4c96 c:\Program Files (x86)\360\Total Security\i18n\hi\ipc\appd.dll.locale
f0584639cbc83cba9f6a391f28a69235 c:\Program Files (x86)\360\Total Security\i18n\hi\ipc\filemgr.dll.locale
8832a1eaa25429a66f9a53c14a58865e c:\Program Files (x86)\360\Total Security\i18n\hi\ipc\yhregd.dll.locale
44d6531aa7031c983d8de709d8319bde c:\Program Files (x86)\360\Total Security\i18n\hi\safemon\360SPTool.exe.locale
184345e22462199c88b50871013b8f6c c:\Program Files (x86)\360\Total Security\i18n\hi\safemon\360procmon.dll.locale
6c7a17405ea030d79f8a65c9afccba59 c:\Program Files (x86)\360\Total Security\i18n\hi\safemon\SelfProtectAPI2.dll.locale
38ce7430c5cc2c897f475ff921ba7945 c:\Program Files (x86)\360\Total Security\i18n\hi\safemon\UDiskScanEngine.dll.locale
1e0bdf33b5e1125563d371d355e20959 c:\Program Files (x86)\360\Total Security\i18n\hi\safemon\chrome\360webshield.exe.locale
aac382748a707f4d29f5bce9b6ddffa7 c:\Program Files (x86)\360\Total Security\i18n\hi\safemon\safemon.dll.locale
3617d3c0a4511ac8108050d7bbf0341c c:\Program Files (x86)\360\Total Security\i18n\hi\safemon\webprotection_firefox\plugins\nptswp.dll.locale
39caa308c66c66f83a66e82634d401d7 c:\Program Files (x86)\360\Total Security\i18n\pt\Antiadwa.dll.locale
602ca1c8baf48fafb2284b4b411fd81c c:\Program Files (x86)\360\Total Security\i18n\pt\UrlSettings.dll.locale
3fc8481e902c532038ca787b7fd39e99 c:\Program Files (x86)\360\Total Security\i18n\pt\deepscan\DsRes.dll
c1ac20a0b6bae4008af1c9aa6656221c c:\Program Files (x86)\360\Total Security\i18n\pt\deepscan\DsRes64.dll
b71912123cd7d2b5de1396d3f4897263 c:\Program Files (x86)\360\Total Security\i18n\pt\ipc\NetDefender.dll.locale
41ad76774d31ca6c1c92217c28a9143b c:\Program Files (x86)\360\Total Security\i18n\pt\ipc\Sxin.dll.locale
ec9e938695ad014f925c8f206951f9cb c:\Program Files (x86)\360\Total Security\i18n\pt\ipc\Sxin64.dll.locale
da3edad29ada20bcb580a4895b6c4650 c:\Program Files (x86)\360\Total Security\i18n\pt\ipc\appd.dll.locale
9305aa90434d48e4a349462eb95e4d8b c:\Program Files (x86)\360\Total Security\i18n\pt\ipc\filemgr.dll.locale
58c91d3ea097a9741cb1e33fc2e24c1f c:\Program Files (x86)\360\Total Security\i18n\pt\ipc\yhregd.dll.locale
1ff00e554380f0bca88745c272759993 c:\Program Files (x86)\360\Total Security\i18n\pt\safemon\360SPTool.exe.locale
eddf7bafdea2fc0298f6e0c9529210f5 c:\Program Files (x86)\360\Total Security\i18n\pt\safemon\360procmon.dll.locale
8305b78dd83a210591296265faa45a14 c:\Program Files (x86)\360\Total Security\i18n\pt\safemon\Safemon.dll.locale
363b6f498260984d4d1c36c017560cce c:\Program Files (x86)\360\Total Security\i18n\pt\safemon\SelfProtectAPI2.dll.locale
4b7ecec7e6f0f30fd6540e6b21bfdfa1 c:\Program Files (x86)\360\Total Security\i18n\pt\safemon\UDiskScanEngine.dll.locale
e7e563ace57bcff5a6a1ae284d12d9ab c:\Program Files (x86)\360\Total Security\i18n\pt\safemon\chrome\360webshield.exe.locale
9d946a13e391badcbff0ce2703ef0766 c:\Program Files (x86)\360\Total Security\i18n\pt\safemon\webprotection_firefox\plugins\nptswp.dll.locale
b6cf134aac06414be34abca411a23f78 c:\Program Files (x86)\360\Total Security\i18n\ru\AntiAdwa.dll.locale
e8265e61415a7a5e41d5c38ef771d025 c:\Program Files (x86)\360\Total Security\i18n\ru\UrlSettings.dll.locale
6b9172df50085c3fadbc73a61e152208 c:\Program Files (x86)\360\Total Security\i18n\ru\deepscan\DsRes.dll
64a6ddf703a3e1e2f254e639d0d1bae7 c:\Program Files (x86)\360\Total Security\i18n\ru\deepscan\DsRes64.dll
fb86134950ca839033705065f56c2f8b c:\Program Files (x86)\360\Total Security\i18n\ru\ipc\NetDefender.dll.locale
b91dd8dd773a332d95479a736c4e878a c:\Program Files (x86)\360\Total Security\i18n\ru\ipc\Sxin.dll.locale
9ae4809d9020396a2a67516d8d3d88e7 c:\Program Files (x86)\360\Total Security\i18n\ru\ipc\Sxin64.dll.locale
ab7a9ce51e00cb8a194762d7065e5a97 c:\Program Files (x86)\360\Total Security\i18n\ru\ipc\appd.dll.locale
669ce4e6a41a4dd299ffb67b4ec236e0 c:\Program Files (x86)\360\Total Security\i18n\ru\ipc\filemgr.dll.locale
20ccb9f6517eb5c7aafe34004855e8af c:\Program Files (x86)\360\Total Security\i18n\ru\ipc\yhregd.dll.locale
b73a74ebf7c30079dbb1d1fcb370c956 c:\Program Files (x86)\360\Total Security\i18n\ru\safemon\360SPTool.exe.locale
5dbb5e1feaacc9f097491fdea7a3deaa c:\Program Files (x86)\360\Total Security\i18n\ru\safemon\360procmon.dll.locale
d0a825cba20b18f96c975f74128e1932 c:\Program Files (x86)\360\Total Security\i18n\ru\safemon\Safemon.dll.locale
37fd6ad1242108535999c58be840f97a c:\Program Files (x86)\360\Total Security\i18n\ru\safemon\SelfProtectAPI2.dll.locale
91ebdd3701bd1834802384b728abd0cb c:\Program Files (x86)\360\Total Security\i18n\ru\safemon\UDiskScanEngine.dll.locale
8768617f4c8488cbbc23e50c30e2af15 c:\Program Files (x86)\360\Total Security\i18n\ru\safemon\chrome\360webshield.exe.locale
2ccb1135a31d4502cff25d0e53da89e2 c:\Program Files (x86)\360\Total Security\i18n\ru\safemon\webprotection_firefox\plugins\nptswp.dll.locale
7f0cbe734fec8cf4034faafc5490e83b c:\Program Files (x86)\360\Total Security\i18n\tr\AntiAdwa.dll.locale
5eba678c5b96d16373e99dbdfeab0471 c:\Program Files (x86)\360\Total Security\i18n\tr\UrlSettings.dll.locale
df363d23852fe94a70fab9b5001920cd c:\Program Files (x86)\360\Total Security\i18n\tr\deepscan\DsRes.dll
7d11b3a7f7053c5853c2c9fc98bef46c c:\Program Files (x86)\360\Total Security\i18n\tr\deepscan\DsRes64.dll
b698e7cc1e7610362cf15039d0d842e8 c:\Program Files (x86)\360\Total Security\i18n\tr\ipc\NetDefender.dll.locale
8597b8851698fde9dcff358af4f74b90 c:\Program Files (x86)\360\Total Security\i18n\tr\ipc\Sxin.dll.locale
a21a981e7a0adfff351c6a9ed115f25f c:\Program Files (x86)\360\Total Security\i18n\tr\ipc\Sxin64.dll.locale
a0c88fc5174375b607da9b661ade7f9e c:\Program Files (x86)\360\Total Security\i18n\tr\ipc\appd.dll.locale
4996648fa4751525838465d25bd1fef9 c:\Program Files (x86)\360\Total Security\i18n\tr\ipc\filemgr.dll.locale
864ef75cfbdbe14d5d0a90c2cc0d245e c:\Program Files (x86)\360\Total Security\i18n\tr\ipc\yhregd.dll.locale
a849ce96427191f49a0c091624d415f7 c:\Program Files (x86)\360\Total Security\i18n\tr\safemon\360SPTool.exe.locale
cd1df97454bade57b601dbb6fd2e335e c:\Program Files (x86)\360\Total Security\i18n\tr\safemon\360procmon.dll.locale
42a833746f6feacd0806012bf54bd091 c:\Program Files (x86)\360\Total Security\i18n\tr\safemon\SelfProtectAPI2.dll.locale
4eccfb3ddbbf5aa9174ced7d380bf1a5 c:\Program Files (x86)\360\Total Security\i18n\tr\safemon\UDiskScanEngine.dll.locale
7d1639e3feea5586c7f132b930b53f44 c:\Program Files (x86)\360\Total Security\i18n\tr\safemon\chrome\360webshield.exe.locale
bc580d57c56e67924dc493d0a0f0d546 c:\Program Files (x86)\360\Total Security\i18n\tr\safemon\safemon.dll.locale
5efd82b0e517230c5fcbbb4f02936ed0 c:\Program Files (x86)\360\Total Security\i18n\tr\safemon\webprotection_firefox\plugins\nptswp.dll.locale
ad7780222bca673975bbc7bdbf4587e4 c:\Program Files (x86)\360\Total Security\i18n\vi\AntiAdwa.dll.locale
3b237a30af209ea0c5e2bf041614946b c:\Program Files (x86)\360\Total Security\i18n\vi\UrlSettings.dll.locale
0fa04f7147b7d58e019f8461d354ad40 c:\Program Files (x86)\360\Total Security\i18n\vi\deepscan\DsRes.dll
b1f532abc4da80899e3f93983830ea12 c:\Program Files (x86)\360\Total Security\i18n\vi\deepscan\DsRes64.dll
b3640f8eb5dc2e83f617b5c8cba9f8e1 c:\Program Files (x86)\360\Total Security\i18n\vi\ipc\NetDefender.dll.locale
a7270cca11efc4fafef55a15695a7b54 c:\Program Files (x86)\360\Total Security\i18n\vi\ipc\Sxin.dll.locale
d6194d16acc8686082087ab4b0356ab5 c:\Program Files (x86)\360\Total Security\i18n\vi\ipc\Sxin64.dll.locale
4eb2e0bbf92f7d1ecfdd69b2f5d3f163 c:\Program Files (x86)\360\Total Security\i18n\vi\ipc\appd.dll.locale
39425f1503d863a2a187be7640ede8e9 c:\Program Files (x86)\360\Total Security\i18n\vi\ipc\filemgr.dll.locale
a9cbdc4907bbf0e6366a74f1064677d7 c:\Program Files (x86)\360\Total Security\i18n\vi\ipc\yhregd.dll.locale
8f6e965a4fe38c5f1c35b6bb903f795d c:\Program Files (x86)\360\Total Security\i18n\vi\safemon\360SPTool.exe.locale
722a770a5746314fc7475ccdf0b10859 c:\Program Files (x86)\360\Total Security\i18n\vi\safemon\360procmon.dll.locale
d4e86d27d044a4fe08cf924d6fc78bde c:\Program Files (x86)\360\Total Security\i18n\vi\safemon\SelfProtectAPI2.dll.locale
5ec0bfe71a79de1348bd0613ecd6da6e c:\Program Files (x86)\360\Total Security\i18n\vi\safemon\UDiskScanEngine.dll.locale
e6efb8a7bd18f4101fee9dcd877f3d01 c:\Program Files (x86)\360\Total Security\i18n\vi\safemon\chrome\360webshield.exe.locale
8bf196034f4af8ee9cf88bcae6e134e3 c:\Program Files (x86)\360\Total Security\i18n\vi\safemon\safemon.dll.locale
0fdedf23f925021a4454665fbedd49cd c:\Program Files (x86)\360\Total Security\i18n\vi\safemon\webprotection_firefox\plugins\nptswp.dll.locale
7ecc68e7f634afe5076d61bcc8b8f73d c:\Program Files (x86)\360\Total Security\i18n\zh-CN\AntiAdwa.dll.locale
8cb0bf9367c0e23f1c0b30bd70682f1c c:\Program Files (x86)\360\Total Security\i18n\zh-CN\UrlSettings.dll.locale
e6b53f645278ea1a45093db4f37497d5 c:\Program Files (x86)\360\Total Security\i18n\zh-CN\deepscan\DsRes.dll
66171cf0474220e4be51282450afcd75 c:\Program Files (x86)\360\Total Security\i18n\zh-CN\deepscan\DsRes64.dll
f133ddbd2619edf8cacf47caa3aa1b5d c:\Program Files (x86)\360\Total Security\i18n\zh-CN\ipc\NetDefender.dll.locale
c6ea80ca114c4885fb41b16a124ea841 c:\Program Files (x86)\360\Total Security\i18n\zh-CN\ipc\Sxin.dll.locale
8c27992c3502254ed6f92a02cb432373 c:\Program Files (x86)\360\Total Security\i18n\zh-CN\ipc\Sxin64.dll.locale
b69de4572d3070a146c4420b4e5fb72e c:\Program Files (x86)\360\Total Security\i18n\zh-CN\ipc\appd.dll.locale
45b862670d3c8bc8122407506d1fe052 c:\Program Files (x86)\360\Total Security\i18n\zh-CN\ipc\filemgr.dll.locale
ca514ea34867da1e371d6dae31f9b518 c:\Program Files (x86)\360\Total Security\i18n\zh-CN\ipc\yhregd.dll.locale
b26f96bd732e122906a05979549f84f6 c:\Program Files (x86)\360\Total Security\i18n\zh-CN\safemon\360SPTool.exe.locale
b5674a9b8183d7e98420977dce1760dc c:\Program Files (x86)\360\Total Security\i18n\zh-CN\safemon\360procmon.dll.locale
2acd4e6941d209a5df226870f6688b90 c:\Program Files (x86)\360\Total Security\i18n\zh-CN\safemon\Safemon.dll.locale
f9e52406ef1707ef839068bfb6334c20 c:\Program Files (x86)\360\Total Security\i18n\zh-CN\safemon\SelfProtectAPI2.dll.locale
a7ad4257d9eaa1941acc76a7c2f166cd c:\Program Files (x86)\360\Total Security\i18n\zh-CN\safemon\UDiskScanEngine.dll.locale
bbada95fbbbceefba22dc8a1fd6b95b5 c:\Program Files (x86)\360\Total Security\i18n\zh-CN\safemon\chrome\360webshield.exe.locale
37a82af097f424199884182d0096c325 c:\Program Files (x86)\360\Total Security\i18n\zh-CN\safemon\webprotection_firefox\plugins\nptswp.dll.locale
cb66c5314e5c5bb1a1f0a4769422a2b5 c:\Program Files (x86)\360\Total Security\i18n\zh-TW\AntiAdwa.dll.locale
16ede4dc56f1957f2a9f6d9e6988df6a c:\Program Files (x86)\360\Total Security\i18n\zh-TW\UrlSettings.dll.locale
e4734970e15679754d7b5332b2f525fb c:\Program Files (x86)\360\Total Security\i18n\zh-TW\deepscan\DsRes.dll
0959f9f8dafd121bc109dc0f349d5e9a c:\Program Files (x86)\360\Total Security\i18n\zh-TW\deepscan\DsRes64.dll
c707a9e296705ea27d99438f1dd9f2e2 c:\Program Files (x86)\360\Total Security\i18n\zh-TW\ipc\NetDefender.dll.locale
a1896c538b3817ef6d3d8f195c7d36e2 c:\Program Files (x86)\360\Total Security\i18n\zh-TW\ipc\Sxin.dll.locale
6608d2bd79b716dba6807fa7d8799f41 c:\Program Files (x86)\360\Total Security\i18n\zh-TW\ipc\Sxin64.dll.locale
ae795d7f330f851cb166295b3a4ca79f c:\Program Files (x86)\360\Total Security\i18n\zh-TW\ipc\appd.dll.locale
1a3eb4b4806dac5d3e0049e471748e7b c:\Program Files (x86)\360\Total Security\i18n\zh-TW\ipc\filemgr.dll.locale
94171ad0a5b0fa51120f769dcba1b39b c:\Program Files (x86)\360\Total Security\i18n\zh-TW\ipc\yhregd.dll.locale
c5a8221323db32593e971ea588e4d055 c:\Program Files (x86)\360\Total Security\i18n\zh-TW\safemon\360SPTool.exe.locale
51557349730e3426817abdb9cf998903 c:\Program Files (x86)\360\Total Security\i18n\zh-TW\safemon\360procmon.dll.locale
ba62b0a07b8fb65f09005ae532eae074 c:\Program Files (x86)\360\Total Security\i18n\zh-TW\safemon\Safemon.dll.locale
391bb5f09f663286495e98c13bc73230 c:\Program Files (x86)\360\Total Security\i18n\zh-TW\safemon\SelfProtectAPI2.dll.locale
bd45fac3eafc5164e05d86cb0b2e0da1 c:\Program Files (x86)\360\Total Security\i18n\zh-TW\safemon\UDiskScanEngine.dll.locale
be1f295eab9f6af2c09cf6b2f707f2f6 c:\Program Files (x86)\360\Total Security\i18n\zh-TW\safemon\chrome\360webshield.exe.locale
d782b07838b80666b980623ca178d375 c:\Program Files (x86)\360\Total Security\i18n\zh-TW\safemon\webprotection_firefox\plugins\nptswp.dll.locale
fa02b2c4d2091e841cd87a672a293be6 c:\Program Files (x86)\360\Total Security\ipc\360AntiHacker.dll
52595955f119578e4ed54b5dd528e589 c:\Program Files (x86)\360\Total Security\ipc\360AntiHacker.sys
15fe196a71357ac9ff6e5a4b360bdb20 c:\Program Files (x86)\360\Total Security\ipc\360AntiHacker64.sys
560651624ed7e32627d4c61e46c10fc2 c:\Program Files (x86)\360\Total Security\ipc\360Box.dll
ecfed10d908aad82bebc1581c185473e c:\Program Files (x86)\360\Total Security\ipc\360Box.sys
a583f4daaa4db87bf92fd033966abc4b c:\Program Files (x86)\360\Total Security\ipc\360Box64.sys
2255330a69644f179d0438666eef1861 c:\Program Files (x86)\360\Total Security\ipc\360Camera.sys
d31541708a595bca380105d44c2c2ad5 c:\Program Files (x86)\360\Total Security\ipc\360Camera64.sys
7a08b9ac69a1d538d514007ea9d3a719 c:\Program Files (x86)\360\Total Security\ipc\360boxld.exe
8c680010ced9087e7565cc5e9f9c11fb c:\Program Files (x86)\360\Total Security\ipc\360boxld64.exe
202cd3ec01e80b4fa963f0f5f007dd79 c:\Program Files (x86)\360\Total Security\ipc\360boxmain.exe
629e215120534dcc5a480932a081cc04 c:\Program Files (x86)\360\Total Security\ipc\DrvUtility.dll
2a3019a9536a275c51832058aeae2be4 c:\Program Files (x86)\360\Total Security\ipc\FileMgr.dll
20a95217f6bb7d46cfcde42610430d18 c:\Program Files (x86)\360\Total Security\ipc\NetDefender.dll
de5389c0b14f2e61da7aecb7f5df0d0f c:\Program Files (x86)\360\Total Security\ipc\SXIn.dll
b6e52418fc69c246698499b1fba04ffa c:\Program Files (x86)\360\Total Security\ipc\SXIn64.dll
263e382351c16a7bf904172531adf5f7 c:\Program Files (x86)\360\Total Security\ipc\SxWrapper.dll
ee6ec397b817b3ac3cf418e593e9bc1d c:\Program Files (x86)\360\Total Security\ipc\X64For32Lib.dll
9b1cdaf49a6af4f7c7ffeb040723208c c:\Program Files (x86)\360\Total Security\ipc\appd.dll
aafd535daf5c50c68e29165155e1d726 c:\Program Files (x86)\360\Total Security\ipc\appdext.dll
4b89182be351b3a69aa5d723495ae6c7 c:\Program Files (x86)\360\Total Security\ipc\ipcService.dll
d9d066dfa4f62817236d310d0986ab68 c:\Program Files (x86)\360\Total Security\ipc\qutmipc.dll
6358934b6cbde5d03a39865d67421404 c:\Program Files (x86)\360\Total Security\ipc\qutmipc.sys
cd58bda4e8b0ac5c7fb32f5d6d66df00 c:\Program Files (x86)\360\Total Security\ipc\sbmon.dll
0bdbcd1c97e174fb71eab6c0dd7fee02 c:\Program Files (x86)\360\Total Security\ipc\yhregd.dll
7fde62e513d0640239c54d49f3904f2b c:\Program Files (x86)\360\Total Security\leakrepair.dll
634154f9b970e3e419d6bfa39322fbc0 c:\Program Files (x86)\360\Total Security\netmon\360GameIdentify.dll
bac04c07ed042d9ffe51bafdda529236 c:\Program Files (x86)\360\Total Security\netmon\Netgm.dll
1777732c31b70324d02e2b45232830a5 c:\Program Files (x86)\360\Total Security\safemon\360AV.tpi
d379cc6ef1c3ef89edb92aaf16169c23 c:\Program Files (x86)\360\Total Security\safemon\360GuardBase.dll
2041813175353dda6fc7dfc4dbac7970 c:\Program Files (x86)\360\Total Security\safemon\360SPTool.exe
5e1c49803e42a1adf5569fb6c3576fd5 c:\Program Files (x86)\360\Total Security\safemon\360SafeCamera.tpi
0bbdac6662a660776c126109296f2043 c:\Program Files (x86)\360\Total Security\safemon\360SelfProtection.sys
dafa2c8b54a617e253aab366f8459d7a c:\Program Files (x86)\360\Total Security\safemon\360Tray.exe
7506457f57ed209f39ca5dd7e6d2bd20 c:\Program Files (x86)\360\Total Security\safemon\360UDisk.tpi
7d4c79291cc614ed8840497334a53195 c:\Program Files (x86)\360\Total Security\safemon\360compro.dll
36852a7345c57ada1c2c4e9fd36dec45 c:\Program Files (x86)\360\Total Security\safemon\360hipsPopWnd.dll
2532e778883285c803456b6e859a52ed c:\Program Files (x86)\360\Total Security\safemon\360procmon.dll
142c2df8cb64c41ecc3d760e4a1ce064 c:\Program Files (x86)\360\Total Security\safemon\360safemonpro.tpi
a10415ccc5dfbe9015ed6cbeec7ace91 c:\Program Files (x86)\360\Total Security\safemon\360zipc.dll
34d201db838c733d54358184a5116192 c:\Program Files (x86)\360\Total Security\safemon\7z.dll
12d2e17fd5dcd04a066c0e719b18e656 c:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
036f4bc6ab6fce17f886993fb7c8abf9 c:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
776361a68ad6c3449adbca07e135119c c:\Program Files (x86)\360\Total Security\safemon\QHToasts.exe
2571b45b9573c5b42ae04d48e36118cb c:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe
775fe6177fce4c9fcb6f50af336e13a3 c:\Program Files (x86)\360\Total Security\safemon\SelfProtectAPI2.dll
b1dec6aeaf9ecb3e5ec8703d5978cda1 c:\Program Files (x86)\360\Total Security\safemon\SomProxy.dll
7f14cfee39dfd7e67a541b67470cb334 c:\Program Files (x86)\360\Total Security\safemon\UDiskScanEngine.dll
e6ac7afc9d5b4f257001f8a4081b2c95 c:\Program Files (x86)\360\Total Security\safemon\WDPayPro.exe
8b3b79e6df8a90562899400f787cfe78 c:\Program Files (x86)\360\Total Security\safemon\WDRecord.dll
c19637b4da07de8d2a89a752cd751932 c:\Program Files (x86)\360\Total Security\safemon\WDSafeDown.exe
318175681fb78fc3ed2439822dc2b971 c:\Program Files (x86)\360\Total Security\safemon\WscReg.exe
7c60cf4a939f2137704a4f167d35a656 c:\Program Files (x86)\360\Total Security\safemon\chrome\360webshield.exe
64f2427bab6f7b0f521a1c60dd4ba55a c:\Program Files (x86)\360\Total Security\safemon\dlproc.dll
c369978dbcf5e6b18bf595cc30c6a5f3 c:\Program Files (x86)\360\Total Security\safemon\gamemode.tpi
a377dac0a2443f5301e97fa76096e609 c:\Program Files (x86)\360\Total Security\safemon\hookport.sys
bbe58d8ba07ebb6bc9db38d147df9009 c:\Program Files (x86)\360\Total Security\safemon\iNetSafe.dll
796c20ab08d42d96bce1b9dbcdf272d2 c:\Program Files (x86)\360\Total Security\safemon\safemon.dll
7691da40a547e6d33c1e493486b0ded1 c:\Program Files (x86)\360\Total Security\safemon\urlproc.dll
5ef30201a552721749200e7278f06478 c:\Program Files (x86)\360\Total Security\safemon\wdui2.dll
a88d64734dd2b88fa45a83cca38db260 c:\Program Files (x86)\360\Total Security\safemon\wdui3.dll
4fe01dc65902fff76805aa735043142a c:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox\plugins\nptswp.dll
012b352afa4cc7fbf954bcc059c38ff6 c:\Program Files (x86)\360\Total Security\safescan.dll
a46da3ce2f11102850711ecdda8046e1 c:\Program Files (x86)\360\Total Security\scanbase.dll
7f186173e147c6f636648f405fe015a8 c:\Program Files (x86)\360\Total Security\scanproxy.dll
0afa636081aa1bfa48d2da8acf47655e c:\Program Files (x86)\360\Total Security\scanstub.dll
04a2b5758fc8ca6897b0e7243569dd77 c:\Program Files (x86)\360\Total Security\sites.dll
a976147886932652f8bb0dd2df69ed92 c:\Program Files (x86)\360\Total Security\softmgr\360SoftMgrS.dll
f5b75a82fcae6c253c38b9f3003ded55 c:\Program Files (x86)\360\Total Security\softmgr\SomAdvUtils.dll
9d16e935943e16dc5f84e3b848a95a0f c:\Program Files (x86)\360\Total Security\softmgr\SomAdvUtilsWrap.dll
7efb7d4089abbe163d726149195fbd95 c:\Program Files (x86)\360\Total Security\softmgr\SpeedUp.dll
0104db298800fb97f13f229314738a08 c:\Program Files (x86)\360\Total Security\softmgr\somkernl.dll
5555730dd02f3cca685226e27dbcd2c0 c:\Program Files (x86)\360\Total Security\sweeper\CleanHelper64.exe
3a604f30d608cb71a441e7fd2223ecea c:\Program Files (x86)\360\Total Security\sweeper\RemoteTrashInterface.dll
a19209ad7e35b4ca20e2737b6a4d1740 c:\Program Files (x86)\360\Total Security\sweeper\SysSweeper.dll
7ae14956462a73e308bf80ec8d00f652 c:\Program Files (x86)\360\Total Security\sweeper\TrashClean.dll
f54ae50f78f883a0da90f96ec94b8736 c:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6HVGFTJ0\360TotalSecurity_Rus_Setup_0001[1].exe
a5dbd83383fae13d2de6a4acab62aaa3 c:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HDZ3KS6S\Directx_9.10.11[1].exe
8c42fc725106cf8276e625b4f97861bc c:\Users\"%CurrentUserName%"\AppData\Local\Temp\1429760925_00000000_base\360base.dll
a5dbd83383fae13d2de6a4acab62aaa3 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd45AA.tmp.exe
9e0711bed229b60a853bcc5d10deaafc c:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DSETUP.dll
ddce338bb173b32024679d61fb4f2ba6 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DXSETUP.exe
0f58ccd58a29827b5d406874360e4c08 c:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\dsetup32.dll

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Trojan's file once a user opens a drive's folder in Windows Explorer.

VersionInfo

No information is available.

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 37484 37888 4.11399 ab04b737e912b2d921facc6512684286
.data 45056 144 512 0.86365 3b4d640825fa0546a087a45d82fc4d7e
.rdata 49152 24552 24576 4.99289 c048b5754afd326ca2a4eabaaf948a46
.bss 73728 112596 0 0 d41d8cd98f00b204e9800998ecf8427e
.idata 188416 4960 5120 3.67966 f869bd1dfb7c16e92b07aef7e161ae9f
.ndata 196608 65536 1024 0 0f343b0931126a20f133d67c2b018a3b
.rsrc 262144 84208 84480 3.77312 a869ecee254cd015a2c70ca46ce4cfb8

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

URLs

URL IP
hxxp://www-google-analytics.l.google.com/collect?v=1&tid=UA-54698389-1&cid=4001577&t=pageview&dp=/softobase_wrapper_started
hxxp://www-google-analytics.l.google.com/collect?v=1&tid=UA-54698389-1&cid=4001577&t=pageview&dp=/softobase_wrapper_second_screen
hxxp://www-google-analytics.l.google.com/collect?v=1&tid=UA-54698389-1&cid=4001577&t=pageview&dp=/softobase_wrapper_offer_yes
hxxp://download.softobase.com/ru//Directx_9.10.11.exe
hxxp://download.softobase.com/ru/360TotalSecurity_Rus_Setup_0001.exe
hxxp://s.360safe.com/safei18n/ins.htm?mid=09bcd29b60133ba15b849679a9d82fa3&ver=6.2.0.1027&lan=en&os=6.1-x64&ch=softobase_ru&ue=1
hxxp://qup.cloud.os-lb.com/qconf.php
hxxp://104.192.108.116/cloudquery.php
hxxp://q.patch.360safe.com.awsr53.qihucdn.com/qm/f3d59eaa9ff33dcbe50abb4276fbe86c_7f60e69c8df5184d2425290206a842ea_5c78d14616e83859609ca3a719ba5701_08759c104a2519b794dbb88e67c68b5b.html?lang=en 54.76.174.118
hxxp://q.patch.360safe.com.awsr53.qihucdn.com/qm/b0586730837afd39a4c6ffc29b8b45d1_0e20c81dbd120c83183c177cfc89a0cd_a8a404644af66d5edc3ddbf197bfa603_a0b0c1d9e2b22a2b18db00adfaf188b8_c60679ca1168c44c164f07248f20e5bc_729e30d5c7cc3017124cc6b758e3c18f_f2a5f9f80981ac71a5fed8321d0f97ed_771d63b6be5618a5a7348c591a6eaa8b_e6b21c42019a616ba330879cab91b21f_e2cbb6402ac6b292f2e8f47364289cee.html?lang=en 54.76.174.118
hxxp://q.patch.360safe.com.awsr53.qihucdn.com/qm/c6cb4f5ac0255d2baf41678f26cd50cc_e9ae86455b04bf504ecbd7c7944b9dbe_7fdde18475dc134cace116c202eee2d4_351aaa705ad2bfe61d737e6c2ff59cb7_8e3f695edfee356c0ce44d45973e6e3d_10a33cc11d32c95ebe3dc53ebb04ca53_9bddd8965f0fb4f43008698df4c88648_64adc54c5e594f2dea16b70cc30c60e3_639d29e60ac1265ee915507a58eee764_619737941c6f039502af0ca22aef89a4.html?lang=en 54.76.174.118
hxxp://q.patch.360safe.com.awsr53.qihucdn.com/qm/4ae7fb61ded98e1cd0fa51382739609d_eb6ffe3d9a8bc43b119f425d7455d531_3a4ecb93bee8365798b40edf1c7fd91e_4d46a68264b8919496d26d364d8090b6_36f661643ed70de2c3ba8953ff1e1413_b9ac2efa36cb97ec91388bc33ab41834_3f9d587294f714ec7225f558fb0188d4_1d9d050a761ca43372b982242d454a1d_92f9e3aa0878870a4141ec34bc6d5801_9c9cbe7e714bcd27ebada3be27f59997.html?lang=en 54.76.174.118
hxxp://q.patch.360safe.com.awsr53.qihucdn.com/qm/dbbccf0284b1c6112444badae27b87c1_5f0a5b172d4b5ecc5b3ef0cc5474cd37_ad73e74d2e19934416da93519d7df2b1_fa5e8d8c25b5c5065a2dd11f06204c85_2b1338ddf314d8226e904876a3ee7080_07981a7a353d752cfb1592b50da561f5_8060a700fac6122047189ef371cd3f74_643bc87126cf236fc79dd6f724aca265_5ead54d5f96109bae4d9c930a8939abe_3de7aad99977dd3b7bce4d7903aaf9d3.html?lang=en 54.76.174.118
hxxp://q.patch.360safe.com.awsr53.qihucdn.com/qm/7539e5c431f211952383e009cce4062d_db88b047a62996ecbdd46d4963a6e31c_8577fa6c6033344612199762bb9f103d_b38f46b78ddb8002e9f62beef6ad93f9_790208b89dfc8dc6a26482279ece0df5_fe000a5f0d9c756acaa12501852dd3e1_22738172936eb3c113317245ad15a3a9_e7ef487131e23bdeb1194f844474d8f1_81047bc4f848deb9c1e01d7e99ce85da_c89221d597d1b038b275e583c49aef33.html?lang=en 54.76.174.118
hxxp://q.patch.360safe.com.awsr53.qihucdn.com/qm/9909aa216b30b502f677bfff05000b0e_8ecb89f3f07308b46e8f3b9910dc0f51_5da0bfb669c5f1fa42a938f8731a2ff5_4d5081f0e6ef496e640537ab0d892e92_396e96b0d6cf2047f661e847da722261_d4a64e1269957bfdf26df207f44924ff_405db178237b942c4b5871775daa9d37_95930fb68cca6ba86d1876431d0410a9_25decf1c6f9b4b7d68e04342781efe95_48db5a7174e85b83303b2e691959f20d.html?lang=en 54.76.174.118
hxxp://q.patch.360safe.com.awsr53.qihucdn.com/qm/e6e862c79dc156d48370cc4f389eee28_58d21421ec10d7ec9ef08ce78a988b1e_8f166cecb19c47f41c45ed863de7b0d1_896ddf703e6e0c17d1fbf3fd2b467bcb_5ab2456234592215792583ee5ef9e433_74c7a7cd928fcedef39ccee1474ddb37_2e223e0dcce1b2ac068778ee37521487_90590ddf1137009e5d306a8fcbb9f5f5_a53cf4ce8dcc65dbd195aaf5769cd693_79a73367e8f15c93cdce7773eefc808b.html?lang=en 54.76.174.118
hxxp://q.patch.360safe.com.awsr53.qihucdn.com/qm/0cd47f5d563ba06a1e44716398931a08_4dec213c03a525d652460c0d5181cd45_4375cc87f7432f2774c519a50f5074df_e6f7ea0625257466991d27e0b8ac71cd_9e5615703c195167788ea46b1ed76600_3572385f0a757d33e2a9ee99a763834e_d7bee05e090c87a6b33bc2b8c77da29d_ae75251d6b6fe765d3979069dff3fbbd_b9dd248083413c0a205ba1803cf1710b_f7382d6e2985358f3ab826c871f5d968.html?lang=en 54.76.174.118
hxxp://54.76.137.169/cloudquery.php
hxxp://www.google-analytics.com/collect?v=1&tid=UA-54698389-1&cid=4001577&t=pageview&dp=/softobase_wrapper_second_screen
hxxp://tconf.cloud.360safe.com/qconf.php
hxxp://q.patch.360safe.com/qm/b0586730837afd39a4c6ffc29b8b45d1_0e20c81dbd120c83183c177cfc89a0cd_a8a404644af66d5edc3ddbf197bfa603_a0b0c1d9e2b22a2b18db00adfaf188b8_c60679ca1168c44c164f07248f20e5bc_729e30d5c7cc3017124cc6b758e3c18f_f2a5f9f80981ac71a5fed8321d0f97ed_771d63b6be5618a5a7348c591a6eaa8b_e6b21c42019a616ba330879cab91b21f_e2cbb6402ac6b292f2e8f47364289cee.html?lang=en 54.76.174.118
hxxp://q.patch.360safe.com/qm/9909aa216b30b502f677bfff05000b0e_8ecb89f3f07308b46e8f3b9910dc0f51_5da0bfb669c5f1fa42a938f8731a2ff5_4d5081f0e6ef496e640537ab0d892e92_396e96b0d6cf2047f661e847da722261_d4a64e1269957bfdf26df207f44924ff_405db178237b942c4b5871775daa9d37_95930fb68cca6ba86d1876431d0410a9_25decf1c6f9b4b7d68e04342781efe95_48db5a7174e85b83303b2e691959f20d.html?lang=en 54.76.174.118
hxxp://q.patch.360safe.com/qm/e6e862c79dc156d48370cc4f389eee28_58d21421ec10d7ec9ef08ce78a988b1e_8f166cecb19c47f41c45ed863de7b0d1_896ddf703e6e0c17d1fbf3fd2b467bcb_5ab2456234592215792583ee5ef9e433_74c7a7cd928fcedef39ccee1474ddb37_2e223e0dcce1b2ac068778ee37521487_90590ddf1137009e5d306a8fcbb9f5f5_a53cf4ce8dcc65dbd195aaf5769cd693_79a73367e8f15c93cdce7773eefc808b.html?lang=en 54.76.174.118
hxxp://www.google-analytics.com/collect?v=1&tid=UA-54698389-1&cid=4001577&t=pageview&dp=/softobase_wrapper_offer_yes
hxxp://q.patch.360safe.com/qm/dbbccf0284b1c6112444badae27b87c1_5f0a5b172d4b5ecc5b3ef0cc5474cd37_ad73e74d2e19934416da93519d7df2b1_fa5e8d8c25b5c5065a2dd11f06204c85_2b1338ddf314d8226e904876a3ee7080_07981a7a353d752cfb1592b50da561f5_8060a700fac6122047189ef371cd3f74_643bc87126cf236fc79dd6f724aca265_5ead54d5f96109bae4d9c930a8939abe_3de7aad99977dd3b7bce4d7903aaf9d3.html?lang=en 54.76.174.118
hxxp://q.patch.360safe.com/qm/f3d59eaa9ff33dcbe50abb4276fbe86c_7f60e69c8df5184d2425290206a842ea_5c78d14616e83859609ca3a719ba5701_08759c104a2519b794dbb88e67c68b5b.html?lang=en 54.76.174.118
hxxp://www.google-analytics.com/collect?v=1&tid=UA-54698389-1&cid=4001577&t=pageview&dp=/softobase_wrapper_started
hxxp://q.patch.360safe.com/qm/7539e5c431f211952383e009cce4062d_db88b047a62996ecbdd46d4963a6e31c_8577fa6c6033344612199762bb9f103d_b38f46b78ddb8002e9f62beef6ad93f9_790208b89dfc8dc6a26482279ece0df5_fe000a5f0d9c756acaa12501852dd3e1_22738172936eb3c113317245ad15a3a9_e7ef487131e23bdeb1194f844474d8f1_81047bc4f848deb9c1e01d7e99ce85da_c89221d597d1b038b275e583c49aef33.html?lang=en 54.76.174.118
hxxp://q.patch.360safe.com/qm/0cd47f5d563ba06a1e44716398931a08_4dec213c03a525d652460c0d5181cd45_4375cc87f7432f2774c519a50f5074df_e6f7ea0625257466991d27e0b8ac71cd_9e5615703c195167788ea46b1ed76600_3572385f0a757d33e2a9ee99a763834e_d7bee05e090c87a6b33bc2b8c77da29d_ae75251d6b6fe765d3979069dff3fbbd_b9dd248083413c0a205ba1803cf1710b_f7382d6e2985358f3ab826c871f5d968.html?lang=en 54.76.174.118
hxxp://q.patch.360safe.com/qm/4ae7fb61ded98e1cd0fa51382739609d_eb6ffe3d9a8bc43b119f425d7455d531_3a4ecb93bee8365798b40edf1c7fd91e_4d46a68264b8919496d26d364d8090b6_36f661643ed70de2c3ba8953ff1e1413_b9ac2efa36cb97ec91388bc33ab41834_3f9d587294f714ec7225f558fb0188d4_1d9d050a761ca43372b982242d454a1d_92f9e3aa0878870a4141ec34bc6d5801_9c9cbe7e714bcd27ebada3be27f59997.html?lang=en 54.76.174.118
hxxp://q.patch.360safe.com/qm/c6cb4f5ac0255d2baf41678f26cd50cc_e9ae86455b04bf504ecbd7c7944b9dbe_7fdde18475dc134cace116c202eee2d4_351aaa705ad2bfe61d737e6c2ff59cb7_8e3f695edfee356c0ce44d45973e6e3d_10a33cc11d32c95ebe3dc53ebb04ca53_9bddd8965f0fb4f43008698df4c88648_64adc54c5e594f2dea16b70cc30c60e3_639d29e60ac1265ee915507a58eee764_619737941c6f039502af0ca22aef89a4.html?lang=en 54.76.174.118


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

SURICATA UDPv4 invalid checksum
SURICATA IPv4 invalid checksum
ET POLICY User-Agent (NSIS_Inetc (Mozilla)) - Sometimes used by hostile installers
ET SHELLCODE Possible TCP x86 JMP to CALL Shellcode Detected
ET DNS Non-DNS or Non-Compliant DNS traffic on DNS port Reserved Bit Set - Likely Kazy

Traffic

GET /qm/9909aa216b30b502f677bfff05000b0e_8ecb89f3f07308b46e8f3b9910dc0f51_5da0bfb669c5f1fa42a938f8731a2ff5_4d5081f0e6ef496e640537ab0d892e92_396e96b0d6cf2047f661e847da722261_d4a64e1269957bfdf26df207f44924ff_405db178237b942c4b5871775daa9d37_95930fb68cca6ba86d1876431d0410a9_25decf1c6f9b4b7d68e04342781efe95_48db5a7174e85b83303b2e691959f20d.html?lang=en HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)
Host: q.patch.360safe.com
Accept: */*
Connection: Keep-Alive
Cache-Control: no-cache



hXXp://dl.patch.360safe.com/leak/ty/NDP40-KB2742595-x64.exe|b9=1|b3=4d
5081f0e6ef496e640537ab0d892e92|p2=4ee5d4e821bfca4b539e56f72559638c0295
03db|b2=13309984|h3=60|h7=7|p4=7200|b5=vulnerability fix</link>&
lt;/url><url md5="396e96b0d6cf2047f661e847da722261"><link&
gt;pdown://hXXp://qh.dlservice.microsoft.com/download/E/3/C/E3CC9887-7
01B-453C-9386-87BBCFF22057/NDP40-KB2789642-x64.exe;hXXp://dl.patch.360
safe.com/leak/ty/NDP40-KB2789642-x64.exe|b9=1|b3=396e96b0d6cf2047f661e
847da722261|p2=850ad178d64e17ff114006bf2089b8f560776d60|b2=4256248|h3=
60|h7=7|p4=7200|b5=vulnerability fix</link></url><url m
d5="d4a64e1269957bfdf26df207f44924ff"><link>pdown://hXXp://qh
.dlservice.microsoft.com/download/7/3/9/7393F2CE-7701-4CD6-9501-D10CF8
AF680C/Windows6.1-KB2840149-x64.msu;hXXp://dl.patch.360safe.com/leak/w
in7/Windows6.1-KB2840149-x64.msu|b9=1|b3=d4a64e1269957bfdf26df207f4492
4ff|p2=00621b6ee4919fba840764b0d533d29f4929b44e|b2=1651749|h3=60|h7=7|
p4=7200|b5=vulnerability fix</link></url><url md5="405d
b178237b942c4b5871775daa9d37"><link>pdown://hXXp://qh.dlservi
ce.microsoft.com/download/F/D/B/FDB0E76D-2C15-45D1-A49B-BFB405008569/W
indows6.1-KB2813430-x64.msu;hXXp://dl.patch.360safe.com/leak/win7/Wind
ows6.1-KB2813430-x64.msu|b9=1|b3=405db178237b942c4b5871775daa9d37|p2=d
1f8f88664f18ef565a5e11db3ff1df64a0e7c26|b2=3989948|h3=60|h7=7|p4=7200|
b5=vulnerability fix</link></url><url md5="95930fb68cca
6ba86d1876431d0410a9"><link>pdown://hXXp://qh.dlservice.m

<<< skipped >>>

POST /cloudquery.php HTTP/1.1
User-Agent: Post_Multipart
Host: 54.76.137.169
Accept: */*
Pragma: no-cache
X-360-Cloud-Security-Desc: Scan Suspicious File
x-360-ver: 4
Content-Length: 978
Content-Type: multipart/form-data; boundary=----------------------------49d1b5b13606

------------------------------49d1b5b13606
Content-Disposition: form-data; name="m"

..@Bs.....!.6 .d..[email protected]...,O.....c&g.K..m.(.lo`.'
........6N.>.G.&......f...../}EQ.'...cBC...c................R..S..P~|.
.xi...67...N./.M..'...B.K...-?...0|..8x...s..?.|..S....'....t........F...6...X\.`;.!..*M
f.)..~I.kN.o.i..~.<..d2...'q..7n.....G.d.....Q...q.D.;..{... _s^.W.Bb'. .Ew..z.5.... ...........].....h.Z.....#..... ..3[...\....p...v........\..)v.5..1.....0.XT..,q.....|.........{:..5.......
R_)......J\._..k.)l38..,V........tph.r....p.s.X},..E4....K.....lT[S......b.N.
.%..t~=..K..bD$*T.Y.'Q..u
.zQ.."T...n...X.75S.<..b..k.."m..P..Gz.)......$...k..B...a.G......*[email protected]...*T.K.X..`[email protected] ....I$/...EufO{..s,.....`........Tn.Z...98.A...I;.....z".C........Ll.4...q.`.]..2'..G.ja..|..V...!.A.I.5.zl..".>.....Yi..'...m.U..0m..a8.J1y.5.m.|.....z.1..."..K.......:._......*..m.rTG_NK.Z..".$.e.........
------------------------------49d1b5b13606--

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Thu, 23 Apr 2015 03:52:05 GMT
Content-Type: text/plain
Content-Length: 208
Connection: close
Vary: Accept-Encoding
....Bs......P.....Jo.N..^d.nj.......m..a....K..... >.Q.{.y`%1...r.;
.......>..J^.9........8l,v....<.R...R.T.U.....T...U...P.W.......
T...S...T...R...........T.P...S...........T.?.....................?.?.
....<.<..


GET /qm/7539e5c431f211952383e009cce4062d_db88b047a62996ecbdd46d4963a6e31c_8577fa6c6033344612199762bb9f103d_b38f46b78ddb8002e9f62beef6ad93f9_790208b89dfc8dc6a26482279ece0df5_fe000a5f0d9c756acaa12501852dd3e1_22738172936eb3c113317245ad15a3a9_e7ef487131e23bdeb1194f844474d8f1_81047bc4f848deb9c1e01d7e99ce85da_c89221d597d1b038b275e583c49aef33.html?lang=en HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)
Host: q.patch.360safe.com
Accept: */*
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: nginx/1.2.9
Date: Thu, 23 Apr 2015 03:50:50 GMT
Content-Type: text/xml
Content-Length: 2695
Connection: close
<?xml version="1.0" encoding="utf-8"?><xml><url md5="b3
8f46b78ddb8002e9f62beef6ad93f9"><link>pdown://hXXp://qh.dlser
vice.microsoft.com/download/9/3/2/932772EB-1CB6-4231-B93B-3720A2D2680C
/Windows6.1-KB2968294-x64.msu;hXXp://dl.patch.360safe.com/leak/win7/Wi
ndows6.1-KB2968294-x64.msu|b9=1|b3=b38f46b78ddb8002e9f62beef6ad93f9|p2
=212f4b9ded624a282f0d8120e8045057c1cc1232|b2=1397666|h3=60|h7=15|b5=vu
lnerability fix</link></url><url md5="790208b89dfc8dc6a
26482279ece0df5"><link>pdown://hXXp://qh.dlservice.microsoft.
com/download/9/B/6/9B6373AF-6E54-4972-BB2B-99048F023632/Windows6.1-KB2
972100-x64.msu;hXXp://dl.patch.360safe.com/leak/win7/Windows6.1-KB2972
100-x64.msu|b9=1|b3=790208b89dfc8dc6a26482279ece0df5|p2=dba40228571104
537e6d577390fb1bacb91cec24|b2=2135528|h3=60|h7=15|b5=vulnerability fix
</link></url><url md5="fe000a5f0d9c756acaa12501852dd3e1
"><link>pdown://hXXp://qh.dlservice.microsoft.com/download/1/
5/E/15E6F381-A764-457D-A9BF-D4DF22665F1D/NDP40-KB2972106-x64.exe;http:
//dl.patch.360safe.com/leak/ty/NDP40-KB2972106-x64.exe|b9=1|b3=fe000a5
f0d9c756acaa12501852dd3e1|p2=9e48abec988f0ded037283d862e38e16436e9d3c|
b2=4013232|h3=60|h7=15|b5=vulnerability fix</link></url>&l
t;url md5="22738172936eb3c113317245ad15a3a9"><link>pdown://ht
tp://qh.dlservice.microsoft.com/download/C/3/E/C3E70E3A-E9F9-4BC2-8452
-FAC21EDA04B4/Windows6.1-KB2977292-x64.msu;hXXp://dl.patch.360safe.com
/leak/win7/Windows6.1-KB2977292-x64.msu|b9=1|b3=22738172936eb3c113

<<< skipped >>>

GET /qm/dbbccf0284b1c6112444badae27b87c1_5f0a5b172d4b5ecc5b3ef0cc5474cd37_ad73e74d2e19934416da93519d7df2b1_fa5e8d8c25b5c5065a2dd11f06204c85_2b1338ddf314d8226e904876a3ee7080_07981a7a353d752cfb1592b50da561f5_8060a700fac6122047189ef371cd3f74_643bc87126cf236fc79dd6f724aca265_5ead54d5f96109bae4d9c930a8939abe_3de7aad99977dd3b7bce4d7903aaf9d3.html?lang=en HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)
Host: q.patch.360safe.com
Accept: */*
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: nginx/1.2.9
Date: Thu, 23 Apr 2015 03:50:49 GMT
Content-Type: text/xml
Content-Length: 49
Connection: close
<?xml version="1.0" encoding="utf-8"?><xml></xml>..


GET /qm/4ae7fb61ded98e1cd0fa51382739609d_eb6ffe3d9a8bc43b119f425d7455d531_3a4ecb93bee8365798b40edf1c7fd91e_4d46a68264b8919496d26d364d8090b6_36f661643ed70de2c3ba8953ff1e1413_b9ac2efa36cb97ec91388bc33ab41834_3f9d587294f714ec7225f558fb0188d4_1d9d050a761ca43372b982242d454a1d_92f9e3aa0878870a4141ec34bc6d5801_9c9cbe7e714bcd27ebada3be27f59997.html?lang=en HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)
Host: q.patch.360safe.com
Accept: */*
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: nginx/1.2.9
Date: Thu, 23 Apr 2015 03:50:49 GMT
Content-Type: text/xml
Content-Length: 3083
Connection: close
<?xml version="1.0" encoding="utf-8"?><xml><url md5="4a
e7fb61ded98e1cd0fa51382739609d"><link>pdown://hXXp://qh.dlser
vice.microsoft.com/download/C/C/A/CCA7CA55-9109-42B0-908C-FFA419E4792E
/NDP40-KB2978125-x64.exe;hXXp://dl.patch.360safe.com/leak/ty/NDP40-KB2
978125-x64.exe|b9=1|b3=4ae7fb61ded98e1cd0fa51382739609d|p2=6ce8b5a8c71
17ced5200728b10ce0bbd118198ed|b2=2076344|h3=60|h7=15|b5=vulnerability
fix</link></url><url md5="eb6ffe3d9a8bc43b119f425d7455d
531"><link>pdown://hXXp://qh.dlservice.microsoft.com/download
/C/6/9/C6997FC5-FBD6-40F6-AA11-3ABBB25B6DA4/Windows6.1-KB2991963-x64.m
su;hXXp://dl.patch.360safe.com/leak/win7/Windows6.1-KB2991963-x64.msu|
b9=1|b3=eb6ffe3d9a8bc43b119f425d7455d531|p2=2d1a373da3175f43c702b83b5f
2402415e9a2715|b2=1294527|h3=60|h7=15|b5=vulnerability fix</link>
;</url><url md5="3a4ecb93bee8365798b40edf1c7fd91e"><lin
k>pdown://hXXp://qh.dlservice.microsoft.com/download/8/2/8/828063ED
-DEF2-415A-B39F-F0CB06C4BDE4/Windows6.1-KB2992611-x64.msu;hXXp://dl.pa
tch.360safe.com/leak/win7/Windows6.1-KB2992611-x64.msu|b9=1|b3=3a4ecb9
3bee8365798b40edf1c7fd91e|p2=c494fce3ed8d648614ed49d367426b7839e99ccf|
b2=5479321|h3=60|h7=15|b5=vulnerability fix</link></url>&l
t;url md5="4d46a68264b8919496d26d364d8090b6"><link>pdown://ht
tp://qh.dlservice.microsoft.com/download/0/9/0/090571D8-1045-4032-9710
-96C8847D2F5B/Windows6.1-KB2993958-x64.msu;hXXp://dl.patch.360safe.com
/leak/win7/Windows6.1-KB2993958-x64.msu|b9=1|b3=4d46a68264b8919496

<<< skipped >>>

POST /qconf.php HTTP/1.1
User-Agent: Post_Multipart
Host: tconf.cloud.360safe.com
Accept: */*
Pragma: no-cache
X-360-Cloud-Security-Desc: Scan Suspicious File
x-360-ver: 4
Content-Length: 68
Content-Type: application/x-www-form-urlencoded

....../.....f.....)7.)..l.........0S.bb..o....-..d2S..]6o..|.C.M.u
HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Thu, 23 Apr 2015 03:50:46 GMT
Content-Type: text/plain
Content-Length: 36
Connection: close
Vary: Accept-Encoding
......B.pc..%p....jC...]....-...S..^..


GET /qm/f3d59eaa9ff33dcbe50abb4276fbe86c_7f60e69c8df5184d2425290206a842ea_5c78d14616e83859609ca3a719ba5701_08759c104a2519b794dbb88e67c68b5b.html?lang=en HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)
Host: q.patch.360safe.com
Accept: */*
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: nginx/1.2.9
Date: Thu, 23 Apr 2015 03:50:49 GMT
Content-Type: text/xml
Content-Length: 49
Connection: close
<?xml version="1.0" encoding="utf-8"?><xml></xml>..


GET /safei18n/ins.htm?mid=09bcd29b60133ba15b849679a9d82fa3&ver=6.2.0.1027&lan=en&os=6.1-x64&ch=softobase_ru&ue=1 HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/6.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C)
Host: s.360safe.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: nginx/1.0.12
Date: Thu, 23 Apr 2015 03:49:13 GMT
Content-Type: text/html
Content-Length: 0
Last-Modified: Sun, 04 Jan 2015 10:43:27 GMT
Connection: close
Accept-Ranges: bytes


POST /qconf.php HTTP/1.1
User-Agent: Post_Multipart
Host: tconf.cloud.360safe.com
Accept: */*
Pragma: no-cache
X-360-Cloud-Security-Desc: Scan Suspicious File
x-360-ver: 4
Content-Length: 68
Content-Type: application/x-www-form-urlencoded

....../.....1...IX.h....i...........AT...-.4.*.....u.........}..2.3
HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Thu, 23 Apr 2015 03:52:04 GMT
Content-Type: text/plain
Content-Length: 36
Connection: close
Vary: Accept-Encoding
......B.pc....;.zE.2.6.V.lN...C.......


GET /qm/0cd47f5d563ba06a1e44716398931a08_4dec213c03a525d652460c0d5181cd45_4375cc87f7432f2774c519a50f5074df_e6f7ea0625257466991d27e0b8ac71cd_9e5615703c195167788ea46b1ed76600_3572385f0a757d33e2a9ee99a763834e_d7bee05e090c87a6b33bc2b8c77da29d_ae75251d6b6fe765d3979069dff3fbbd_b9dd248083413c0a205ba1803cf1710b_f7382d6e2985358f3ab826c871f5d968.html?lang=en HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)
Host: q.patch.360safe.com
Accept: */*
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: nginx/1.2.9
Date: Thu, 23 Apr 2015 03:50:50 GMT
Content-Type: text/xml
Content-Length: 3923
Connection: close
<?xml version="1.0" encoding="utf-8"?><xml><url md5="0c
d47f5d563ba06a1e44716398931a08"><link>pdown://hXXp://qh.dlser
vice.microsoft.com/download/D/E/D/DED978C0-ED29-4240-9DCE-038107D70142
/Windows6.1-KB2868038-x64.msu;hXXp://dl.patch.360safe.com/leak/win7/Wi
ndows6.1-KB2868038-x64.msu|b9=1|b3=0cd47f5d563ba06a1e44716398931a08|p2
=3f5f29645c1123bd49e89095152be113c3adc07d|b2=415822|h3=60|h7=3|p4=3600
|b5=vulnerability fix</link></url><url md5="4dec213c03a
525d652460c0d5181cd45"><link>pdown://hXXp://qh.dlservice.micr
osoft.com/download/B/9/6/B96CA2A3-6D3D-4089-AB09-69A383ACACF5/Windows6
.1-KB2862152-x64.msu;hXXp://dl.patch.360safe.com/leak/win7/Windows6.1-
KB2862152-x64.msu|b9=1|b3=4dec213c03a525d652460c0d5181cd45|p2=9d9357cf
1bac89acc0aaed880e8bb8ceeff2d82c|b2=1226216|h3=60|h7=7|p4=7200|b5=vuln
erability fix</link></url><url md5="4375cc87f7432f2774c
519a50f5074df"><link>pdown://hXXp://qh.dlservice.microsoft.co
m/download/8/6/7/867F988B-F418-4E8A-9CAD-0373A56FC9E2/Windows6.1-KB286
8626-x64.msu;hXXp://dl.patch.360safe.com/leak/win7/Windows6.1-KB286862
6-x64.msu|b9=1|b3=4375cc87f7432f2774c519a50f5074df|p2=78f3fc29be51c28a
a699190e8caa2252b7a1b836|b2=2169972|h3=60|h7=7|p4=7200|b5=vulnerabilit
y fix</link></url><url md5="e6f7ea0625257466991d27e0b8a
c71cd"><link>pdown://hXXp://qh.dlservice.microsoft.com/downlo
ad/7/4/D/74D7C7A7-1D28-48D2-AF3B-BCCB9DFB75CE/Windows6.1-KB2868725-x64
.msu;hXXp://dl.patch.360safe.com/leak/win7/Windows6.1-KB2868725-x6

<<< skipped >>>

POST /qconf.php HTTP/1.1
User-Agent: Post_Multipart
Host: tconf.cloud.360safe.com
Accept: */*
Pragma: no-cache
X-360-Cloud-Security-Desc: Scan Suspicious File
x-360-ver: 4
Content-Length: 68
Content-Type: application/x-www-form-urlencoded

....../.....1...IX.h....i...........AT...-.4.*.....u.........}..2.3
HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Thu, 23 Apr 2015 03:50:47 GMT
Content-Type: text/plain
Content-Length: 508
Connection: close
Vary: Accept-Encoding
.......6.S...../....jQc.'d....[.M..*..$..n.........t|...V..........u..
.>....p....(...w..@f..`.~..?.R5-.]..(..`.b.[bw....2.b=X...&.G...7Z.
..d.H.....F.:v.....yo........ ...b..P.}-...d.Pz.w.b..<.]un![.pJ...@
[email protected].,..Bz....h LQ...m.O..H(.e....6..L.0.....y.tP.J... p..I..:.<
^.G..hnG...{eK.Aj.....o...."V...Pe[%...|7z.....:[email protected]..)....
.......q .x.;.g6$../.\.e..."....)|.`w........s.....W.\16=......-.....n
lx...7q.......#[email protected](6V .w.D?4...VZG.....m1...y
.#..t..gx....R}C.f4.Y.v.d....


POST /cloudquery.php HTTP/1.1
User-Agent: Post_Multipart
Host: 54.76.137.169
Accept: */*
Pragma: no-cache
X-360-Cloud-Security-Desc: Scan Suspicious File
x-360-ver: 4
Content-Length: 1058
Content-Type: multipart/form-data; boundary=----------------------------349cf2984a14

------------------------------349cf2984a14
Content-Disposition: form-data; name="m"

...Bs.....|;.\~...u..$.S'|/.....=>.%.^..p|K.....\.d...RR....>n^G3I..f..1.t.'.|.x....8s..[.}/@..?B..5l<..N.:9.4=:.v..d.(^.hsTm.....|......7...:~I...D.<..X @.1.E.x..U.N.x...|.,../...?........l..Q:..v-..]._..<.A
-..........5.HH LM..U.......Lz<v.....:...5Q/...^...O.X.oN
h..1..:.6..,{
M.NV. x.(..c..n.......3......4....o.6W...N?,..}.......!.t. ...M.......h6......q
..q..wb~E#i....zV.5...&...KP...R..$t.d..VC..........W..e...l.......(.$.~"..U.....*...^.*x.j.......(}[email protected]......\......Y..@^.6.u.g.{*.b.S;.j...8.y#*$X7....=[.......,...r.Y...c....51....!.bs.8.j.. ...)..oJ...-qE....,O..Z'jz...P.M!..3._~.kwkZ......?_(l7..`0....i....{..........-Z3|{..#Y..Z..y..Fe.26l.w....WF.e(...-.dN..o..
.0..{.u...c.&...[9/I..!G....P.V.....H.q5.....A.m.Bw.....'k.......$...bl..[W..:.2'3.....A..:.J.o...
..W7.....@!h'.*..D..)...({.v..U.V.)U....rQU%..Z..#:.#...9.....El.I...`....a..cl....-a5..ch,Mp8Y..{0H\[...E..1K..
------------------------------349cf2984a14--

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Thu, 23 Apr 2015 03:52:05 GMT
Content-Type: text/plain
Content-Length: 297
Connection: close
Vary: Accept-Encoding
....Bs......P.-Z...A.K..q..>....Hb..l......).[..2C~.I..&n.........q
[email protected]%E.w.e.h....<.R...T.R.......T...P...T.W...P.....P
.R...P.S.S.....S.....W.R.....S...W...T.S.?...................?.?w.:.5.
.Y.E.Z...Y.B.F.Y.S.E..w./.).z...:.w.....w.-.*.z...:.q.....v.....z./...
v.6.3.u...(.q..?.?.?.;...


POST /cloudquery.php HTTP/1.1
User-Agent: Post_Multipart
Host: 104.192.108.116
Accept: */*
Pragma: no-cache
X-360-Cloud-Security-Desc: Scan Suspicious File
x-360-ver: 4
Content-Length: 410
Content-Type: multipart/form-data; boundary=----------------------------f4eba8e9cbe1

------------------------------f4eba8e9cbe1
Content-Disposition: form-data; name="m"

...Au.....7..........Um...3k...B.1F.Bb.8.....Uwn.{uH/..<...."Z.....0.b.....'......?,H..eb....[....GR.}.g....K...eN.j.q...A/.l..D.B...o...o./..d. Gk.l.x.....>6..=N..`Y.F....yV.B..(..xc..........
D.....Q..o......p....i.yA..=E '.M.$1V..........9..G_:......s8...^2.....V)_..X
------------------------------f4eba8e9cbe1--

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Thu, 23 Apr 2015 03:50:47 GMT
Content-Type: text/plain
Content-Length: 181
Connection: close
Vary: Accept-Encoding
....Au......PVC%...R.........u.....v.*Y..w.*b\.....Z...!.=..5<...&m
.=..h......B..................<.R..................................
.....?.?.?.?.?.?.?.~.L.[...\.....L.Q...?.?.?.;...


GET /ru//Directx_9.10.11.exe HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: download.softobase.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Thu, 23 Apr 2015 03:48:26 GMT
Content-Type: application/octet-stream
Content-Length: 100340480
Last-Modified: Wed, 05 Sep 2012 12:37:40 GMT
Connection: keep-alive
ETag: "50474794-5fb1300"
Access-Control-Allow-Origin: *
Accept-Ranges: bytes
MZP.....................@.............................................
..!..L.!..This program must be run under Win32..$7....................
......................................................................
..............................................PE..L....^B*............
................d.............@.......................................
[email protected].... ...Z......................
d.....................................................................
..............CODE................................ ..`DATA............
....................@...BSS......................................idata
[email protected]................................
[email protected].................
[email protected]... ...\[email protected]..
[email protected]..............................................
......................................................................
[email protected]............@...
[email protected].@.........,[email protected].@.<.@.@[email protected]
[email protected]@.,[email protected]@..TObject.% .A....%..A....%..A....%..A....%..A....%..A..
..%,.A....%..A....%..A....%..A....%..A....%..A....%<.A....%8.A....%
4.A....%..A....%H.A....%D.A....%..A....%..A...S........T......D$,.t...
\$0....D[....%..A....%..A....%..A....%..A....%..A....%..A....%..A....%
..A...S......A..;.uYhD...j.......D$..|$..u.3...$.P.D$.....A....D$....A
[email protected]$..D$......D$...$..$...

<<< skipped >>>

GET /ru/360TotalSecurity_Rus_Setup_0001.exe HTTP/1.1

User-Agent: NSIS_Inetc (Mozilla)
Host: download.softobase.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: nginx/1.6.2
Date: Thu, 23 Apr 2015 03:48:37 GMT
Content-Type: application/octet-stream
Content-Length: 33607288
Last-Modified: Thu, 09 Apr 2015 02:28:49 GMT
Connection: keep-alive
ETag: "5525e3e1-200ce78"
Access-Control-Allow-Origin: *
Accept-Ranges: bytes
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$............km..km.
.km..$...km......km.....gkm..9...km......km......km......km..kl..im...
...km..9...km......km.Rich.km.........PE..L...cH.U....................
........ld............@..........................@.......*....@.......
..............................T.......tK................... ...... ...
....................x.......0...@...............@.......@.............
.......text............................... ..`.rdata..~1.......2......
............@[email protected][email protected]..........
[email protected]..............@[email protected]
oc....... [email protected]..................................
......................................................................
......................................................................
......................................................................
..............................................X.I...........V....X.I..
.....D$..t.V..........^................L$...v$.D$..T$.V........W......
....f.._..^..D$..................D$..L$..T$.V.t$.PQRV..........^......
..........j.h.aI.d.....PQV.`.L.3.P.D$.d........t$......3..D$..N.....I.
j..A..A.....P.A..D$$P........L$.d......Y^............D$.VP...........I
...^..........V......I..~$.r..F.P.X......3..F$.....F .F...^.d.........
........j.h.aI.d.....PQV.`.L.3.P.D$.d........t$..K...3..D$..N...`?J.j.
.A..A.....P.A..D$$P........L$.d......Y^............y$.r..A...A....

<<< skipped >>>

POST /qconf.php HTTP/1.1
User-Agent: Post_Multipart
Host: tconf.cloud.360safe.com
Accept: */*
Pragma: no-cache
X-360-Cloud-Security-Desc: Scan Suspicious File
x-360-ver: 4
Content-Length: 68
Content-Type: application/x-www-form-urlencoded

....../.....1...IX.h....i...........AT...-.4.*.....u.........}..2.3
HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Thu, 23 Apr 2015 03:52:04 GMT
Content-Type: text/plain
Content-Length: 36
Connection: close
Vary: Accept-Encoding
......B.pc....;.zE.2.6.V.lN...C.......


POST /qconf.php HTTP/1.1
User-Agent: Post_Multipart
Host: tconf.cloud.360safe.com
Accept: */*
Pragma: no-cache
X-360-Cloud-Security-Desc: Scan Suspicious File
x-360-ver: 4
Content-Length: 68
Content-Type: application/x-www-form-urlencoded

....../.....f.....)7.)..l.........0S.bb..o....-..d2S..]6o..|.C.M.u
HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Thu, 23 Apr 2015 03:50:47 GMT
Content-Type: text/plain
Content-Length: 508
Connection: close
Vary: Accept-Encoding
.........{........L.;.c%.|...vK.......czWj.....[[email protected].]~.,.....K.
..U.5U.?...}....M.d../.Fd*s$y..0..1}.H4..L....fS..n.UIb.L 9&......PK..
....$.v.......,.vM.....)[email protected]....;.....9Q...
#.x.t..5..W...D.\..)......m.%.>.......D..x...%_M.N...qD..G`.T...rB.
.8_..............f~k.......Rs@...._d...6.....x.O(By.!.... ......m.c|c.
.\.Zx..>.(,.).n6...z.;T?xq.....7.....A.....7.V....`.il.`F`..-;X..2.
.>Rw.e.....\.#E9.....QW.?..1..y3z{..m.....*@...M...c5.>.zp..i.\.
.f..._..d.....z4.:.W...^.$......


GET /qm/e6e862c79dc156d48370cc4f389eee28_58d21421ec10d7ec9ef08ce78a988b1e_8f166cecb19c47f41c45ed863de7b0d1_896ddf703e6e0c17d1fbf3fd2b467bcb_5ab2456234592215792583ee5ef9e433_74c7a7cd928fcedef39ccee1474ddb37_2e223e0dcce1b2ac068778ee37521487_90590ddf1137009e5d306a8fcbb9f5f5_a53cf4ce8dcc65dbd195aaf5769cd693_79a73367e8f15c93cdce7773eefc808b.html?lang=en HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)
Host: q.patch.360safe.com
Accept: */*
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: nginx/1.2.9
Date: Thu, 23 Apr 2015 03:50:50 GMT
Content-Type: text/xml
Content-Length: 3914
Connection: close
<?xml version="1.0" encoding="utf-8"?><xml><url md5="e6
e862c79dc156d48370cc4f389eee28"><link>pdown://hXXp://qh.dlser
vice.microsoft.com/download/7/D/C/7DC58284-AFC4-4122-A89D-F1E8B299C456
/Windows6.1-KB2847927-x64.msu;hXXp://dl.patch.360safe.com/leak/win7/Wi
ndows6.1-KB2847927-x64.msu|b9=1|b3=e6e862c79dc156d48370cc4f389eee28|p2
=88356fddfec452ed7f91728f52b20eaeb2975a28|b2=1668392|h3=60|h7=7|p4=720
0|b5=vulnerability fix</link></url><url md5="58d21421ec
10d7ec9ef08ce78a988b1e"><link>pdown://hXXp://qh.dlservice.mic
rosoft.com/download/E/8/2/E8245CAE-CA46-42AA-BA0B-F3AA49C58DBA/Windows
6.1-KB2862966-x64.msu;hXXp://dl.patch.360safe.com/leak/win7/Windows6.1
-KB2862966-x64.msu|b9=1|b3=58d21421ec10d7ec9ef08ce78a988b1e|p2=37e84cc
30f4d5aa824d4ea4e7fe8162873fa8753|b2=2332207|h3=60|h7=7|p4=7200|b5=vul
nerability fix</link></url><url md5="8f166cecb19c47f41c
45ed863de7b0d1"><link>pdown://hXXp://qh.dlservice.microsoft.c
om/download/5/E/4/5E40CC10-B3BA-4344-ACE9-C321381C6E06/NDP40-KB2840628
-v2-x64.exe;hXXp://dl.patch.360safe.com/leak/ty/NDP40-KB2840628-v2-x64
.exe|b9=1|b3=8f166cecb19c47f41c45ed863de7b0d1|p2=45b0d7127e349cd5b608f
dfa62dd23c64e3f7c01|b2=18157704|h3=60|h7=7|p4=7200|b5=vulnerability fi
x</link></url><url md5="896ddf703e6e0c17d1fbf3fd2b467bc
b"><link>pdown://hXXp://qh.dlservice.microsoft.com/download/D
/C/C/DCCDA3B5-a8fcbb9f5f5"><link>pdown://hXXp://qh.dlservice.
microsoft.com/download/B/4/B/B4B92AF3-413E-4BCC-93A9-B78E02793B3F/

<<< skipped >>>

GET /collect?v=1&tid=UA-54698389-1&cid=4001577&t=pageview&dp=/softobase_wrapper_started HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: VVV.google-analytics.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Pragma: no-cache
Expires: Mon, 07 Aug 1995 23:30:00 GMT
Access-Control-Allow-Origin: *
Last-Modified: Sun, 17 May 1998 03:00:00 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Date: Thu, 16 Apr 2015 23:35:36 GMT
Server: Golfe2
Content-Length: 35
Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
Age: 533547
Alternate-Protocol: 80:quic,p=1
GIF89a.............,...........D..;HTTP/1.1 200 OK..Pragma: no-cache..
Expires: Mon, 07 Aug 1995 23:30:00 GMT..Access-Control-Allow-Origin: *
..Last-Modified: Sun, 17 May 1998 03:00:00 GMT..X-Content-Type-Options
: nosniff..Content-Type: image/gif..Date: Thu, 16 Apr 2015 23:35:36 GM
T..Server: Golfe2..Content-Length: 35..Cache-Control: private, no-cach
e, no-cache=Set-Cookie, proxy-revalidate..Age: 533547..Alternate-Proto
col: 80:quic,p=1..GIF89a.............,...........D..;
....



GET /collect?v=1&tid=UA-54698389-1&cid=4001577&t=pageview&dp=/softobase_wrapper_second_screen HTTP/1.1

User-Agent: NSIS_Inetc (Mozilla)
Host: VVV.google-analytics.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Pragma: no-cache
Expires: Mon, 07 Aug 1995 23:30:00 GMT
Access-Control-Allow-Origin: *
Last-Modified: Sun, 17 May 1998 03:00:00 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Date: Thu, 16 Apr 2015 23:35:36 GMT
Server: Golfe2
Content-Length: 35
Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
Age: 533563
Alternate-Protocol: 80:quic,p=1
GIF89a.............,...........D..;HTTP/1.1 200 OK..Pragma: no-cache..
Expires: Mon, 07 Aug 1995 23:30:00 GMT..Access-Control-Allow-Origin: *
..Last-Modified: Sun, 17 May 1998 03:00:00 GMT..X-Content-Type-Options
: nosniff..Content-Type: image/gif..Date: Thu, 16 Apr 2015 23:35:36 GM
T..Server: Golfe2..Content-Length: 35..Cache-Control: private, no-cach
e, no-cache=Set-Cookie, proxy-revalidate..Age: 533563..Alternate-Proto
col: 80:quic,p=1..GIF89a.............,...........D..;
....



GET /collect?v=1&tid=UA-54698389-1&cid=4001577&t=pageview&dp=/softobase_wrapper_offer_yes HTTP/1.1

User-Agent: NSIS_Inetc (Mozilla)
Host: VVV.google-analytics.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Pragma: no-cache
Expires: Mon, 07 Aug 1995 23:30:00 GMT
Access-Control-Allow-Origin: *
Last-Modified: Sun, 17 May 1998 03:00:00 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Date: Thu, 16 Apr 2015 23:35:36 GMT
Server: Golfe2
Content-Length: 35
Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
Age: 533570
Alternate-Protocol: 80:quic,p=1
GIF89a.............,...........D..;HTTP/1.1 200 OK..Pragma: no-cache..
Expires: Mon, 07 Aug 1995 23:30:00 GMT..Access-Control-Allow-Origin: *
..Last-Modified: Sun, 17 May 1998 03:00:00 GMT..X-Content-Type-Options
: nosniff..Content-Type: image/gif..Date: Thu, 16 Apr 2015 23:35:36 GM
T..Server: Golfe2..Content-Length: 35..Cache-Control: private, no-cach
e, no-cache=Set-Cookie, proxy-revalidate..Age: 533570..Alternate-Proto
col: 80:quic,p=1..GIF89a.............,...........D..;..


GET /qm/b0586730837afd39a4c6ffc29b8b45d1_0e20c81dbd120c83183c177cfc89a0cd_a8a404644af66d5edc3ddbf197bfa603_a0b0c1d9e2b22a2b18db00adfaf188b8_c60679ca1168c44c164f07248f20e5bc_729e30d5c7cc3017124cc6b758e3c18f_f2a5f9f80981ac71a5fed8321d0f97ed_771d63b6be5618a5a7348c591a6eaa8b_e6b21c42019a616ba330879cab91b21f_e2cbb6402ac6b292f2e8f47364289cee.html?lang=en HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)
Host: q.patch.360safe.com
Accept: */*
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: nginx/1.2.9
Date: Thu, 23 Apr 2015 03:50:49 GMT
Content-Type: text/xml
Content-Length: 49
Connection: close
<?xml version="1.0" encoding="utf-8"?><xml></xml>..


GET /qm/c6cb4f5ac0255d2baf41678f26cd50cc_e9ae86455b04bf504ecbd7c7944b9dbe_7fdde18475dc134cace116c202eee2d4_351aaa705ad2bfe61d737e6c2ff59cb7_8e3f695edfee356c0ce44d45973e6e3d_10a33cc11d32c95ebe3dc53ebb04ca53_9bddd8965f0fb4f43008698df4c88648_64adc54c5e594f2dea16b70cc30c60e3_639d29e60ac1265ee915507a58eee764_619737941c6f039502af0ca22aef89a4.html?lang=en HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)
Host: q.patch.360safe.com
Accept: */*
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: nginx/1.2.9
Date: Thu, 23 Apr 2015 03:50:49 GMT
Content-Type: text/xml
Content-Length: 2005
Connection: close
<?xml version="1.0" encoding="utf-8"?><xml><url md5="c6
cb4f5ac0255d2baf41678f26cd50cc"><link>pdown://hXXp://qh.dlser
vice.microsoft.com/download/D/4/3/D43DD544-D69D-475B-9769-82BEDA1EC706
/IE10-Windows6.1-KB2909210-x64.msu;hXXp://dl.patch.360safe.com/leak/wi
n7/IE10-Windows6.1-KB2909210-x64.msu|b9=1|b3=c6cb4f5ac0255d2baf41678f2
6cd50cc|p2=b565da99f504e4a622a611b9740beabe11aaddf7|b2=1001760|h3=60|h
7=3|p4=3600|b5=vulnerability fix</link></url><url md5="
e9ae86455b04bf504ecbd7c7944b9dbe"><link>pdown://hXXp://qh.dls
ervice.microsoft.com/download/A/2/6/A26B576B-6573-499D-9DB0-31C42FC2A1
DC/Windows6.1-KB2911501-x64.msu;hXXp://dl.patch.360safe.com/leak/win7/
Windows6.1-KB2911501-x64.msu|b9=1|b3=e9ae86455b04bf504ecbd7c7944b9dbe|
p2=156852756d587f7f27aa8c9f979cb71b69dc2bd2|b2=796370|h3=60|h7=3|p4=36
00|b5=vulnerability fix</link></url><url md5="7fdde1847
5dc134cace116c202eee2d4"><link>pdown://hXXp://qh.dlservice.mi
crosoft.com/download/A/E/D/AEDDD34E-EB10-4D54-9B68-250667EF7A8B/Window
s6.1-KB2912390-x64.msu;hXXp://dl.patch.360safe.com/leak/win7/Windows6.
1-KB2912390-x64.msu|b9=1|b3=7fdde18475dc134cace116c202eee2d4|p2=203a1f
438914f5f26ec02e0672a1585db95a924f|b2=3153869|h3=60|h7=7|p4=7200|b5=vu
lnerability fix</link></url><url md5="351aaa705ad2bfe61
d737e6c2ff59cb7"><link>pdown://hXXp://qh.dlservice.microsoft.
com/download/C/7/7/C77BDB45-54E4-485E-82EB-2F424113AA12/Windows6.1-KB2
871997-v2-x64.msu;hXXp://dl.patch.360safe.com/leak/win7/Windows6.1

<<< skipped >>>

POST /cloudquery.php HTTP/1.1
Content-Type: multipart/form-data; boundary=---------------------------riB5lWb2zKNzPDqv52lk
Accept-Encoding: gzip
Host: 104.192.108.116
Content-Length: 424
Pragma: no-cache
Connection: Keep-Alive
x-360-ver: 4

-----------------------------riB5lWb2zKNzPDqv52lk
Content-Disposition: form-data; name="m"

...Au.....7..........Um...3k...B.1F.Bb.8.....Uwn.{uH/..<...."Z.....0.b.....'......?,H..eb....[....GR.}.g....K...eN.j.q...A/.l..D.B...o...o./..d. Gk.l.x.....>6..=N..`Y.F....yV.B..(..xc..........
D.....Q..o......p....i.yA..=E '.M.$1V..........9..G_:......s8...^2.....V)_..X
-----------------------------riB5lWb2zKNzPDqv52lk--

HTTP/1.1 200 OK
Server: nginx/0.6.39
Date: Thu, 23 Apr 2015 03:50:47 GMT
Content-Type: text/plain
Transfer-Encoding: chunked
Connection: close
Vary: Accept-Encoding
Content-Encoding: gzip
a..............a4...baX.X.... .....z..h..e....?..w....O..IiE../..J....
..]Q"\..;l..2.....Z......?.......}../.f/..g.......f.o.?h9."6<.}..l.
E...../............v7.#.=V ;p=.l................0..


The Trojan connects to the servers at the folowing location(s):

DXSETUP.exe_1376:

.text
`.data
.rsrc
@.reloc
%s %s: %s: (null)
%s %s: %s: %s
%s%s%s
Logs\DirectX.log
DXSETUP_DPF(): GetWindowsDirectory() failed.
Logs\DXError.log
%s(): %s
DXSError(): FormatMessage() failed, error = %d.
(0x%x)
%s(): %s failed.
%s(): %s failed, error = %d.
%s(): %s failed, error = 0x%x.
module: %s(%s), file: %s, line: %d, function: %s
[%s %s]
/windowsupdate
Unable to load %s.
e:\bt\193462\setup\deliverables\dsetup\inc\dsinline.h
Module: %s, Function: %s
advpack.dll
GetFileVersionInfoBlock(): %s does not have version information.
GetFileVersionInfoBlock(): Unable to get FileVersionInfoSize, file: %s, reason: %d.
RegCloseKey()
e:\bt\193462\setup\deliverables\dxsetup\dxsetup.cpp
RegCreateKeyEx()
RegOpenKeyEx()
RegCloseKey().
Unable to create path string, %s%s.
DXSetup: GetRequiredDiskSpaceFromLog(): GetWindowsDirectory() failed.
String ID: %d
MsgBox
Unable to find %s
Unable to find %s.
dsetup.dll
dsetup32.dll
\dsetup32.dll
\dsetup.dll
Unable to copy string %s.
CommandLine: %s
dxntunp.inf
directx.inf
dxnt.cab
directx.cab
Module: dsetup.dll
This version of DirectX is not compatible with WindowsNT 4.0.
Invalid command line switch, using command ID %d without flat image.
DSetupCallback(): Phase = %d, Steps = %d
e:\bt\193462\setup\deliverables\dxsetup\psheets.cpp
e:\bt\193462\setup\deliverables\dxsetup\psheets.h
\ntkrnlpa.exe
comctl32.dll version: %d.d.d.d
\comctl32.dll
Win95(): This platform is not supported.
e:\bt\193462\setup\deliverables\dxsetup\utils.cpp
GetProcessWindowStation
operator
DXSETUP.pdb
t%SPh
u9SShp
u.Sj0jr
RegCloseKey
RegCreateKeyExA
RegOpenKeyExA
ADVAPI32.dll
GetWindowsDirectoryA
KERNEL32.dll
GDI32.dll
EnumWindows
ExitWindowsEx
GetAsyncKeyState
USER32.dll
VERSION.dll
COMCTL32.dll
GetCPInfo
GetProcessHeap
C:\Windows\Logs\DirectX.log
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DXSETUP.exe
k2v_.mX0q[,hT9
|/oZ/nY-kV.mX0q[/oZ0r\2u_2v_5}e6
)`N*dQ,gS/nY/nY/oZ/oZ/nY0q[-jV-kV.mXO
?3&YH0q[0q[0q[/nY/nY.mX.mX.mX-jV-jV-kV-kV*dQI
|||}}}~~~
|||^^^{{{
version="1.0.0.0"
name="Microsoft.DirectX.Setup"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
2(2-272_2
4!4)4/444:4
0$0,0`0|0
> >$>(>,>0>4>8><>@>
mscoree.dll
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
KERNEL32.DLL
WUSER32.DLL
hXXp://VVV.BetaPlace.com
Windows(R)!
stup k webov
mu serveru hXXp://VVV.BetaPlace.com, budete muset syst
m Windows(R) znovu nainstalovat.
ssen Windows(R) erneut installieren, wenn Sie
gen, und auf die Website hXXp://VVV.BetaPlace.com zugreifen, wenn die Kennung abl
You will need to re-install Windows(R) if you do not have a valid DirectX BetaID and access to hXXp://VVV.BetaPlace.com website when it expires!
que volver a instalar Windows(R) si no tiene un Id. v
que visitar el sitio Web hXXp://VVV.BetaPlace.com cuando el Id. haya caducado.
Vous devrez installer Windows(R)
hXXp://VVV.BetaPlace.com lorsque l'identificateur aura expir
necessario reinstallare Windows(R) se alla scadenza non si dispone di un BetaID valido per DirectX e di accesso al sito Web hXXp://VVV.BetaPlace.com
Windows(R)
Windows(R)
U dient Windows(r) opnieuw te installeren als u geen geldige b
ta-id voor DirectX en toegang tot de website hXXp://VVV.betaplace.com hebt wanneer DirectX verloopt.
Po wygasnieciu waznosci tej wersji trzeba bedzie ponownie zainstalowac system Windows(R) w wypadku braku prawidlowego identyfikatora Beta programu DirectX i dostepu do witryny hXXp://VVV.BetaPlace.com w sieci Web!
de reinstalar o Windows(R) se n
lida e acessar hXXp://VVV.BetaPlace.com quando ela expirar!
Windows(R)
hXXp://VVV.BetaPlace.com.
ste installera om Windows(R) om du inte har ett giltigt DirectX BetaID och
tkomst till webbplatsen hXXp://VVV.BetaPlace.com n
effettuato l'aggiornamento. L'operazione pu
o em tempo de execu
procurar componentes de tempo de execu
The DirectX setup wizard guides you through installation of DirectX Runtime Components. Please read the following license agreement. Press the PAGE DOWN key to see the rest of the agreement. You must accept the agreement to continue the setup.
o dos componentes de tempo de execu
Sla uw werk op en sluit alle toepassingen voordat u verder gaat.
Windows NT 4.0
Windows
mem Windows NT 4.0.lInstalacn
mu WIndows.<Rozhran
pro instalaci..Zdrojov
..Zdrojov
ne %d MB. M
=DirectX funktioniert ist mit Windows NT 4.0 nicht kompatibel.
r die Installation von DirectX neu starten. Klicken Sie auf "OK", um den Computer jetzt neu zu starten..DirectX-Setup wurde erfolgreich abgeschlossen.YDiese DirectX-Version ist mit der zurzeit installierten Windows-Version nicht kompatibel.GEine ben
hr %d MB ben
<This version of DirectX is not compatible with WindowsNT 4.0EDirectX setup needs to restart your machine, press OK to restart now.)DirectX setup has completed successfully.ZThis version of DirectX is not compatible with the version of Windows currently installed.9DirectX could not find a file necessary for installation.!DirectX source file is incorrect.!DirectX source file is incorrect.%DirectX did not copy a required file.
DirectX needs approximately %dMB. You can increase available disk space by uninstalling applications or by deleting unneeded files.
n de DirectX no es compatible con Windows NT 4.0eLa instalaci
xito.YEsta versi
n de Windows instalada actualmente.CDirectX no pudo encontrar un archivo necesario para la instalaci
DirectX necesita aproximadamente %d MB. Puede liberar espacio en disco desinstalando aplicaciones o eliminando archivos que no necesite.
ACette version de DirectX n'est pas compatible avec Windows
e correctement.`Cette version de DirectX n'est pas compatible avec la version de Windows actuellement install
e.BDirectX n'a pas pu trouver un fichier n
cessite environ %d Mo. Vous pouvez lib
compatibile con Windows NT 4.0.D
compatibile con la versione di Windows attualmente installata.;Impossibile trovare un file necessario per l'installazione.%File origine di DirectX non corretto.%File origine di DirectX non corretto.'Impossibile copiare un file necessario.
DirectX richiede circa %d MB. Per liberare spazio su disco, disinstallare alcune applicazioni o eliminare i file non necessari.
WindowsNT 4.0
=Deze versie van DirectX is niet compatibel met Windows NT 4.0oDirectX is pas juist ge
nstalleerd nadat het systeem opnieuw is opgestart. Klik op OK om opnieuw op te starten.'De installatie van DirectX is voltooid.VDe huidige DirectX-versie is niet compatibel met de ge
nstalleerde versie van Windows.ADirectX kan een voor de installatie benodigd bestand niet vinden."DirectX-bronbestand is niet juist."DirectX-bronbestand is niet juist.2DirectX heeft een vereist bestand niet gekopieerd.
DirectX heeft ongeveer %d MB nodig. U kunt de beschikbare schijfruimte vergroten door niet langer benodigde toepassingen of bestanden te verwijderen.
?Ta wersja programu DirectX nie jest zgodna z systemem WindowsNT_Instalator DirectX musi zrestartowac komputer. Aby zrestartowac go teraz, nacisnij przycisk OK./Instalacja DirectX zostala ukonczona pomyslnie.^Ta wersja programu DirectX nie jest zgodna z wersja aktualnie zainstalowanego systemu Windows.CInterfejs DirectX nie moze znalezc pliku potrzebnego do instalacji.'Plik zr
Program DirectX wymaga okolo %d MB. Mozesz zwiekszyc dostepne miejsce na dysku, odinstalowujac aplikacje lub usuwajac niepotrzebne pliki.
vel com o WindowsNT 4.0hO Programa de Instala
xito.aEsta vers
o do sistema operacional atualmente instalado.EO DirectX n
O DirectX precisa de aproximadamente %dMB. Voc
Windows NT 4.0
Windows.8DirectX:
r inte kompatibel med Windows NT 4.0hInstallationsprogrammet f
rdig.XDen h
r inte kompatibel med den Windows-version som
r installerad.DDet gick inte att hitta en n
r %d MB. Du kan
WindowsNT 4.0
DXError.log
DirectX.log
(ManagedDX.CAB)
.NET Framework
.NET Framework
soubor INF.DInstalacn
to chybe naleznete v souborech DXError.log a DirectX.log ve slo
ce Windows.DRozhran
mu Windows NT podporov
operacn
tko Storno.HRozhran
mu Windows NT predinstalov
treba znovu instalovat.wAktu
mu.qTyp procesoru nen
.mTento komprimovan
DirectX (ManagedDX.CAB) v distribucn
na platforma .NET Framework. Nainstalujte platformu .NET Framework a potom znovu spustte instalaci rozhran
DirectX.ZStahov
Weitere Informationen zum Ermitteln des Problems finden Sie in den Dateien "DXError.log" und "DirectX.log" im Ordner "Windows".7DirectX3D wird von dieser NT-Version nicht unterst
her.yDie Kabinettdatei f
r die Managed DirectX-Komponente (ManagedDX.CAB) ist im DirectX-Verzeichnis "redist" nicht vorhanden.
r die Managed DirectX-Komponente muss .NET Framework installiert werden, bevor DirectX installiert wird. Installieren Sie .NET Framework, und f
hren Sie dann DirectX-Setup erneut aus.dFehler beim Downloaden einer f
Please refer to DXError.log and DirectX.log in your Windows folder to determine problem..This version on NT does not support DirectX3D.&An unknown operating system was found.
User hit the cancel key.3DirectX was not preinstalled on this version on NT.rDirectX setup has determined that a newer version of DirectX is already installed.
Please logon again as an Administrator or contact your PC Administrator.qProcessor type is unsupported by DirectX.
DirectX supports Pentium-compatible and K6 class processors or higher.dThe Managed DirectX component cab file (ManagedDX.CAB) is missing from the DirectX redist directory.
Managed DirectX component requires .NET Framework to be installed before DirectX. Please install .NET Framework and then run DirectX setup again.MDownloading a file necessary for installation failed. Please run setup again.
A cabinet file necessary for installation cannot be trusted. Please verify the Cryptographic Services are enabled and the cabinet file certificate is valid.
un archivo .inf necesario.DLa instalaci
Vea el archivo de registro DXError.log y DirectX.log en la carpeta Windows para determinar el problema.'Esta versi
un sistema operativo desconocido.&El usuario presion
DirectX es compatible con procesadores K6, compatibles con Pentium, o superiores.|No se encuentra el archivo CAB de componentes Managed DirectX (ManagedDX.CAB) en el directorio de redistribuci
El componente Managed DirectX necesita que .NET Framework se instale antes que DirectX. Instale .NET Framework y vuelva a ejecutar el programa de instalaci
n de DirectX.jError al descargar un archivo necesario para la instalaci
Un archivo .CAB necesario para la instalaci
lido el certificado del archivo .CAB.
ULe programme d'installation de DirectX n'a pas pu trouver un fichier .inf n
cessaire.ULe programme d'installation de DirectX n'a pas pu localiser un r
Consultez les fichiers DXError.log et DirectX.log situ
s dans le dossier Windows pour d
DirectX prend en charge les processeurs compatibles Pentium et K6 ou plus.sLe fichier CAB des composants Managed DirectX (ManagedDX.CAB) est introuvable dans le r
Le composant Managed DirectX requiert l'installation de .NET Framework avant celle de DirectX. Installez .NET Framework et relancez le programme d'installation de DirectX.jUn fichier n
s et que le certificat du fichier CAB est valide.
Per individuare il problema, vedere i file DXError.log e DirectX.log nella cartella di Windows.1La versione su Windows NT non supporta DirectX3D.*Rilevato un sistema operativo sconosciuto.!Operazione annullata dall'utente.CDirectX non
stato preinstallato su questa versione di Windows NT.
Effettuare nuovamente l'accesso come amministratore o contattare l'amministratore del computer in uso.yTipo di processore non supportato da DirectX.
Sono supportati processori compatibili Pentium e di classe K6 o superiori.cFile cab del componente DirectX gestito (ManagedDX.CAB) mancante dalla directory redist di DirectX.wIl componente gestito DirectX richiede .NET Framework. Installare .NET Framework e ripetere l'installazione di DirectX.pImpossibile scaricare un file necessario per l'installazione. Eseguire nuovamente il programma di installazione.
Un file CAB necessario per l'installazione risulta non attendibile. Verificare che i servizi di crittografia siano abilitati e che il certificato relativo al file CAB sia valido.
Windows
Windows NT
.NET Framework
DirectX.log
Windows NT
.GManaged DirectX
(ManagedDX.CAB)
.xManaged DirectX
. .NET Framework
Raadpleeg DXError.log en DirectX.log in de map Windows om vast te stellen wat het probleem is..Deze versie van NT ondersteunt DirectX3D niet.2Er is een onbekend besturingssysteem aangetroffen.
nstalleerd op deze versie van NT.sDirectX Setup heeft ontdekt dat er al een nieuwere versie van DirectX is ge
DirectX ondersteunt Pentium-compatibele en klasse K6-processors of hoger.cHet cab-bestand met het DirectX-beheeronderdeel (ManagedDX.CAB) ontbreekt in de DirectX redist-map.
.NET Framework moet zijn ge
nstalleerd voordat u het onderdeel Managed DirectX kunt installeren. Installeer .NET Framework en voer vervolgens Setup voor DirectX opnieuw uit.fHet downloaden van een bestand dat voor de installatie vereist is, is mislukt. Voer Setup opnieuw uit.
n of meerdere bestanden door een toepassing zijn geopend. Sluit alle toepassingen af voordat u de installatie van DirectX opnieuw uitvoert.
Een CAB-bestand dat nodig is voor de installatie wordt niet vertrouwd. Controleer of de service Cryptographic Services ingeschakeld is en of het certificaat van het CAB-bestand geldig is.
9Instalator DirectX nie moze znalezc wymaganego pliku inf.=Instalator DirectX nie moze zlokalizowac wymaganego katalogu.tWystapil wewnetrzny blad systemu.
Sprawdz plik DXError.log i DirectX.log w folderze Windows, aby rozpoznac problem.-Ta wersja systemu NT nie obsluguje DirectX3D.&Znaleziono nieznany system operacyjny.$Uzytkownik nacisnal przycisk Anuluj.LInterfejs DirectX nie zostal wstepnie zainstalowany w tej wersji systemu NT.sInstalator DirectX wykryl, ze jest juz zainstalowana nowsza wersja programu DirectX.
Program DirectX obsluguje procesory zgodne z Pentium oraz procesory klasy K6 lub nowsze.\Brak pliku cab skladnika Managed DirectX (ManagedDX.CAB) w katalogu redist programu DirectX.
Skladnik Managed DirectX wymaga zainstalowania architektury .NET Framework przed programem DirectX. Zainstaluj architekture .NET Framework, a nastepnie uruchom ponownie Instalatora programu DirectX.YPobieranie pliku wymaganego do instalacji nie powiodlo sie. Uruchom ponownie instalatora.
Nie mozna zaufac plikowi cabinet wymaganemu dla instalacji. Sprawdz, czy uslugi kryptograficzne sa wlaczone i czy certyfikat pliku cabinet jest prawidlowy.
rio.LO Programa de Instala
ria.lErro interno de sistema.
Consulte DXError.log e DirectX.log na pasta do Windows para determinar o problema..Esta vers
suporte ao DirectX3D.,Sistema operacional desconhecido encontrado.-O usu
o oferece suporte a este tipo de processador. O
DirectX oferece suporte a processadores compat
veis com Pentium ou da classe K6 ou superiores.nO arquivo de instala
o do componente Managed DirectX (ManagedDX.CAB) est
Para ser instalado antes do DirectX, o componente Managed DirectX requer o .NET Framework. Instale o .NET Framework e execute a instala
o do DirectX novamente.lFalha ao fazer o download de um arquivo necess
o. Execute o programa de instala
o em uso por um aplicativo. Feche todos os aplicativos antes de executar a instala
vel. Certifique-se de que os Servi
o habilitados e que o certificado do arquivo de gabinete
Windows. 
.BDirectX:
ndig INF-fil.JInstallationsprogrammet f
ndig katalog.kEtt internt fel uppstod.
Information om felet finns i filen DXError.log och DirectX.log i Windows-mappen..Den h
nt operativsystem hittades.&Anv
r.jProcessortypen st
gre.ZCAB-filen med DirectX-komponenten f
r hanterad kod (ManagedDX.CAB) saknas i redist-mappen.
ver att .NET Framework
r installerat innan du installerar DirectX. Installera .NET Framework och f
r aktiverad och att kabinettfilens certifikat
.DirectX
lo k chybe %d instalacn
DirectX-Setupfehler %d
DirectX setup error %d
%Error %d de la instalaci
n de DirectX.Modificador de la l
#Erreur d'installation de DirectX %d'Option de ligne de commande non valide.
3Errore %d del programma di installazione di DirectX Parametro della riga di comando non valido.
DirectX Setup-fout %d*Ongeldige schakeloptie voor opdrachtregel.
Blad instalatora DirectX: %d,Nieprawidlowy przelacznik wiersza polecenia.
Erro %d na instala
DirectX %d#
Installationsfel %d f
%s kann nicht gefunden werden.
No se encuentra %s
Impossible de trouver %s
Impossibile trovare %s
Kan %s niet vinden
Nie mozna znalezc %s
vel localizar %s
r inte att hitta %s
hXXp://Microsoft.com/DirectX
hXXp://VVV.betaplace.com
te na webov
m serveru hXXp://Microsoft.com/DirectX. Aktualizovanou predprodejn
m serveru hXXp://VVV.betaplace.com.
Diese Vorabversion von DirectX ist bereits abgelaufen. Besuchen Sie hXXp://Microsoft.com/DirectX, um die neueste ver
ffentlichte DirectX-Version zu downloaden, oder besuchen Sie hXXp://VVV.betaplace.com, um die aktuelle Vorabversion zu downloaden.
This pre-release version of DirectX has already expired. Please goto hXXp://Microsoft.com/DirectX to get the latest released version DirectX., or to hXXp://VVV.betaplace.com to get an updated pre-release version.
n preliminar ya ha caducado. Vaya a hXXp://Microsoft.com/DirectX para obtener la versi
s reciente disponible de DirectX o a hXXp://VVV.betaplace.com para obtener una versi
. Visitez le site hXXp://Microsoft.com/DirectX (site en anglais) pour obtenir la derni
e de DirectX, ou le site hXXp://VVV.betaplace.com (site en anglais) pour obtenir une version B
scaduta. Visitare il sito Web hXXp://Microsoft.com/DirectX per ottenere l'ultima versione completa di DirectX o la pagina hXXp://VVV.betaplace.com per ottenere una versione preliminare aggiornata.
hXXp://Microsoft.com/DirectX
hXXp://VVV.betaplace.com
. hXXp://Microsoft.com/DirectX
, hXXp://VVV.betaplace.com
Deze evaluatieversie is reeds verlopen. Ga naar hXXp://Microsoft.com/DirectX voor de meest recente releaseversie van DirectX of ga naar hXXp://VVV.betaplace.com voor een bijgewerkte evaluatieversie.
Waznosc tej wersji wstepnej programu DirectX juz wygasla. Przejdz do witryny hXXp://Microsoft.com/DirectX, aby uzyskac najnowsza z wydanych wersji programu DirectX, lub do witryny hXXp://VVV.betaplace.com, aby uzyskac zaktualizowana wersje wstepna.
expirou. Visite hXXp://Microsoft.com/DirectX para obter a vers
o mais recente do DirectX, ou hXXp://VVV.betaplace.com para obter uma vers
hXXp://Microsoft.com/DirectX,
hXXp://VVV.betaplace.com,
till webbplatsen hXXp://Microsoft.com/DirectX f
mta den senaste officiella versionen av DirectX eller till hXXp://VVV.betaplace.com om du vill h
mto operacn
DirectX SetupZDirectX is not completely installed on your computer. Are you sure you want to quit setup?7This package is not supported on this Operating System.
n?7Este paquete no es compatible con el sistema operativo.&Se cancel
n sea necesario. Esta operaci
Installazione di DirectXFInstallazione di DirectX non completata. Interrompere l'installazione?6Pacchetto non supportato nel sistema operativo in uso.
StatoOAttendere. Il programma di installazione sta completando le seguenti operazioni
in corso la ricerca dei componenti di run-time di DirectX. Se necessario, i componenti verranno aggiornati. L'operazione potrebbe richiedere alcuni minuti...
Instalator programu DirectXpProgram DirectX nie zostal calkowicie zainstalowany na tym komputerze. Czy na pewno chcesz zakonczyc instalacje?;Ten pakiet nie jest obslugiwany w tym systemie operacyjnym.
completamente instalado neste computador. Tem certeza de que deseja sair da instala
suporte a este pacote neste sistema operacional.
o do DirectX4Instalar componentes de tempo de execu
Procurando por componentes em tempo de execu
r operativsystemet.
DirectX: %s
m Windows(R) znovu nainstalovat.GChcete pokracovat v instalaci t
&DirectX-Setup - VORABVERSIONWARNUNG!!!.Diese Vorabversion von DirectX L
UFT am %s AB!
&DirectX setup - pre-release WARNING!!!2This pre-release version of DirectX EXPIRES on %s!
You will need to re-install Windows(R) if you do not have a valid DirectX BetaID and access to hXXp://VVV.BetaPlace.com website when it expires!XWould you like to continue with the installation of this pre-release version of DirectX?
Instalando archivos...eInstalaci
n preliminar de DirectX CADUCA el %s.
n beta de DirectX y accede al sitio Web hXXp://VVV.BetaPlace.com cuando el Id. haya caducado.J
ta de DirectX expirera le %s.
.HVoulez-vous poursuivre l'installation de cette version B
6Installazione di DirectX - Avviso versione preliminare3Questa versione preliminare di DirectX SCADE il %s.
necessario reinstallare Windows(R) se alla scadenza non si dispone di un BetaID valido per DirectX e di accesso al sito Web hXXp://VVV.BetaPlace.comEContinuare l'installazione di questa versione preliminare di DirectX?
Bestanden installeren...CInstallatie van DirectX Runtime voor ontwikkelaars (foutopsporing):CInstallatie van DirectX Runtime voor ontwikkelaars (handelsversie):
-DirectX Setup. Waarschuwing: evaluatieversie.0Deze evaluatieversie van DirectX verloopt op %s!
U dient Windows(R) opnieuw te installeren als u geen geldige b
ta-id voor DirectX en toegang tot de website hXXp://VVV.betaplace.com hebt wanneer DirectX verloopt.HWilt u doorgaan met de installatie van deze evaluatieversie van DirectX?
<Instalator programu DirectX - OSTRZEZENIE O WERSJI WSTEPNEJ!7Waznosc tej wersji wstepnej programu DirectX WYGASA %s!
Po wygasnieciu waznosci tej wersji trzeba bedzie ponownie zainstalowac system Windows(R) w wypadku braku prawidlowego identyfikatora Beta programu DirectX i dostepu do witryny hXXp://VVV.BetaPlace.com w sieci web!ICzy chcesz kontynuowac instalowanie tej wersji wstepnej programu DirectX?
amento do DirectX EXPIRA em %s!
lida e acessar hXXp://VVV.BetaPlace.com quando ela expirar!HDeseja continuar a instala
hXXp://VVV.BetaPlace.com.?
Filer installeras...LInstallation av k
lla den %s.
4.9.0.0904
dxsetup.exe
Microsoft(R) DirectX for Windows(R)
DirectX for Windows
r Windows
DirectX para Windows
DirectX pour Windows
Microsoft(R) DirectX per Windows(R)
Microsoft(R) DirectX voor Windows(R)
DirectX dla systemu Windows
Windows

QHActiveDefense.exe_804:

.text
`.rdata
@.data
.rsrc
@.reloc
8%u3P
tCPj
vSSSh
FTPjK
FtPj;
C.PjRV
Uu.AUu
Visual C   CRT: Not enough memory to complete call to strerror.
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
portuguese-brazilian
Broken pipe
Inappropriate I/O control operation
Operation not permitted
GetProcessWindowStation
USER32.DLL
operator
Local\{C15730E2-145C-4c5e-B005-3BC753F42475}-once-flag
\\.\Scsi%d:
XXXXXX
\\.\%s
SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards
%s:x
BRegDeleteKeyExW
BRegDeleteKeyEx
BRegCloseKey
BRegEnumKeyExW
BRegEnumKeyEx
BRegEnumKeyW
BRegEnumKey
BRegDeleteKeyW
BRegDeleteKey
BRegCreateKeyExW
BRegCreateKeyEx
BRegCreateKeyW
BRegCreateKey
BRegOpenKeyExW
BRegOpenKeyEx
BRegOpenKeyW
BRegOpenKey
shellexecute=
kernel32.dll
TTransportException: Unknown transport exception
TTransportException: Transport not open
TTransportException: Timed out
TTransportException: End of file
TTransportException: Interrupted
TTransportException: Invalid arguments
TTransportException: Corrupted Data
TTransportException: Internal error
TTransportException: (Invalid exception type)
Cannot open base TTransport.
Cannot close base TTransport.
Base TTransport cannot read.
Base TTransport cannot write.
Base TTransport cannot consume.
C:\vmagent_new\bin\joblist\38554\src\Q_capital\QHService_6.2\360LPUB\dev\include\boost/exception/detail/exception_ptr.hpp
received invalid message type %d from client
SetAuthKey
sendMsg2Srv
sendMsg2SrvEx
sendCMD2Srv
sendWndCopyDataMsg2Srv
SendMsg2Users
deleteContext() tid:%d
Advapi32.dll
GetNamedPipeClientProcessId
Q360DsMainMutexNetProbe_b6bb85f3-a4ba-499c-8a14-eac587ec1fc2
RegDeleteKeyExW
Unable to open pipe
SetNamedPipeHandleState failed
Called read on non-open pipe
Called write on non-open pipe
Write to pipe failed
Thrift: %s
TThreadPoolServer exception %s: %s
TThreadPoolServer: TServerTransport died on accept:
TPipeServer unable to initiate pipe comms, GLE=
TPipeServer unable to initiate pipe comms
TPipeServer CreateNamedPipe failed, GLE=
TPipeServer CreateNamedPipe failed
TPipeServer ConnectNamedPipe GLE=
TPipeServer: client connection failed
TPipeServer::TCreateNamedPipe() GLE=
TCreateNamedPipe() failed
TApplicationException: Unsupported client type
i32AuthKey
i32MagicKey
iAuthKey
i32PipePortHandle
QTrayClient_SetAuthKey_pargs
iMsgInfoId
copyDataMsg
SetAuthKey failed: unknown result
dwLastErr=%d
QTrayService_SetAuthKey_result
QTrayService_sendMsg2Srv_result
QTrayService_sendMsg2SrvEx_result
QTrayService_sendCMD2Srv_result
QTrayService_sendWndCopyDataMsg2Srv_result
QTrayService_SendMsg2Users_result
QTrayService.RegisterClient
QTrayService.SetAuthKey
QTrayService.AttachMessage
QTrayService.AddEventLog
QTrayService.GetAutoliveState
QTrayService.GetUserInfo
QTrayService.QueryClientObject
QTrayService.OnMessage
QTrayService.AVMessageToSrv
QTrayService.TestValue
QTrayService.ping
QTrayService.HipsFnCallBack
QTrayService.setAppMonState2Srv
QTrayService.setDrvMonState2Srv
QTrayService.setSBNetworkState2Srv
QTrayService.setCommonState2Srv
QTrayService.stopService
QTrayService.sendMsg2Srv
QTrayService.sendMsg2SrvEx
QTrayService.sendTrayData2Srv
QTrayService.sendSBLaunchData2Srv
QTrayService.sendCMD2Srv
QTrayService.UDiskMessageToSrv
QTrayService.ReplyMessage2Srv
QTrayService.sendWndCopyDataMsg2Srv
QTrayService.sendLaunchProcData2Srv
QTrayService.ScanMessageToSrv
QTrayService.SendMsg2Users
szKeyName
iSrvPipeHandle
dwMsgID
%s:%I64X
\\.\PhysicalDrive%d
C:\vmagent_new\bin\joblist\38554\out\Release\QHActiveDefense.pdb
GetWindowsDirectoryW
GetProcessHeap
KERNEL32.dll
USER32.dll
RegCreateKeyExW
RegOpenKeyExW
RegEnumKeyExW
RegCloseKey
RegQueryInfoKeyW
RegDeleteKeyW
ADVAPI32.dll
ShellExecuteExW
SHELL32.dll
ole32.dll
OLEAUT32.dll
URLDownloadToCacheFileW
urlmon.dll
SHDeleteKeyW
SHLWAPI.dll
WINMM.dll
IPHLPAPI.DLL
VERSION.dll
WS2_32.dll
PSAPI.DLL
RPCRT4.dll
USERENV.dll
WTSAPI32.dll
NETAPI32.dll
PeekNamedPipe
SetNamedPipeHandleState
ConnectNamedPipe
CreateNamedPipeW
DisconnectNamedPipe
GetSystemWindowsDirectoryW
GetCPInfo
GetConsoleOutputCP
RegEnumKeyExA
RegOpenKeyExA
zcÁ
.?AV?$sp_counted_impl_p@V?$TBinaryProtocolT@VTTransport@transport@thrift@apache@@@protocol@thrift@apache@@@detail@boost@@
.?AV?$sp_counted_impl_p@VTPipe@transport@thrift@apache@@@detail@boost@@
.?AV?$sp_counted_impl_p@VTBufferedTransport@transport@thrift@apache@@@detail@boost@@
.?AV?$TVirtualTransport@VTBufferedTransport@transport@thrift@apache@@VTBufferBase@234@@transport@thrift@apache@@
.?AVTBufferedTransport@transport@thrift@apache@@
.?AV?$TVirtualTransport@VTBufferBase@transport@thrift@apache@@VTTransportDefaults@234@@transport@thrift@apache@@
.?AVTBufferBase@transport@thrift@apache@@
.?AVTTransportDefaults@transport@thrift@apache@@
.?AV?$TVirtualProtocol@V?$TBinaryProtocolT@VTTransport@transport@thrift@apache@@@protocol@thrift@apache@@VTProtocolDefaults@234@@protocol@thrift@apache@@
.?AV?$TBinaryProtocolT@VTTransport@transport@thrift@apache@@@protocol@thrift@apache@@
.?AVTTransportException@transport@thrift@apache@@
.?AVTTransport@transport@thrift@apache@@
.?AV?$sp_counted_impl_p@VTBufferedTransportFactory@transport@thrift@apache@@@detail@boost@@
.?AV?$sp_counted_impl_p@V?$TBinaryProtocolFactoryT@VTTransport@transport@thrift@apache@@@protocol@thrift@apache@@@detail@boost@@
.?AV?$sp_counted_impl_p@VTPipeServer@transport@thrift@apache@@@detail@boost@@
.?AVTBufferedTransportFactory@transport@thrift@apache@@
.?AV?$TBinaryProtocolFactoryT@VTTransport@transport@thrift@apache@@@protocol@thrift@apache@@
.?AVTTransportFactory@transport@thrift@apache@@
.?AVTPipe@transport@thrift@apache@@
.?AVIQSScanMsgCenter@@
.?AV?$C360PublicDLLHelper@VC360UtilExportFuncs@@@@
.?AVC360UtilExportFuncs@@
.?AV?$C360PublicDLLHelper@VC360ConfExportFuncs@@@@
.?AVC360ConfExportFuncs@@
.?AV?$C360PublicDLLHelper@VC360BaseExportFuncs@@@@
.?AVC360BaseExportFuncs@@
.?AVCScanMsgResult@@
.?AVIQSScanMsgResult@@
.?AV?$TVirtualTransport@VTPipe@transport@thrift@apache@@VTTransportDefaults@234@@transport@thrift@apache@@
.?AVTPipeServer@transport@thrift@apache@@
.?AVTServerTransport@transport@thrift@apache@@
.?AVCUrlCallback@@
.?AVQTrayClient_SetAuthKey_presult@qtray@@
.?AVQTrayClient_SetAuthKey_pargs@qtray@@
.?AVQTrayService_SendMsg2Users_result@qtray@@
.?AVQTrayService_SendMsg2Users_args@qtray@@
.?AVQTrayService_sendWndCopyDataMsg2Srv_result@qtray@@
.?AVQTrayService_sendWndCopyDataMsg2Srv_args@qtray@@
.?AVQTrayService_sendCMD2Srv_result@qtray@@
.?AVQTrayService_sendCMD2Srv_args@qtray@@
.?AVQTrayService_sendMsg2SrvEx_result@qtray@@
.?AVQTrayService_sendMsg2SrvEx_args@qtray@@
.?AVQTrayService_sendMsg2Srv_result@qtray@@
.?AVQTrayService_sendMsg2Srv_args@qtray@@
.?AVQTrayService_SetAuthKey_result@qtray@@
.?AVQTrayService_SetAuthKey_args@qtray@@
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
7r7C7N7_7u7{7
939@9#:0:
3"3'3.353<3{3
;$;(;,;0;
46U6f6
6*7074787<7
7-7Q7w7}7
=5>;>]>}>
< <1<6<<<
4 4$4(4,404
9(?,?0?8?
2 2$2(2,2024282<2
mscoree.dll
KERNEL32.DLL
deepscan\cloudcom2.dll
\360Safe\LogInfo
%s\%s*%s
%s\%s
.log2
Newctrl.lck
important_log
%s\%s%s%d%s
\\.\A:
%d_%d_%d_%d_%d
..\..\deepscan\BAPI.dll
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\QHSafeMain.exe
autorun.inf
safemon\UDiskScanEngine.dll
<clear=1><lnk=%d><vbs=%d><bat=%d><cmd=%d><exe=%d>
shellexecute
config.ini
udisk.locale
..\..\360verify.dll
\LogInfo
safemon\gamemode.tpi
safemon\360procmon.dll
ipc\netdefender.dll
ipc\appd.dll
ipc\yhregd.dll
ipc\fileMgr.dll
ipc\ipcservice.dll
Software\360TotalSecurity\srvtpi\%s
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\QHSafeTray.exe
QHSafeTray.exe
360rp.dll
recvmsg
recvmsgcontext
sendmsg
sendmsgtosession
sendmsgcontext
sendmsgtosessioncontext
\\.\qutmipc
.qihoo.com
.360safe.com
.360.cn
360base.dll
360NetBase.dll
%d.%d.%d.%d
user32.dll
safemon\QHSafeTray.exe
QHSafeMain.exe
QHVer.dll
%d.%d-%s
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe
\galaxy.dat
\\.\pipe\%ws
psapi.dll
Kernel32.dll
\galaxy2.dat
%%%s%%
CrashReport.dll
\\.\360SelfProtection
modules\360tsesafeup.exe
modules\360isafeup.exe
\360Tray.exe" /start
\QHSafeTray.exe" /start
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
AL_Keylogger
QHWatchdog.exe
rpcrt4.dll
"%s" %s
explorer.exe
{1099D519-05E2-47e9-B669-413DDCD5D53E}
deepscan\BAPI.dll
safemon\QHWatchdog.exe /watch
Global\0FB40CC1-AFF9-441d-8D9B-9F285AD8F637__
\explorer.exe
deepscan\qutmload.dll
safemon\SelfProtectAPI2.dll
webfw.log
wddown.log
ScanStub.dll
deepscan\speedmem2.hg
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
HKEY_PERFORMANCE_DATA
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
{5EEE8B0C-BEB2-4f05-BA7E-5EF3A65B8ECC}
\deepscan\BAPI.dll
AviraImp.dll
%s.bak
\\.\pipe\
UrlSettings.dll.locale
hXXp://s.360safe.com/safei18n/
\i18n.dll
main.htm?
tray.htm?m=%s&cs=%s&a=%s&?
ins.htm?mid=%s&ver=%s&lan=%s&os=%s&ch=%s
uni.htm?mid=%s&ver=%s&lan=%s&os=%s&ch=%s&cpu=%s&ram=%s&protect=%s&ttl=%s&avp=%s&scan=%s&moni=%s
feature.htm?id=%d&
up.htm?mid=%s&ver=%s&lan=%s&os=%s&ch=%s
off_vdb.htm?dt=%s&dv=%s&prod=%s&mid=%s&ver=%s&lan=%s&os=%s&ch=%s
pmode.htm?m=%s&cs=%s&
err.htm?mod=sp&code=10&mid=%s&ver=%s&lan=%s&os=%s&ch=%s&rn=%s
engine.htm?t=%s&s=%d&
vs.htm?m=%s&
wifi.htm?f=%s&r=%s&c=%s&
fb.htm?a=%s&s=%s&
checkup.htm?a=%s&
instcomp.htm?soft=20130127&status=%d&mid=%s
safe/instcomp.htm?soft=6701&status=%d&mid=%s
safe/instcomp.htm?soft=6701&status=%d&sda=%d&mid=%s
safe/instcomp.htm?soft=6701&status=%d&sda=%d&sdb=%d&mid=%s
ws_ff.htm?s=%s&
toolbox.htm?id=%d&
toolboxmodule.htm?id=%d&status=%d&
dumpuper.htm?stack=%s&ver=%s&queryResponse=%s&sendResponse=%s
wd.htm
wdpaypro.htm
filemon.htm
hips.htm
src.htm
%s?bd=%d&avira=%d&exectime=%u&step=%d&
&curl=0
&curl=1
&curl=2&curlerr=0xx
&curl=2
%smid=%s&ver=%s&lan=%s&os=%s&ch=%s
\safemon\WscReg.exe
WHERE pathToSignedProductExe LIKE '%safemon\\QHSafeTray.exe'
{X-X-X-X-XX}_
.\QHCheckCertificate.c
Operator
Certificate Table
0|2008-10-08|15:04:02|QHErrObj.cpp|1||MEM|1|
netmsg.dll
mqutil.dll
wininet.dll
__crt
|hu-hu-hu|hu:hu:hu|%s|%d|%s|%s|%d|%s
{A0972F10-452C-4cd1-904E-B50E394EDE34}
%s-%d-%s:
%s-%d-%s:%s
1830B7BD-F7A3-4c4d-989B-C004DE465EDE
%s %u
F:\WorkCode\Pub\360GPUBNew\dev\include\Interface\QHTL.h
hXXp://down.360safe.com/setup.exe
hXXp://down.360safe.com/setupbeta.exe
%Program Files% (x86)\360\Total Security\safemon\QHActiveDefense.exe
%Program Files% (x86)\360\Total Security\safemon
QHActiveDefense.exe
%Program Files% (x86)\360\Total Security
6,2,0,1000
QHActive.exe

QHWatchdog.exe_2492:

.text
`.rdata
@.data
.rsrc
@.reloc
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
operator
GetProcessWindowStation
USER32.DLL
C:\vmagent_new\bin\joblist\31966\out\Release\QHWatchdog.pdb
KERNEL32.dll
ADVAPI32.dll
SHLWAPI.dll
GetCPInfo
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
9'9,90949]9
7'7,70747]7
014181<1
< <@<\<`<
mscoree.dll
KERNEL32.DLL
%Program Files% (x86)\360\Total Security\safemon\QHWatchdog.exe
6,0,0,1001
QHWatchdog.exe

QHSafeTray.exe_1172:

.text
`.rdata
@.data
.rsrc
@.reloc
L$.Qf
tCPj
vSSSh
FTPjK
FtPj;
C.PjRV
FUu.AUu
kernel32.dll
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
portuguese-brazilian
GetProcessWindowStation
USER32.DLL
operator
Local\{C15730E2-145C-4c5e-B005-3BC753F42475}-once-flag
\\.\Scsi%d:
XXXXXX
\\.\%s
SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards
%s:x
Visual C   CRT: Not enough memory to complete call to strerror.
Broken pipe
Inappropriate I/O control operation
Operation not permitted
<4,$?7/'
(3-!0,1'8"5.*2$
BRegOpenKey
BRegOpenKeyW
BRegOpenKeyEx
BRegOpenKeyExW
BRegCreateKey
BRegCreateKeyW
BRegCreateKeyEx
BRegCreateKeyExW
BRegDeleteKey
BRegDeleteKeyW
BRegEnumKey
BRegEnumKeyW
BRegEnumKeyEx
BRegEnumKeyExW
BRegCloseKey
BRegDeleteKeyEx
BRegDeleteKeyExW
GetNamedPipeClientProcessId
GetNamedPipeServerProcessId
%s\%s
AL_Keylogger
AutoLogin
NetPayShowWeb
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths
QHSafeMain.exe
C:\vmagent_new\bin\joblist\39403\src\Q_capital\QHSafeTray__6.2\360LPUB\dev\include\boost/exception/detail/exception_ptr.hpp
\"^&`<>[]{}
-_.!~*'()
dkey
bootkey
select * from %s
select * from %s
update %s set %s=%d, %s=%d where %s='%s'
insert into %s(%s, %s, %s, %s, %s, %s, %s)values('%d', '%s', '%s', '%d', '%d', '%d', '%d')
select * from %s where %s='%s'
update %s set %s=%d where %s='%s'
create table %s(%s int, %s char, %s char, %s int, %s int, %s int, %s int);
create table %s(%s char, %s char);
select * from %s where %s<=%d and %s=0 order by %s desc limit %d
select * from %s where %s='%d' and %s=0
update %s set %s='%s' where %s='%s'
insert into %s(%s, %s)values('%s', '%s')
select * from %s where %s<=%d and %s=0
select * from %s where %s > %d and %s <= %d and %s=0 limit %d
select * from %s where %s <= %d and %s=0 order by rowid desc limit %d
select * from %s where %s>=%d and %s <= %d and %s=0 order by %s asc limit %d
select * from %s where %s>=%d and %s <= %d and %s=0
select * from %s where %s=0 and %s <= %d
speedupopt.db
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
\\.\X:
TTransportException: Unknown transport exception
TTransportException: Transport not open
TTransportException: Timed out
TTransportException: End of file
TTransportException: Interrupted
TTransportException: Invalid arguments
TTransportException: Corrupted Data
TTransportException: Internal error
TTransportException: (Invalid exception type)
Cannot open base TTransport.
Cannot close base TTransport.
Base TTransport cannot read.
Base TTransport cannot write.
Base TTransport cannot consume.
received invalid message type %d from client
SetAuthKey
_PPQueryIPPort
Thrift: %s
TThreadPoolServer exception %s: %s
TThreadPoolServer: TServerTransport died on accept:
Unable to open pipe
SetNamedPipeHandleState failed
Called read on non-open pipe
Called write on non-open pipe
Write to pipe failed
TPipeServer unable to initiate pipe comms, GLE=
TPipeServer unable to initiate pipe comms
TPipeServer CreateNamedPipe failed, GLE=
TPipeServer CreateNamedPipe failed
TPipeServer ConnectNamedPipe GLE=
TPipeServer: client connection failed
TPipeServer::TCreateNamedPipe() GLE=
TCreateNamedPipe() failed
user32.dll
dwLastErr=%d
TApplicationException: Unsupported client type
i32AuthKey
i32MagicKey
iAuthKey
i32PipePortHandle
QTrayClient_SetAuthKey_result
iMsgInfoId
copyDataMsg
SetAuthKey failed: unknown result
QTrayClient.SetTrayIcon
QTrayClient.SetTipText
QTrayClient.ShowBallon
QTrayClient.SkinMessageBox
QTrayClient.SetTrayData
QTrayClient.GetTrayData
QTrayClient.AVMessageToCli
QTrayClient.TestValueClient
QTrayClient.HipsCreateNotifyWnd
QTrayClient.SetAuthKey
QTrayClient.PostMessage
QTrayClient.SendMessage
QTrayClient.UDiskMessageToCli
QTrayClient.PostCopyDataMessage
QTrayClient.ScanMessageToCli
sendMsg2Srv
sendMsg2SrvEx
sendCMD2Srv
sendWndCopyDataMsg2Srv
SendMsg2Users
u8StrClientPipe
QTrayService_SetAuthKey_pargs
nStartMsg
nEndMsg
bBypassVista
uMsg
iMsgType
iMsg
QTrayService_sendMsg2Srv_pargs
QTrayService_sendMsg2SrvEx_pargs
strKey
cmdline
iCMD
QTrayService_sendCMD2Srv_pargs
iCopyDataMsgId
QTrayService_sendWndCopyDataMsg2Srv_pargs
iMsgId
QTrayService_SendMsg2Users_pargs
sendMsg2Srv failed: unknown result
sendMsg2SrvEx failed: unknown result
sendCMD2Srv failed: unknown result
sendWndCopyDataMsg2Srv failed: unknown result
SendMsg2Users failed: unknown result
szKeyName
u8StrCmd
dwMsgID
%s:%I64X
\\.\PhysicalDrive%d
C:\vmagent_new\bin\joblist\39403\out\Release\QHSafeTray.pdb
GetWindowsDirectoryW
DisconnectNamedPipe
KERNEL32.dll
ExitWindowsEx
USER32.dll
SetViewportOrgEx
GDI32.dll
RegOpenKeyExW
RegCloseKey
RegEnumKeyExW
RegCreateKeyExW
RegCreateKeyA
RegDeleteKeyW
RegQueryInfoKeyW
ADVAPI32.dll
ShellExecuteW
ShellExecuteExW
SHELL32.dll
ole32.dll
OLEAUT32.dll
URLDownloadToCacheFileW
urlmon.dll
SHLWAPI.dll
COMCTL32.dll
PSAPI.DLL
Secur32.dll
WINMM.dll
VERSION.dll
RPCRT4.dll
WTSAPI32.dll
WS2_32.dll
IMM32.dll
NETAPI32.dll
GetProcessHeap
PeekNamedPipe
SetNamedPipeHandleState
ConnectNamedPipe
CreateNamedPipeW
GetSystemWindowsDirectoryW
GetCPInfo
GetConsoleOutputCP
RegEnumKeyExA
RegOpenKeyExA
zcÁ
.?AVCUrlCallback@@
.?AVTBufferedTransportFactory@transport@thrift@apache@@
.?AV?$TVirtualTransport@VTBufferedTransport@transport@thrift@apache@@VTBufferBase@234@@transport@thrift@apache@@
.?AVTBufferedTransport@transport@thrift@apache@@
.?AV?$TVirtualTransport@VTBufferBase@transport@thrift@apache@@VTTransportDefaults@234@@transport@thrift@apache@@
.?AVTBufferBase@transport@thrift@apache@@
.?AVTTransportDefaults@transport@thrift@apache@@
.?AV?$TBinaryProtocolFactoryT@VTTransport@transport@thrift@apache@@@protocol@thrift@apache@@
.?AV?$TVirtualProtocol@V?$TBinaryProtocolT@VTTransport@transport@thrift@apache@@@protocol@thrift@apache@@VTProtocolDefaults@234@@protocol@thrift@apache@@
.?AV?$TBinaryProtocolT@VTTransport@transport@thrift@apache@@@protocol@thrift@apache@@
.?AVTTransportFactory@transport@thrift@apache@@
.?AV?$sp_counted_impl_p@VTBufferedTransportFactory@transport@thrift@apache@@@detail@boost@@
.?AV?$sp_counted_impl_p@V?$TBinaryProtocolFactoryT@VTTransport@transport@thrift@apache@@@protocol@thrift@apache@@@detail@boost@@
.?AV?$sp_counted_impl_p@VTPipeServer@transport@thrift@apache@@@detail@boost@@
.?AV?$sp_counted_impl_p@VTBufferedTransport@transport@thrift@apache@@@detail@boost@@
.?AVTTransportException@transport@thrift@apache@@
.?AVTTransport@transport@thrift@apache@@
.?AVTPipe@transport@thrift@apache@@
.?AV?$sp_counted_impl_p@V?$TBinaryProtocolT@VTTransport@transport@thrift@apache@@@protocol@thrift@apache@@@detail@boost@@
.?AV?$sp_counted_impl_p@VTPipe@transport@thrift@apache@@@detail@boost@@
.PA_W
.?AV?$CModalWindow@VCMsgBox@@@@
.?AV?$CWindowImpl@VCMsgBox@@VCWindow@ATL@@V?$CWinTraits@$0IGAAMCAA@$0BAA@@3@@ATL@@
.?AV?$IDispEventSimpleImpl@$00VCMsgBox@@$1?DIID_Isite_events@sitesUI@@3U_GUID@@B@ATL@@
.?AVCMsgBox@@
.?AV?$C360PublicDLLHelper@VC360UtilExportFuncs@@@@
.?AVC360UtilExportFuncs@@
.?AV?$C360PublicDLLHelper@VC360ConfExportFuncs@@@@
.?AVC360ConfExportFuncs@@
.?AV?$C360PublicDLLHelper@VC360BaseExportFuncs@@@@
.?AVC360BaseExportFuncs@@
.?AV?$TVirtualTransport@VTPipe@transport@thrift@apache@@VTTransportDefaults@234@@transport@thrift@apache@@
.?AVTPipeServer@transport@thrift@apache@@
.?AVTServerTransport@transport@thrift@apache@@
.?AVQTrayClient_SetAuthKey_result@qtray@@
.?AVQTrayClient_SetAuthKey_args@qtray@@
.?AVQTrayService_SendMsg2Users_presult@qtray@@
.?AVQTrayService_SendMsg2Users_pargs@qtray@@
.?AVQTrayService_sendWndCopyDataMsg2Srv_presult@qtray@@
.?AVQTrayService_sendWndCopyDataMsg2Srv_pargs@qtray@@
.?AVQTrayService_sendCMD2Srv_presult@qtray@@
.?AVQTrayService_sendCMD2Srv_pargs@qtray@@
.?AVQTrayService_sendMsg2SrvEx_presult@qtray@@
.?AVQTrayService_sendMsg2SrvEx_pargs@qtray@@
.?AVQTrayService_sendMsg2Srv_presult@qtray@@
.?AVQTrayService_sendMsg2Srv_pargs@qtray@@
.?AVQTrayService_SetAuthKey_presult@qtray@@
.?AVQTrayService_SetAuthKey_pargs@qtray@@
%dM"og
.UMUX
KeyU
.Rd0Jb
4m`%D@P
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity>
55v6
:':0:6:?:
=&>6>]>}>
9œ9
< <&< <:<
<"<0<*=>=
=!=,=>=}=
7'7,70747]7
= =$=(=,=0=4=~=
? ?$?(?,?
01S1
88
? ?$?(?,?0?4?
= =$=(=,=0=
2(3,30343
6$8(8,8084888
: :<:@:`:
mscoree.dll
KERNEL32.DLL
powrprof.dll
BypassMetroDesktop
Software\Microsoft\Windows\CurrentVersion\Policies
%s\Explorer
360InternationTray\traymenu.xml
\LiveUpdate360.exe
ipc\360boxmain.exe
xsoftmgr\somkernl.dll
d.360.cn
.360safe.com
<urltype=URL_FILEMON><ver=%s><lanid=%s><os=%s><ch=%s>%s
<urltype=URL_HIPS><ver=%s><lanid=%s><os=%s><ch=%s>%s
360.cn
\\.\360SelfProtection
"%s\Utils\360MsgCenter.exe" /NOTIFY=%d
360TotalSecurityUpdMsgWnd
[md=%u][op=%u][e=%u]
[md=%u][e=%u]
360base.dll
360conf.dll
..\360base.dll
\deepscan\360base.dll
..\..\360base.dll
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe
..\360conf.dll
..\..\360conf.dll
deepscan\BAPI.dll
..\ipc\360boxmain.exe
Kernel32.dll
CrashReport.dll
\360Base.dll
\CrashReport.dll
sites.dll
i18n.dll
%strayna.html?
Global\0FB40CC1-AFF9-441d-8D9B-9F285AD8F637__
360verify.dll
\LogInfo
softmgr\somkernl.dll
\deepscan\qutmload.dll
360InternationSafe\image\%s
Session%d
safemon\SelfProtectAPI2.dll
safemon\360procmon.dll
e\safemon\somproxy.dll
\safemon\QHSafeTray.exe" /start
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\QHSafeMain.exe
safemon\QHActiveDefense.exe
safemon\360hipsPopWnd.dll
\galaxy.dat
360InternationSafe\msgbox.xml
360chrome
safevideo.exe
chrome_exe
IDS_360EXE_NOT_IN_SB
360InternationTray\speedld.xml
360InternationTray\shared.xml
%sbtime.html?tp=%d&n=%d&o=%d&t=%d&
\QHToasts.exe
tsupd.ini
IDS_TRAY_EXIT_MSG_TEXT
IDS_TRAY_EXIT_MSG_YES
IDS_TRAY_EXIT_MSG_NO
/cmd=
/cmdline=
F\galaxy.dat
QHSafeScanner.exe
"%s\%s" %s
safemon\360safemonpro.tpi
safemon\360AV.tpi
safemon\360Udisk.tpi
\deepscan\CloudSec3.dll
\deepscan\Deepscan.dll
360SkinView.exe
"%s%s" "%s"
"%s" %s
\PatchUp.exe
PDown.dll
d.360safe.com
.360.cn
\\.\pipe\%ws
pKernel32.dll
explorer.exe
taskmgr.exe
QHVer.dll
config.ini
%d.%d-%s
\StringFileInfo\xx
%s\ProductName
%s\FileDescription
%d.%d.%d.%d
%s\OriginalFilename
%s\InternalName
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\%s
360se6.exe
360se.exe
360chrome.exe
%s\shell
%s\shell\%s\command
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
ntdll.dll
okernel32.dll
\ntoskrnl.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion
360util.dll
360NetBase.dll
softcounter_%u.xml
\StringFileInfo\xx\ProductName
http=
https=
CLSID\%s\InprocServer32
windows
%s\Microsoft Shared\OFFICE9
%s\Microsoft Shared\OFFICE10
%s\Microsoft Shared\OFFICE11
%s\Microsoft Shared\OFFICE12
%s\Microsoft Shared\OFFICE14
%s\Microsoft Shared\OFFICE15
%smid=%s&ver=%s&lan=%s&os=%s&ch=%s
&curl=0
&curl=1
&curl=2&curlerr=0xx
&curl=2
\config.ini
..\config.ini
%snosign.htm?f=%s&re=%s&mid=%s&ver=%s&lan=%s&os=%s&ch=%s
hXXp://VVV.360totalsecurity.com/d/ts/%s/%s/
%s%cd:d
%s "%s"
%s %s
IEXPLORE.EXE
firefox
%Y-%m-%d
\leakrepair.dll
%llu%s
%d:%s
ipc\ipcservice.dll
Software\360TotalSecurity\traytpi\%s
safemon\360TrayMenu.dll
%d/d/d
%dddddd
%Y-%m-%d %H:%M:%S
somextrainfo2.ini
svdl.ini
svchost.exe
[%d][%d] u:u:u:u - %s
{1099D519-05E2-47e9-B669-413DDCD5D53E}
Common\XML\CommonResource.xml
support
cmd.exe
.android_secure
\deepscan\BAPI.dll
safemon\cleanedFileFullpath.dat
can not load pdown.dll
n360TsLiveUpd.exe
modules\360isafeup.exe
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
HKEY_PERFORMANCE_DATA
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
0.xml
default.xml
theme.xml
\\.\pipe\
UrlSettings.dll.locale
hXXp://s.360safe.com/safei18n/
\i18n.dll
main.htm?
tray.htm?m=%s&cs=%s&a=%s&?
ins.htm?mid=%s&ver=%s&lan=%s&os=%s&ch=%s
uni.htm?mid=%s&ver=%s&lan=%s&os=%s&ch=%s&cpu=%s&ram=%s&protect=%s&ttl=%s&avp=%s&scan=%s&moni=%s
feature.htm?id=%d&
up.htm?mid=%s&ver=%s&lan=%s&os=%s&ch=%s
off_vdb.htm?dt=%s&dv=%s&prod=%s&mid=%s&ver=%s&lan=%s&os=%s&ch=%s
pmode.htm?m=%s&cs=%s&
err.htm?mod=sp&code=10&mid=%s&ver=%s&lan=%s&os=%s&ch=%s&rn=%s
engine.htm?t=%s&s=%d&
vs.htm?m=%s&
wifi.htm?f=%s&r=%s&c=%s&
fb.htm?a=%s&s=%s&
checkup.htm?a=%s&
instcomp.htm?soft=20130127&status=%d&mid=%s
safe/instcomp.htm?soft=6701&status=%d&mid=%s
safe/instcomp.htm?soft=6701&status=%d&sda=%d&mid=%s
safe/instcomp.htm?soft=6701&status=%d&sda=%d&sdb=%d&mid=%s
ws_ff.htm?s=%s&
toolbox.htm?id=%d&
toolboxmodule.htm?id=%d&status=%d&
dumpuper.htm?stack=%s&ver=%s&queryResponse=%s&sendResponse=%s
wd.htm
wdpaypro.htm
filemon.htm
hips.htm
src.htm
\i18n\i18n.ini
\softmgr\AdvUtils.ini
qurl
{X-X-X-X-XX}_
psapi.dll
.\QHCheckCertificate.c
Operator
Certificate Table
:SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards
0|2008-10-08|15:04:02|QHErrObj.cpp|1||MEM|1|
netmsg.dll
mqutil.dll
wininet.dll
__crt
|hu-hu-hu|hu:hu:hu|%s|%d|%s|%s|%d|%s
{A0972F10-452C-4cd1-904E-B50E394EDE34}
%s-%d-%s:
%s-%d-%s:%s
1830B7BD-F7A3-4c4d-989B-C004DE465EDE
%s %u
F:\WorkCode\Pub\360GPUBNew\dev\include\Interface\QHTL.h
%Program Files% (x86)\360\Total Security\safemon\QHSafeTray.exe
%Program Files% (x86)\360\Total Security
UAC_MESSAGE=To continue, type an administrator password
6,2,0,1002
QHSafeTray.exe

PatchUp.exe_3300:

.text
`.rdata
@.data
.rsrc
@.reloc
D$.Pf
8%u3P
tCPj
.Uu;AUu
kernel32.dll
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
operator
GetProcessWindowStation
USER32.DLL
\\.\Scsi%d:
XXXXXX
\\.\%s
SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards
%s:x
Visual C   CRT: Not enough memory to complete call to strerror.
Broken pipe
Inappropriate I/O control operation
Operation not permitted
_PPQueryIPPort
*`'&#xX;
</%s>
%s="%s"
%s='%s'
<!--%s-->
<![CDATA[%s]]>
version="%s"
encoding="%s"
standalone="%s"
%s:%I64X
\\.\PhysicalDrive%d
C:\vmagent_new\bin\joblist\36029\out\Release\PatchUp.pdb
KERNEL32.dll
GetKeyboardState
keybd_event
GetKeyState
USER32.dll
SetViewportOrgEx
GDI32.dll
RegCloseKey
RegOpenKeyExW
RegOpenKeyW
RegCreateKeyExW
RegEnumKeyExW
RegDeleteKeyW
RegQueryInfoKeyW
ADVAPI32.dll
ShellExecuteW
SHELL32.dll
ole32.dll
OLEAUT32.dll
URLDownloadToCacheFileW
urlmon.dll
SHLWAPI.dll
COMCTL32.dll
gdiplus.dll
VERSION.dll
NETAPI32.dll
GetProcessHeap
GetCPInfo
GetConsoleOutputCP
RegEnumKeyExA
RegOpenKeyExA
zcÁ
.PA_W
.?AV?$C360PublicDLLHelper@VC360UtilExportFuncs@@@@
.?AVC360UtilExportFuncs@@
.?AV?$C360PublicDLLHelper@VC360ConfExportFuncs@@@@
.?AVC360ConfExportFuncs@@
.?AV?$C360PublicDLLHelper@VC360BaseExportFuncs@@@@
.?AVC360BaseExportFuncs@@
.?AV?$CModalWindow@VCMsgBox@@@@
.?AV?$CWindowImpl@VCMsgBox@@VCWindow@ATL@@V?$CWinTraits@$0IGAAMCAA@$0BAA@@3@@ATL@@
.?AV?$IDispEventSimpleImpl@$00VCMsgBox@@$1?DIID_Isite_events@sitesUI@@3U_GUID@@B@ATL@@
.?AVCMsgBox@@
.?AVCUrlCallback@@
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity>
2"3 3>3^3
5T585<5@5
5#5)5.535
5#5)52575
2%3S3f3
373?3`3~3
;4;8;<;@;
6o6d6
0%0>0#161
74888<8@8
>$>(>,>0>4>8><>@>
6 6$6(6,606
7 7$7(7,7074787<7@7
8 8@8`8|8
KERNEL32.DLL
mscoree.dll
dsetupapi.dll
%s||%s||
deepscan\cloudcom2.dll
deepscan\speedmem2.hg
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\QHSafeMain.exe
libwhite.dat
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\%s
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
SOFTWARE\Microsoft\Windows NT\CurrentVersion
360util.dll
\StringFileInfo\xx\ProductName
%smid=%s&ver=%s&lan=%s&os=%s&ch=%s
config.ini
\config.ini
..\config.ini
%snosign.htm?f=%s&re=%s&mid=%s&ver=%s&lan=%s&os=%s&ch=%s
hXXp://VVV.360safe.com/totalsecurity/%s/%s/d
%s "%s"
%s %s
IEXPLORE.EXE
firefox
%Y-%m-%d
%d.%d.%d.%d
360NetBase.dll
360base.dll
ntdll.dll
\ntoskrnl.exe
%d.%d-%s
QHVer.dll
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
HKEY_PERFORMANCE_DATA
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
I18N.dll
\CrashReport.dll
pdown.dll
libleak-64_dif.dat
libleak-64_dif.cab
libleak_dif.dat
libleak_dif.cab
360leakfix\detail_page.xml
hXXp://qh.dlservice.microsoft.com
360leakfix\leakfix_page.xml
%s - %s
hXXp://s.360safe.com/safei18n/patch.html
hXXp://s.360safe.com/safei18n/patch_pop.html
%s?a=%s&nhig=%u¬h=%u&nunr=%u&nfun=%u&
360leakfix\leakfix_pop.xml
ts.product:1003
IDS_MSG_TEXT_QUIT
IDS_PATCH_SAVE_DEFAULT_KEY
%s(%s)
Kernel32.dll
{%s-%s-%s-%s-%s}
spuninst.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\%s\Products
MsiExec.exe /package %s /uninstall %s /qb
SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages
%d-d-d
wusa.exe /uninstall /kb:%d
360leakfix\leakfix_record.xml
Ûyte/s
360leakfix\leakfix_settings.xml
360softmgr_testdir.dat
360leakfix\main_dlg.xml
360leakfix\shared.xml
IDS_DIFF_DOWNLOAD_URL_32
IDS_DIFF_DOWNLOAD_URL_64
%d-%d-%d
can not load pdown.dll
wleakrepair.dll
libleakres.dat
pdown://%s|k=1|h7=1|b7=0|b4=0
hXXp://
0.xml
default.xml
theme.xml
sites.dll
\\.\360SelfProtection
Common\XML\SharedStrings.xml
Common\XML\CommonResource.xml
support
360InternationSafe\msgbox.xml
CrashReport.dll
UrlSettings.dll.locale
hXXp://s.360safe.com/safei18n/
\i18n.dll
hXXp://s.360safe.com/safei18n/wd.htm
hXXp://s.360safe.com/safei18n/wdpaypro.htm
hXXp://s.360safe.com/safei18n/filemon.htm
hXXp://s.360safe.com/safei18n/hips.htm
hXXp://s.360safe.com/safei18n/srv.htm
.\QHCheckCertificate.c
Operator
0|2008-10-08|15:04:02|QHErrObj.cpp|1||MEM|1|
netmsg.dll
mqutil.dll
wininet.dll
__crt
|hu-hu-hu|hu:hu:hu|%s|%d|%s|%s|%d|%s
Certificate Table
:SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards
{A0972F10-452C-4cd1-904E-B50E394EDE34}
%s-%d-%s:
%s-%d-%s:%s
1830B7BD-F7A3-4c4d-989B-C004DE465EDE
%s %u
F:\WorkCode\Pub\360GPUBNew\dev\include\Interface\QHTL.h
%Program Files% (x86)\360\Total Security\PatchUp.exe
%Program Files% (x86)\360\Total Security
%Program Files% (x86)\360\Total Security\pdown.dll
]%Program Files% (x86)\360\Total Security\libleak-64_dif.dat
%Program Files% (x86)\360\Total Security\libleak-64_dif.cab
QHSafeMain.exe
6, 0, 0, 1005
PatchUp.exe


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    QHWatchdog.exe:2492
    DXSETUP.exe:1376
    regsvr32.exe:704
    regsvr32.exe:1580
    %original file name%.exe:2428
    QHActiveDefense.exe:1168
    QHActiveDefense.exe:804
    nss6FC6.tmp.exe:1904

  2. Delete the original Trojan file.
  3. Delete or disinfect the following files created/modified by the Trojan:

    C:\Users\"%CurrentUserName%"\AppData\LocalLow\360WD\wdch.dat (557 bytes)
    %Program Files% (x86)\360\Total Security\safemon\netconfig.dat (18 bytes)
    %Program Files% (x86)\360\Total Security\safemon\wdui2.dll (548 bytes)
    %Program Files% (x86)\360\Total Security\safemon\safemon.dll (49 bytes)
    %Program Files% (x86)\360\Total Security\safemon\SomProxy.dll (339 bytes)
    %Program Files% (x86)\360\Total Security\safemon\routertp.ini (56 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalLow\360WD\wdch.dat-journal (7250 bytes)
    %Program Files% (x86)\360\Total Security\safemon\urlproc.dll (655 bytes)
    %Program Files% (x86)\360\Total Security\hotfix\som_c6cb4f5ac0255d2baf41678f26cd50cc.dat.tmp (2 bytes)
    %Program Files% (x86)\360\Total Security\hotfix\som_7539e5c431f211952383e009cce4062d.dat.tmp (323 bytes)
    %Program Files% (x86)\360\Total Security\hotfix\som_9909aa216b30b502f677bfff05000b0e.dat.tmp (784 bytes)
    %Program Files% (x86)\360\Total Security\hotfix\som_0cd47f5d563ba06a1e44716398931a08.dat.tmp (323 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\360safe\360leakfixer\PatchUp.leakrepair.som.log (17020 bytes)
    %Program Files% (x86)\360\Total Security\hotfix\som_e6e862c79dc156d48370cc4f389eee28.dat.tmp (3 bytes)
    %Program Files% (x86)\360\Total Security\hotfix\som_dbbccf0284b1c6112444badae27b87c1.dat.tmp (49 bytes)
    %Program Files% (x86)\360\Total Security\hotfix\som_4ae7fb61ded98e1cd0fa51382739609d.dat.tmp (3 bytes)
    %Program Files% (x86)\360\Total Security\leakrepair.dat (446 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\netconf.dat (4 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\speedmem2.hg (2091 bytes)
    %Program Files% (x86)\360\Total Security\hotfix\som_b0586730837afd39a4c6ffc29b8b45d1.dat.tmp (49 bytes)
    %Program Files% (x86)\360\Total Security\hotfix\som_f3d59eaa9ff33dcbe50abb4276fbe86c.dat.tmp (49 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\speedmem2.hg-journal (13458 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_d3dcsx_42_x64.cab (49398 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_d3dx9_38_x64.cab (27487 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_d3dx11_42_x64.cab (3051 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2006_XACT_x86.cab (3591 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_XAudio_x86.cab (5874 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\APR2007_XACT_x64.cab (4633 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_d3dx10_41_x64.cab (15925 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_d3dx11_42_x86.cab (1783 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_d3dx11_43_x86.cab (1564 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\NOV2007_X3DAudio_x64.cab (1391 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2008_d3dx10_39_x86.cab (15652 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_XACT_x64.cab (2605 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2006_XACT_x64.cab (3086 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DEC2006_XACT_x86.cab (3227 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2006_xinput_x86.cab (1320 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\APR2007_xinput_x64.cab (1386 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\dsetup32.dll (27267 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2006_MDX1_x86_Archive.cab (72546 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2008_XACT_x86.cab (1707 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2010_XAudio_x86.cab (6136 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2007_d3dx9_36_x86.cab (26253 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_d3dx9_40_x86.cab (22095 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0008.tmp (14404 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_XACT_x64.cab (2473 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\NOV2007_XACT_x86.cab (3849 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2008_XAudio_x86.cab (6895 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2007_d3dx9_35_x64.cab (27382 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_X3DAudio_x64.cab (1985 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2006_XACT_x64.cab (3989 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2007_d3dx9_34_x86.cab (23634 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_d3dx10_42_x86.cab (3771 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DEC2006_d3dx9_32_x64.cab (23092 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\OCT2006_XACT_x86.cab (3491 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\FEB2007_XACT_x64.cab (3357 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_XACT_x86.cab (1671 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_XAudio_x64.cab (6518 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DSETUP.dll (2598 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_d3dx10_38_x64.cab (17923 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2007_XACT_x86.cab (2774 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2006_xinput_x64.cab (2061 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_d3dx11_43_x64.cab (4547 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2006_XACT_x86.cab (3064 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2006_xinput_x86.cab (830 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DXSETUP.exe (11136 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0010.tmp (14404 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\APR2007_xinput_x86.cab (2760 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2006_d3dx9_30_x64.cab (19039 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_D3DCompiler_42_x64.cab (14048 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2007_XACT_x86.cab (2201 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\APR2007_d3dx9_33_x86.cab (23977 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_d3dx10_43_x86.cab (3692 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_XAudio_x64.cab (6514 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_d3dx9_43_x64.cab (17300 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0011.tmp (12676 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DEC2006_XACT_x64.cab (3423 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2006_d3dx9_29_x86.cab (17312 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_X3DAudio_x64.cab (1568 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_d3dx10_40_x86.cab (16648 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_XAudio_x64.cab (6012 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2007_XACT_x64.cab (3999 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_d3dx9_37_x86.cab (20364 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_X3DAudio_x64.cab (581 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\APR2007_XACT_x86.cab (3136 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2006_d3dx9_30_x86.cab (20278 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_XAudio_x64.cab (5815 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DEC2006_d3dx10_00_x64.cab (6385 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_XAudio_x86.cab (4900 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2007_d3dx9_35_x86.cab (34733 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_XACT_x86.cab (1503 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_X3DAudio_x86.cab (21 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\dxupdate.cab (1849 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_D3DCompiler_43_x86.cab (16808 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_XAudio_x86.cab (6547 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_d3dx9_40_x64.cab (30555 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2010_XAudio_x64.cab (6523 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_d3dx10_37_x86.cab (14668 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_d3dcsx_43_x86.cab (14227 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_XAudio_x86.cab (4920 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2008_XAudio_x64.cab (4852 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2005_d3dx9_25_x64.cab (19138 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_D3DCompiler_42_x86.cab (17226 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_d3dx9_41_x64.cab (45112 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\temp_0.tmp (14404 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2007_d3dx10_35_x64.cab (15425 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0002.tmp (14404 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_d3dx9_37_x64.cab (28720 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2007_d3dx10_35_x86.cab (16252 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2005_d3dx9_25_x86.cab (17848 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2006_xinput_x64.cab (3075 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Dec2005_d3dx9_28_x86.cab (17231 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2007_d3dx10_36_x86.cab (18499 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2005_d3dx9_27_x86.cab (17231 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_XAudio_x64.cab (4945 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2007_d3dx10_36_x64.cab (15795 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2005_d3dx9_27_x64.cab (20953 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0004.tmp (14404 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_d3dx9_43_x86.cab (12679 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2010_X3DAudio_x64.cab (683 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2006_d3dx9_29_x64.cab (22025 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_d3dx10_43_x64.cab (6095 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_XAudio_x86.cab (5285 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_d3dx10_40_x64.cab (16329 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0006.tmp (14404 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\NOV2007_X3DAudio_x86.cab (18 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2008_d3dx9_39_x64.cab (27151 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2006_XACT_x64.cab (3624 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2008_d3dx9_39_x86.cab (23198 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2007_d3dx10_34_x86.cab (11482 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2006_MDX1_x86.cab (16914 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2005_d3dx9_24_x64.cab (20378 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2005_d3dx9_26_x64.cab (22088 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0005.tmp (14404 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2007_d3dx9_36_x64.cab (29773 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_XACT_x64.cab (3069 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\APR2007_d3dx10_33_x64.cab (12314 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_X3DAudio_x86.cab (1882 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\OCT2006_XACT_x64.cab (4852 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2007_XACT_x64.cab (5028 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\2.tmp (418 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_XACT_x64.cab (3530 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_d3dcsx_43_x64.cab (14558 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2005_d3dx9_26_x86.cab (19193 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_d3dx10_41_x86.cab (17373 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_d3dx10_37_x64.cab (14641 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\OCT2006_d3dx9_31_x64.cab (20272 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_XACT_x64.cab (3602 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_D3DCompiler_43_x64.cab (17184 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Oct2005_xinput_x86.cab (2114 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2010_XACT_x86.cab (1089 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2007_d3dx10_34_x64.cab (12870 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2010_X3DAudio_x86.cab (841 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2010_XACT_x64.cab (1991 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0003.tmp (14404 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_d3dx9_41_x86.cab (23900 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_d3dx9_38_x86.cab (23827 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\APR2007_d3dx9_33_x64.cab (24421 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_XAudio_x64.cab (5217 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_X3DAudio_x86.cab (21 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2009_XACT_x86.cab (2715 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0001.tmp (14404 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_X3DAudio_x86.cab (1984 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_d3dx10_42_x64.cab (4254 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\15.tmp (110 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Apr2006_XACT_x86.cab (2011 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2008_XACT_x64.cab (2426 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\NOV2007_XACT_x64.cab (4808 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DEC2006_d3dx10_00_x86.cab (4730 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\dxdllreg_x86.cab (1424 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2007_d3dx9_34_x64.cab (24515 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\AUG2006_XACT_x64.cab (3659 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0009.tmp (14404 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_X3DAudio_x64.cab (587 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Dec2005_d3dx9_28_x64.cab (21049 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\FEB2007_XACT_x86.cab (2514 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_d3dcsx_42_x86.cab (51118 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\DEC2006_d3dx9_32_x86.cab (23370 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Mar2008_XACT_x64.cab (3497 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_XACT_x86.cab (2658 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_d3dx9_42_x86.cab (12362 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2006_XACT_x86.cab (3396 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\$inst\0007.tmp (14404 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Jun2010_XAudio_x86.cab (6228 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Oct2005_xinput_x64.cab (638 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2008_d3dx10_39_x64.cab (17527 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\JUN2008_d3dx10_38_x86.cab (15378 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Feb2005_d3dx9_24_x86.cab (23695 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_d3dx9_42_x64.cab (20143 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Aug2009_XACT_x86.cab (1484 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\OCT2006_d3dx9_31_x86.cab (19019 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\APR2007_d3dx10_33_x86.cab (18378 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\setup.tmp\Nov2008_XACT_x86.cab (2729 bytes)
    C:\Windows\Logs\DirectX.log (256 bytes)
    %Program Files% (x86)\360\Total Security\MenuEx64.dll (614 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D285HURO\collect[1].gif (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnE947.tmp\StdUtils.dll (804 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnE947.tmp\System.dll (808 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnE947.tmp\license.rtf (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsd45AA.tmp.exe (6529759 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nss6FC6.tmp.exe (2170387 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JUC72OXY\collect[1].gif (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JUC72OXY\collect[2].gif (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnE946.tmp (6936 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnE947.tmp\nsDialogs.dll (23 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360TS.jpg (1552 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6HVGFTJ0\collect[1].gif (35 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HDZ3KS6S\Directx_9.10.11[1].exe (6103585 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnE947.tmp\inetc.dll (812 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsnE947.tmp\nsRichEdit.dll (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6HVGFTJ0\360TotalSecurity_Rus_Setup_0001[1].exe (2034898 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\stats.txt (140 bytes)
    C:\Windows\System32\drivers\360fsflt.sys (1740 bytes)
    %Program Files% (x86)\360\Total Security\safemon\SelfProtectAPI2.dll (319 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\360FsFlt.sys (315 bytes)
    \\192.168.50.163\PIPE\srvsvc (14264 bytes)
    %Program Files% (x86)\360\Total Security\ipc\360Camera64.sys (40 bytes)
    %Program Files% (x86)\360\Total Security\safemon\WDRecord.dll (184 bytes)
    %Program Files% (x86)\360\Total Security\Logs\Administrators\ipc\galaxy2.dat (17110 bytes)
    %Program Files% (x86)\360\Total Security\safemon\param.ini (24 bytes)
    %Program Files% (x86)\360\Total Security\ipc\filecache\FileCache.dat (1123 bytes)
    %Program Files% (x86)\360\Total Security\sites.dll (49 bytes)
    %Program Files% (x86)\360\Total Security\scanstub.dll (176 bytes)
    %Program Files% (x86)\360\Total Security\safescan.dll (348 bytes)
    %Program Files% (x86)\360\Total Security\safemon\filelog.db (1141 bytes)
    %Program Files% (x86)\360\Total Security\ipc\qutmipc.dll (167 bytes)
    %Program Files% (x86)\360\Total Security\filemon\WhiteCache.dll (49 bytes)
    %Program Files% (x86)\360\Total Security\softmgr\SoftMgr.db (1 bytes)
    C:\ProgramData\360safe\LogInfo\New360_tmp_1429761230_2620.log2 (460 bytes)
    %Program Files% (x86)\360\Total Security\ipc\filecache\FileCache.dat{488f2569-df83-11e4-91a7-0050562b2045}.TMContainer00000000000000000002.regtrans-ms (712 bytes)
    %Program Files% (x86)\360\Total Security\ipc\360AntiHacker64.sys (102 bytes)
    %Program Files% (x86)\360\Total Security\ipc\filecache\FileCache.dat{488f2569-df83-11e4-91a7-0050562b2045}.TM.blf (2654 bytes)
    %Program Files% (x86)\360\Total Security\filemon\wcachedb.db (345 bytes)
    %Program Files% (x86)\360\Total Security\softmgr\somkernl.dll (291 bytes)
    %Program Files% (x86)\360\Total Security\softmgr\SomAdvUtils.dll (888 bytes)
    %Program Files% (x86)\360\Total Security\softmgr\SoftMgr.db-journal (512 bytes)
    %Program Files% (x86)\360\Total Security\filemon\360AVFlt64.sys (81 bytes)
    %Program Files% (x86)\360\Total Security\ipc\filecache\FileCache.dat.LOG1 (1048 bytes)
    %Program Files% (x86)\360\Total Security\ipc\yhregd.dll (409 bytes)
    C:\Windows\System32\drivers\360Camera64.sys (40 bytes)
    %Program Files% (x86)\360\Total Security\safemon\filelog.db-journal (5490 bytes)
    %Program Files% (x86)\360\Total Security\filemon\wcachedb.db-journal (528 bytes)
    %Program Files% (x86)\360\Total Security\ipc\filecache\FileCache.dat{488f2569-df83-11e4-91a7-0050562b2045}.TMContainer00000000000000000001.regtrans-ms (1224 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\ipc\filemon.dat (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\udisk.locale (444 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\safemon\drvmon.dat (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\urllib.dat (600 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360P2SP.dll (9112 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\360InternationTray\image\toast_speed_slow.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\libsdi.dat (84 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\safemon\SelfProtectAPI2.dll.locale (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\Safemon.dll.locale (21 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\gamemode.tpi (129 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\DsSysRepair.dll (6372 bytes)
    %Program Files% (x86)\360\Total Security\ipc\appdef.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360SelfProtection.sys (1691 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\ipc\Sxin64.dll.locale (14 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\safemon\UDiskScanEngine.dll.locale (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\SelfProtectAPI2.dll.locale (12 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\regmon.dat (47 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360liveupdate\360liveupdate_theme.ui (137 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\UrlSettings.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360InternationTray\image (4 bytes)
    %Program Files% (x86)\360\Total Security\tools.xml (2 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\ipc\appmon.dat (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\endata\h_2.dat (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\UrlSettings.dll.locale (12 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\safemon\udisk.locale (486 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\360SPTool.exe.locale (32 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\ipc\Sxin.dll.locale (14 bytes)
    %Program Files% (x86)\360\Total Security\filemon\360rp.dll (18248 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\webprotection_firefox\plugins\nptswp.dll.locale (9 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\appmon.dat (21 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\deepscan\dsr.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wificonfig\ra1000.dat (607 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\safemon.dll.locale (21 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\wificonfig\ra1005.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\UDiskScanEngine.dll.locale (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\deepscan\dsr.dat (1020 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\QHSafeTray.exe (10758 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\libaw.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360NetBase.dll (4426 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\360ipc.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\deepscan\DsRes64.dll (1548 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\safemon\360procmon.dll.locale (601 bytes)
    %Program Files% (x86)\360\Total Security\safemon\wdk.ini (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\filemon.dat (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\Sxin64.dll.locale (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\deepscan\art.dat (18 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\dsbs.dat (38 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\deepscan\art.dat (18 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\appdext.dll (1726 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360NetBase64.dll (4336 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\360SPTool.exe.locale (32 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\deepscan\DsRes.dll (62 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\UDiskScanEngine.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\deepscan.dll (17072 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\ipc\filemgr.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\360SPTool.exe.locale (32 bytes)
    %Program Files% (x86)\360\Total Security\config\lang\hi\SysSweeper.ui.dat (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\safemon\360SPTool.exe.locale (32 bytes)
    %Program Files% (x86)\360\Total Security\safemon\webprotection_firefox\chrome\content\main.js (2 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\DsSysRepair.dll (3073 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\webprotection_firefox\chrome.manifest (275 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\WDRecord.dll (1920 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\regmon.dat (47 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360InternationTray\image\toast_speed_slow.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\360ipc.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\filemon.dat (18 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\sweeper\CleanHelper64.exe (723 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\deepscan\dsurls.dat (844 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\ipc\regmon.dat (44 bytes)
    %Program Files% (x86)\360\Total Security\EfiMon.sys (23 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\ImAVEng.dll (1507 bytes)
    %Program Files% (x86)\360\Total Security\scanbase.dll (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\deepscan\dsr.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\360ipc.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\3G\LibOui.dat (2105 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\360AvFlt.sys (68 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\dynlenv.dll (4491 bytes)
    %Program Files% (x86)\360\Total Security\filemon\360avflt64.sys (601 bytes)
    %Program Files% (x86)\360\Total Security\DumpUper.ini (170 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\NetDefender.dll.locale (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\updatecfg.ini (128 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\drvmk.dat (52 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\filemgr.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\deepscan\DsRes.dll (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\libdefa.dat (160 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\ipc\regmon.dat (44 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\default_theme.ui (2321 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\ipc\filemon.dat (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\urlproc.dll (4863 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wificonfig\ra1005.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\sweeper\CleanHelper64.exe (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\safemon\360SafeCamera.tpi.locale (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (111 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\deepscan\dsconz.dat (12 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\PopSoftEng.dll (3073 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\deepscan\DsRes64.dll (601 bytes)
    %Program Files% (x86)\360\Total Security\CleanPlus.dll (1281 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\WifiAgent.dll (1281 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\Sxin.dll.locale (16 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\ipc\360netd.dat (29 bytes)
    %Program Files% (x86)\360\Total Security\safemon\360GuardBase.dll (1425 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\ipc\filemon.dat (17 bytes)
    %Program Files% (x86)\360\Total Security\sweeper\SysSweeper.dat (5441 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\libdefa.dat (213 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\NetDefender.dll.locale (17 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\libsdi.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\SelfProtectAPI2.dll.locale (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\leakrepair.dll (8648 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\filemon.dat (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\wd.ini (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360TsLiveUpd.exe (8594 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\NetDefender.dll.locale (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\qex\qex.dll (14497 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\360SafeCamera.tpi.locale (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\sites.dll (10999 bytes)
    %Program Files% (x86)\360\Total Security\360Common.dll (1425 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\360Downloads.ini (269 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\libaw.dat (2343 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\360netr.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\deepscan\art.dat (18 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\udisk.locale (334 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\filemon.dat (17 bytes)
    %Program Files% (x86)\360\Total Security\360Util.dll (3073 bytes)
    %Program Files% (x86)\360\Total Security\safemon\360AV.tpi (1425 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\safemon\360SafeCamera.tpi.locale (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\360netd.dat (29 bytes)
    %Program Files% (x86)\360\Total Security\safemon\360uac.dat (8 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\360leakfix\360leakfix_theme.ui (1425 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\safemon\wd.ini (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\chrome\360webshield.exe.locale (15 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\AntiAdwa.dll.locale (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\deepscan (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\fr4.dat (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\1429760925_00000000_base\360base.dll (1815 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\deepscan\dsurls.dat (844 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\sweeper\TrashClean.dll (4180 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\deepscan\dsr.dat (87 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\dswtb.dat (1425 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\360netr.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\filemon\fr8.dat (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360.dat (13 bytes)
    %Program Files% (x86)\360\Total Security\i18n\i18n.ini (490 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\filemgr.dll.locale (11 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\csp.dat (8 bytes)
    %Program Files% (x86)\360\Total Security\rpi.dat (972 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\wificonfig\ra1000.dat (607 bytes)
    %Program Files% (x86)\360\Total Security\ipc\360AntiHacker.sys (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\safemon\wd.ini (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\360netd.dat (29 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\deepscan\DsRes64.dll (64 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\PatchUp.exe (6084 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\libvi.dat (3073 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\3G\3GIdentify.dll (3418 bytes)
    %Program Files% (x86)\360\Total Security\filemon\360AvFlt.dll (95 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\360procmon.dll.locale (101 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\AVE\AVEngine.dll (7345 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\qex\MacroDef.enc (6 bytes)
    %Program Files% (x86)\360\Total Security\safemon\webprotection_firefox\install.rdf (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\deepscan\dsconz.dat (12 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\DsArk.sys (601 bytes)
    %Program Files% (x86)\360\Total Security\360SkinView.exe (2105 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\deepscan\dsconz.dat (12 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\ipc\appmon.dat (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\360ipc.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\safemon\360procmon.dll.locale (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\ipc\Sxin.dll.locale (16 bytes)
    %Program Files% (x86)\360\Total Security\360ShellPro.exe (673 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\ipc\appd.dll.locale (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\UrlSettings.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\scanbase.dll (1123 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\safemon\360SafeCamera.tpi.locale (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\deepscan\ssr.dat (53 bytes)
    %Program Files% (x86)\360\Total Security\ipc\appdext.dll (673 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\deepscan\DsRes.dll (601 bytes)
    %Program Files% (x86)\360\Total Security\I18N.dll (691 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\libdefa.dat (673 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\iNetSafe.dll (2464 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360Base64.dll (7247 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\NetDefender.dll.locale (13 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\dswc.dat (50 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\NetDefender.dll.locale (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\feedback\FeedBack_theme.ui (87 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\LibSDI.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360ShellPro.exe (2114 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\safemon\drvmon.dat (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\Safemon.dll.locale (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\CombineExt.dll (1567 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\360netr.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\deepscan\DsRes64.dll (1542 bytes)
    %Program Files% (x86)\360\Total Security\ipc\clsid.dat (22 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\deepscan\dsconz.dat (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\360netd.dat (29 bytes)
    %Program Files% (x86)\360\Total Security\360Base.dll (6841 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\libaw.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\deepscan\DsRes64.dll (1370 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\netmon\gameidentify.dat (91 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\3G\LibOui.dat (365 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\filemon.dat (18 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\360SPTool.exe.locale (28 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\LibOui.dat (20 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\AntiAdwa.dll.locale (34 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\360SafeCamera.tpi.locale (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\appd.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\wd.ini (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\yhregd.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\safemon\drvmon.dat (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\deepscan\art.dat (19 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\ipc\360netd.dat (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\UDiskScanEngine.dll.locale (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\360SafeCamera.tpi.locale (1 bytes)
    %Program Files% (x86)\360\Total Security\sweeper\SysSweeper.dll (4545 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\wd.ini (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\endata\h_1.dat (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\360netr.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\libdefa.dat (673 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\deepscan\art.dat (18 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\SelfProtectAPI2.dll.locale (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360GuardBase.dll (4626 bytes)
    %Program Files% (x86)\360\Total Security\MenuEx.dll (2321 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\regmon.dat (44 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\UDiskScanEngine.dll.locale (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\AVLib.dat (360 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\ipc\Sxin.dll.locale (15 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\Sxin64.dll.locale (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\QHToasts.exe (3100 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\libdefa.dat (673 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\qutmdrv.sys (1281 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\ipc\regmon.dat (44 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\drvmon.dat (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\filemon.dat (17 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\deepscan\dsconz.dat (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\zh-CN\SysSweeper.ui.dat (114 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\CheckSM.dll (1425 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\libaw.dat (9605 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\AntiAdwa.dll.locale (38 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\safemon\safemon.dll.locale (20 bytes)
    %Program Files% (x86)\360\Total Security\dynlbase.dll (6841 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\ipc\360netr.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\wificonfig\ra1003.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\360DeskAna.exe (1425 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\DsArk.dll (673 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\wdk.ini (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\deepscan\dsr.dat (82 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\360SafeCamera.tpi.locale (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\chrome\360webshield.exe.locale (15 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\safemon\360SPTool.exe.locale (32 bytes)
    %Program Files% (x86)\360\Total Security\safemon\360drwht.dat (42 bytes)
    %Program Files% (x86)\360\Total Security\safemon\QHToasts.exe (1425 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\deepscan\dsurls.dat (844 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\deepscan\art.dat (18 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\regmon.dat (46 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\libdefa.dat (673 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\deepscan\dsr.dat (82 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\deepscan\DsRes64.dll (601 bytes)
    %Program Files% (x86)\360\Total Security\Sites64.dll (15019 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\360SPTool.exe.locale (32 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\ipc\regmon.dat (44 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360zipc.dll (5513 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\360SafeCamera.tpi.locale (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\hookport.sys (397 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360uac.dat (8 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\360InternationSafe\360InternationSafe_theme.ui (55596 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\deepscan\dsr.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360DeskAna64.exe (3906 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\LibSDI.dat (601 bytes)
    %Program Files% (x86)\360\Total Security\ipc\DrvUtility.dll (828 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\deepscan\DsRes.dll (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\DumpUper.ini (170 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\360ipc.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\safemon\360procmon.dll.locale (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\Dumpuper.exe.locale (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\deepscan\dsconz.dat (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\wdui2.dll (7710 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\router.ini (274 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp.7z (27684 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\udiskscan.dat (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\deepscan\dsurls.dat (844 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\ptype.dat (2 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\UrlSettings.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\vi\SysSweeper.ui.dat (128 bytes)
    %Program Files% (x86)\360\Total Security\softmgr\360SoftMgrS.dll (2321 bytes)
    %Program Files% (x86)\360\Total Security\safemon\360zipc.dll (4185 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\drvmon.dat (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\libvi.dat (130 bytes)
    %Program Files% (x86)\360\Total Security\filemon\360AvFlt.sys (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\safemon\udisk.locale (490 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\filemon.dat (17 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\libdefa.dat (673 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\360SPTool.exe.locale (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\PDown.dll (2025 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\deepscan\dsr.dat (601 bytes)
    %Program Files% (x86)\360\Total Security\ipc\360AntiHacker.dll (52 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\libvi.dat (130 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\SomAdvUtils.dll (8690 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\Sxin64.dll.locale (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360Util.dll (5342 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\AntiAdwa.dll.locale (601 bytes)
    %Program Files% (x86)\360\Total Security\360net.dll (3073 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\360procmon.dll.locale (101 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\DSFScan.dll (3996 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\deepscan\dsr.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\libaw.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\360Base64.dll (7547 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\libvi.dat (130 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\LibOui.dat (20 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\libvi.dat (130 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\qutmipc.dll (2626 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\ipcService.dll (5373 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360skinview\360skinview_theme.ui (45 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\wificonfig\ra1004.dat (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\libaw.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\qex\patt.enc (2321 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\deepscan\DsRes.dll (1406 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\deepscan\DsRes.dll (64 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\Dumpuper.exe.locale (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\wd.ini (8 bytes)
    %Program Files% (x86)\360\Total Security\ipc\360boxld64.exe (673 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\TR\SysSweeper.ui.dat (123 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\ipc\360ipc.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\deepscan\art.dat (29 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\safemon\wdk.ini (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\DsArk.dll (1796 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\deepscan\DsRes.dll (601 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\cloudsec2.dll (7547 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\deepscan\ssr.dat (45 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wificonfig\ra1004.dat (2 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\ipc\yhregd.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\360skinview\360skinview_theme.ui (45 bytes)
    %Program Files% (x86)\360\Total Security\safemon\hookport.sys (58 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\filemgr.dll.locale (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\AntiAdwa.dll.locale (89 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\deepscan\dsconz.dat (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\regmon.dat (44 bytes)
    %Program Files% (x86)\360\Total Security\safemon\360SPTool.exe (673 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\safemon\udisk.locale (254 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\deepscan\dsconz.dat (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\deepscan\dsr.dat (55 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\safemon\safemon.dll.locale (20 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\appmon.dat (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\deepscan\DsRes64.dll (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\Sxin64.dll.locale (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\deepscan\DsRes.dll (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\Sxin.dll.locale (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\libvi.dat (130 bytes)
    %Program Files% (x86)\360\Total Security\safemon\wdui3.dll (5441 bytes)
    %Program Files% (x86)\360\Total Security\360TsLiveUpd.exe (6841 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\ipc\360netd.dat (29 bytes)
    %Program Files% (x86)\360\Total Security\safemon\QHWatchdog.exe (601 bytes)
    %Program Files% (x86)\360\Total Security\libredlist.dat (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\360procmon.dll.locale (100 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\QHVer.dll (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\Sxin64.dll.locale (16 bytes)
    %Program Files% (x86)\360\Total Security\safemon\WDPayPro.exe (9098 bytes)
    %Program Files% (x86)\360\Total Security\config\config.xml (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\SomProxy.dll (3594 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\safemon\360SPTool.exe.locale (32 bytes)
    %Program Files% (x86)\360\Total Security\softmgr\AdvUtils.ini (146 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360InternationTray\image\toast_speed_reallyfast.png (2 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\Dumpuper.exe.locale (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\signbwl.dat (684 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\SelfProtectAPI2.dll.locale (15 bytes)
    %Program Files% (x86)\360\Total Security\ipc\360Box.sys (1281 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\NetDefender.dll.locale (13 bytes)
    %Program Files% (x86)\360\Total Security\filemon\fr4.dat (7 bytes)
    %Program Files% (x86)\360\Total Security\dynlenv.dll (3361 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\webprotection_firefox\icon64.png (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\MenuEx.dll (3246 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\ipc\appd.dll.locale (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\libdefa.dat (160 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\Sxin.dll.locale (16 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\safemon\UDiskScanEngine.dll.locale (8 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\wificonfig\ra1001.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\libleak.dat (228 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\wdk.ini (3 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\360InternationTray\image\toast_speed_reallyfast.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\cloudsec2.dll (8633 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\ipc\filemgr.dll.locale (11 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\stsuglist.dat (112 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\libvi.dat (130 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\rpi.dat (972 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\deepscan\DsRes.dll (1465 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\zh-TW\SysSweeper.ui.dat (114 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\Sxin.dll.locale (16 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\safemon\UDiskScanEngine.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\ipc\Sxin64.dll.locale (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\360QuarantPlugin.dll (4573 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\LibSDI.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\UrlSettings.dll.locale (12 bytes)
    %Program Files% (x86)\360\Total Security\config\lang\zh-TW\SysSweeper.ui.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\chrome\360webshield.exe.locale (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (112 bytes)
    %Program Files% (x86)\360\Total Security\MiniUI.dll (6841 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\drvms.dat (3 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\deepscan\ssr.dat (48 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\libvi.dat (130 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\yhregd.dll.locale (9 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\safemon\UDiskScanEngine.dll.locale (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\360netd.dat (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\wdk.ini (3 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\safemon\Safemon.dll.locale (21 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\DSFScan.dll (2105 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\NetDefender.dll.locale (16 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\Dumpuper.exe.locale (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\SXIn.dll (5904 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\Dumpuper.exe.locale (1 bytes)
    %Program Files% (x86)\360\Total Security\config\lang\ru\SysSweeper.ui.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\netmon\Netgm.dll (3254 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dswc.dat (50 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\safemon\chrome\360webshield.exe.locale (15 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\safemon\chrome\360webshield.exe.locale (15 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\UrlSettings.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\UDiskScanEngine.dll.locale (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\fr5.dat (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\deepscan\ssr.dat (48 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\sndw.dat (10 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\ipc\Sxin64.dll.locale (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\Cloudsec3.dll (8817 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\ipc\Sxin.dll.locale (16 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\appd.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\cloudcom2.dll (7547 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\ipc\Sxin.dll.locale (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\appd.dll.locale (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\qutmload.dll (1833 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\ipc\NetDefender.dll.locale (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\chrome\360webshield.exe.locale (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\AVE\AVEngine.dll (8584 bytes)
    %Program Files% (x86)\360\Total Security\safemon\WscReg.exe (22336 bytes)
    %Program Files% (x86)\360\Total Security\ipc\360boxmain.exe (4185 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\QHSafeMain.exe (29771 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\ipc\yhregd.dll.locale (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\LibSDI.dat (78 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\ipc\yhregd.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\deepscan\art.dat (18 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\yhregd.dll.locale (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360InternationTray\image\toasts_waring.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\360SoftMgrS.dll (4865 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\360rp.dll (20395 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\deepscan\DsRes64.dll (377 bytes)
    %Program Files% (x86)\360\Total Security\PDown.dll (1281 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\yhregd.dll.locale (11 bytes)
    %Program Files% (x86)\360\Total Security\endata\h_3.dat (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\Dumpuper.exe.locale (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\deepscan\art.dat (16 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\deepscan\DsRes.dll (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\Dumpuper.exe.locale (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\config.xml (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\AntiAdwa.dll.locale (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\SelfProtectAPI2.dll.locale (11 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\wificonfig\ra1002.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\BAPI.dll (1526 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\X64For32Lib.dll (53 bytes)
    %Program Files% (x86)\360\Total Security\ipc\360boxld.exe (673 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\chrome\360webshield.exe.locale (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\deepscan\ssr.dat (45 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\wd.ini (8 bytes)
    %Program Files% (x86)\360\Total Security\endata\h_1.dat (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\deepscan\dsconz.dat (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safescan.dll (2325 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\LibSDI.dat (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\UrlSettings.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\CQhCltHttpW.dll (3932 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360drwht.dat (42 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\360wdui\360wdui_theme.ui (5441 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\deepscan\dsconz.dat (12 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\wd.ini (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\deepscan\dsr.dat (82 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\NetDefender.dll.locale (14 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\ipc\appd.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\filemgr.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\chrome\manifest.json (332 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\udisk.locale (334 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\SelfProtectAPI2.dll.locale (14 bytes)
    %Program Files% (x86)\360\Total Security\safemon\drvms.dat (3 bytes)
    %Program Files% (x86)\360\Total Security\PatchUp.exe (5441 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360AntiHacker.sys (1101 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\ipc\Sxin.dll.locale (14 bytes)
    %Program Files% (x86)\360\Total Security\AntiAdwa.dll (22336 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\360netd.dat (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\webprotection_firefox\chrome\content\main.js (2 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\ipc\360netd.dat (29 bytes)
    %Program Files% (x86)\360\Total Security\safemon\chrome\360webshield.exe (1425 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\libredlist.dat (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\udisk.locale (490 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360Verify.dll (1321 bytes)
    %Program Files% (x86)\360\Total Security\safemon\chrome\manifest.json (332 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\360CleanPlus\360CleanPlus_theme.ui (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\360procmon.dll.locale (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\Dumpuper.exe.locale (1 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\art.dat (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\WifiAgent.dll (2742 bytes)
    %Program Files% (x86)\360\Total Security\ipc\cleancfg.dat (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\EfiProc.dll (1742 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\ipc\Sxin64.dll.locale (16 bytes)
    %Program Files% (x86)\360\Total Security\libleakres.dat (16582 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\wificonfig\ra1006.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\Uninstall.exe (12812 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\dserror.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\ipc\FileMgr.dll (2105 bytes)
    %Program Files% (x86)\360\Total Security\writeable_test_495427.dat (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\SXIn64.dll (5863 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\360SPTool.exe.locale (28 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\safemon\360SafeCamera.tpi.locale (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\safemon\360procmon.dll.locale (601 bytes)
    %Program Files% (x86)\360\Total Security\softmgr\safespeedboot.dat (25 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\360netd.dat (29 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\Dumpuper.exe.locale (1 bytes)
    %Program Files% (x86)\360\Total Security\libleak-64.dat (22575 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\regmon.dat (44 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\safemon\SelfProtectAPI2.dll.locale (13 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\libvi.dat (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\libvi.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\pt\SysSweeper.ui.dat (123 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\NetDefender.dll.locale (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wificonfig\ra1002.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\ipc\NetDefender.dll.locale (16 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\chrome\360webshield.exe.locale (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\deepscan.dll (22163 bytes)
    C:\Windows\System32\drivers\360Box64.sys (1425 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\deepscan\art.dat (19 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\safemon\webprotection_firefox\plugins\nptswp.dll.locale (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\AVE\AVEI.dll (1750 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\Sxin64.dll.locale (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\CheckSM.exe (3191 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\360netcfg.exe (1281 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\tools.xml (2 bytes)
    %Program Files% (x86)\360\Total Security\ipc\TS.dat (748 bytes)
    %Program Files% (x86)\360\Total Security\config\defaultskin\defaultskin.ui (1281 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\safemon\Safemon.dll.locale (20 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\UDiskScanEngine.dll (4765 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\qex\qex.dll (11518 bytes)
    %Program Files% (x86)\360\Total Security\filemon\FsrMgr.dll (1281 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360wdui\360wdui_theme.ui (735 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\sysfilerepS.dll (1425 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\deepscan\dsconz.dat (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\SxWrapper.dll (1169 bytes)
    %Program Files% (x86)\360\Total Security\mui\en\Strings.dat (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\libsdi.dat (1673 bytes)
    %Program Files% (x86)\360\Total Security\endata\h_2.dat (2 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\safemon\SelfProtectAPI2.dll.locale (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\360ipc.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\ipc\filemon.dat (17 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\libsdi.dat (601 bytes)
    %Program Files% (x86)\360\Total Security\safemon\360SafeCamera.tpi (2321 bytes)
    %Program Files% (x86)\360\Total Security\ipc\SXIn.dll (3073 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dserror.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\ipc\NetDefender.dll.locale (15 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\Antiadwa.dll.locale (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\AntiAdwa.dll.locale (87 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\WiFiSafe.dll (13152 bytes)
    %Program Files% (x86)\360\Total Security\Dumpuper.exe (4545 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\appd.dll.locale (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\7z.dll (50 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\deepscan\art.dat (20 bytes)
    %Program Files% (x86)\360\Total Security\endata\lm_1001.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360Conf.dll (3082 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\filemgr.dll.locale (11 bytes)
    %Program Files% (x86)\360\Total Security\ipc\signbwl.dat (684 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\deepscan\DsRes.dll (29 bytes)
    %Program Files% (x86)\360\Total Security\ipc\qutmipc.sys (45 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\regmon.dat (44 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\ipc\NetDefender.dll.locale (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\360SPTool.exe.locale (31 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\ipc\360netr.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\AntiAdwa.dll.locale (1279 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\ipc\appd.dll.locale (14 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\ipc\Sxin.dll.locale (16 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\Safemon.dll.locale (18 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\360Quarant.dll (4397 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\safemon\webprotection_firefox\plugins\nptswp.dll.locale (9 bytes)
    %Program Files% (x86)\360\Total Security\safemon\QHActiveDefense.exe (5873 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\UrlSettings.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360UDisk\360UDisk_theme.ui (237 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\Antiadwa.dll.locale (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\WhiteCache.dll (12119 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\Sxin.dll.locale (15 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\libvi.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\360AvFlt.dll (46 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\deepscan\DsRes.dll (1483 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360ipc.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\appd.dll.locale (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\cacert.pem (229 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\deepscan\ssr.dat (53 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\appd.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\cloudcom2.dll (10255 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\deepscan\DsRes64.dll (58 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\safemon\wdk.ini (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\Optadn.dat (11 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\deepscan\dsurls.dat (844 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\dsns.dat (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\deepscan\DsRes.dll (1551 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\drvmon.dat (4 bytes)
    %Program Files% (x86)\360\Total Security\softmgr\SpeedUp.dll (673 bytes)
    %Program Files% (x86)\360\Total Security\netmon\360GameIdentify.dll (1281 bytes)
    %Program Files% (x86)\360\Total Security\safemon\360safemonpro.tpi (7971 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\ipc\360ipc.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\safemon\wd.ini (8 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\CQhCltHttpW.dll (2321 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dswtb.dat (263 bytes)
    %Program Files% (x86)\360\Total Security\softmgr\Optadn.dat (11 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\UrlSettings.dll.locale (12 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\safemon\UDiskScanEngine.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\360bps.dat (676 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\LibSDI.dat (77 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\SpeedUp.dll (4095 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\drvmon.dat (4 bytes)
    %Program Files% (x86)\360\Total Security\QHSafeMain.exe (26096 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\dsws.dat (1425 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\qex\patt.enc (416 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\defaultskin\MiniUI.xml (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360net.dll (4879 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\deepscan\dsconz.dat (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\execrule.dat (100 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\deepscan\dsconz.dat (12 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\deepscan\DsRes64.dll (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\360SafeCamera.tpi.locale (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (601 bytes)
    %Program Files% (x86)\360\Total Security\safemon\360hipsPopWnd.dll (7726 bytes)
    %Program Files% (x86)\360\Total Security\safemon\urllib.dat (4185 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\deepscan\dsr.dat (82 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\AntiAdwa.dll (29035 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\deepscan\ssr.dat (47 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\ru\SysSweeper.ui.dat (127 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\360FsFlt.sys (2375 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\CrashReport.dll (4712 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\ipc\regmon.dat (44 bytes)
    %Program Files% (x86)\360\Total Security\CleanPlus.exe (4185 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\deepscan\dsurls.dat (844 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\libvi.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\wd.ini (8 bytes)
    %Program Files% (x86)\360\Total Security\config.ini (278 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\libdefa.dat (673 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\deepscan\art.dat (18 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\deepscan\art.dat (18 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360CleanPlus\360CleanPlus_theme.ui (109 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\BAPI.dll (3138 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\360sandbox\360sandbox_theme.ui (1425 bytes)
    %Program Files% (x86)\360\Total Security\safemon\webprotection_firefox\chrome\content\browser.xul (560 bytes)
    C:\Windows\System32\drivers\BAPIDRV64.SYS (857 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\Sxin.dll.locale (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\wdk.ini (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wificonfig\ra1006.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\safemon\SelfProtectAPI2.dll.locale (15 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\ipc\360netr.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\en\SysSweeper.ui.dat (115 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\sweeper\RemoteTrashInterface.dll (5508 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\ipc\360ipc.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\filemgr.dll.locale (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\appmon.dat (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\Sxin64.dll.locale (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360AntiHacker64.sys (1878 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\360netd.dat (29 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\libaw.dat (10177 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\libsdi.dat (83 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\safemon\360procmon.dll.locale (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\libvi.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\Dumpuper.exe.locale (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\libdefa.dat (162 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\ipc\filemon.dat (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\I18N.dll (280 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\chrome\360webshield.exe.locale (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360Box64.sys (2931 bytes)
    %Program Files% (x86)\360\Total Security\softmgr\SomAdvUtilsWrap.dll (3073 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\360ipc.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\DrvUtility.dll (728 bytes)
    %Program Files% (x86)\360\Total Security\CrashReport.dll (1425 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\UrlSettings.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360Camera.sys (1687 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\safemon\360procmon.dll.locale (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\UDiskScanEngine.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\netmon\Netgm.dll (1425 bytes)
    %Program Files% (x86)\360\Total Security\ipc\360Box.dll (45 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\safemon\drvmon.dat (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\qutmdrv.sys (3004 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\udisk.locale (470 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360bps.dat (676 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360InternationSafe\360InternationSafe_theme.ui (1363 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\udisk.locale (254 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\wdui3.dll (8454 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\deepscan\DsRes64.dll (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\Sxin64.dll.locale (16 bytes)
    %Program Files% (x86)\360\Total Security\safemon\webprotection_firefox\chrome.manifest (275 bytes)
    %Program Files% (x86)\360\Total Security\safemon\360SelfProtection.sys (673 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\360SPTool.exe.locale (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\tools\Tools_theme.ui (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\LibSDI.dat (95 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360SafeCamera.tpi (404 bytes)
    %Program Files% (x86)\360\Total Security\config\lang\pt\SysSweeper.ui.dat (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\libvi.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dsbs.dat (38 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\SomAdvUtilsWrap.dll (5248 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\CheckSM.dll (4562 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\libaw.dat (457 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\UDiskScanEngine.dll.locale (8 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\libaw.dat (9605 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\360netcfg.exe (2047 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\drvmon.dat (5 bytes)
    %Program Files% (x86)\360\Total Security\safemon\360Tray.exe (1425 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\libleak-64.dat (275 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\libvi.dat (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\Dumpuper.exe.locale (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\safemon\wd.ini (8 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\safemon\udisk.locale (482 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\filemon.dat (18 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360Box.dll (1873 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360boxld.exe (1209 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\deepscan\DsRes64.dll (635 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\filemon.dat (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\wd.ini (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\deepscan\DsRes64.dll (2492 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\udisk.locale (486 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\UDiskScanEngine.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\safemon\SelfProtectAPI2.dll.locale (14 bytes)
    %Program Files% (x86)\360\Total Security\safemon\dlproc.dll (4545 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dsark64.sys (1346 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\deepscan\art.dat (20 bytes)
    %Program Files% (x86)\360\Total Security\I18N64.dll (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\drvmon.dat (5 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\ipc\yhregd.dll.locale (11 bytes)
    %Program Files% (x86)\360\Total Security\LiveUpdate360.exe (4185 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\WDSafeDown.exe (1726 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\ipc\NetDefender.dll.locale (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\wdk.ini (3 bytes)
    %Program Files% (x86)\360\Total Security\safemon\webprotection_firefox\icon64.png (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\yhregd.dll.locale (11 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\deepscan\dsr.dat (55 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\AntiAdwa.dll.locale (81 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\filemon\AVLib.dat (2105 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360Common.dll (2070 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\deepscan\DsRes64.dll (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\safemon\360SPTool.exe.locale (32 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\ipc\Sxin64.dll.locale (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dsr.dat (82 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\Dumpuper.exe.locale (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\filemgr.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\SelfProtectAPI2.dll.locale (14 bytes)
    %Program Files% (x86)\360\Total Security\filemon\fr1.dat (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\360procmon.dll.locale (100 bytes)
    %Program Files% (x86)\360\Total Security\ipc\NetDefender.dll (1425 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\libleakres.dat (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\yhregd.dll (5739 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\deepscan\art.dat (18 bytes)
    %Program Files% (x86)\360\Total Security\safemon\drvmk.dat (52 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\appdef.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\webprotection_firefox\icon.png (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\360netr.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\3G\3GIdentify.dll (1281 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\dsconz.dat (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\deepscan\dsr.dat (82 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\deepscan\DsRes64.dll (62 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\360SPTool.exe.locale (30 bytes)
    %Program Files% (x86)\360\Total Security\ipc\360Box64.sys (1425 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\360InternationTray\image\toasts_waring.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\LibSDI.dat (83 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\filemgr.dll.locale (11 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\ipc\NetDefender.dll.locale (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360boxld64.exe (3243 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\deepscan\DsRes64.dll (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\appd.dll.locale (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\UrlSettings.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\TS.dat (748 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\writeable_test_495552.dat (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\filemon.dat (17 bytes)
    C:\Windows\System32\drivers\360AntiHacker64.sys (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\LiveUpd360.dll (4830 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\appmon.dat (21 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\deepscan\ssr.dat (48 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\ipc\filemgr.dll.locale (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\360ipc.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\360SPTool.exe.locale (32 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\Dumpuper.exe.locale (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\libaw.dat (9605 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\360netd.dat (29 bytes)
    %Program Files% (x86)\360\Total Security\Utils\ModuleUpdate.exe (4185 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\safemon\wd.ini (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\360SafeCamera.tpi.locale (1 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\QVM\360QVM.dll (5873 bytes)
    %Program Files% (x86)\360\Total Security\ipc\360ipc.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\ipc\NetDefender.dll.locale (16 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\safemon\wdk.ini (3 bytes)
    %Program Files% (x86)\360\Total Security\safemon\udiskscan.dat (3 bytes)
    %Program Files% (x86)\360\Total Security\sweeper\RemoteTrashInterface.dll (3073 bytes)
    %Program Files% (x86)\360\Total Security\360Conf.dll (1425 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\deepscan\art.dat (18 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dsns.dat (2 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\UrlSettings.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wificonfig\ra1003.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\dslw\dslw.dat (5441 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\webprotection_firefox\plugins\nptswp.dll (3914 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\WDPayPro.exe (12859 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\safemon.dll.locale (20 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\libdefa.dat (160 bytes)
    %Program Files% (x86)\360\Total Security\safemon\wduicfg.dat (10 bytes)
    %Program Files% (x86)\360\Total Security\safemon\360procmon.dll (2321 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\Dumpuper.exe.locale (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\chrome\360webshield.exe.locale (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\Safemon.dll.locale (18 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\AVE\AVEI.dll (673 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\libdefa.dat (162 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\FeedBack.exe (7209 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\BAPIDRV.sys (673 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\regmon.dat (44 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\safemon\wdk.ini (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\Antiadwa.dll.locale (89 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\libaw.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\safemon\drvmon.dat (4 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\ipc\360netr.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360Camera64.sys (526 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\webprotection_firefox\plugins\nptswp.dll.locale (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\UrlSettings.dll.locale (12 bytes)
    %Program Files% (x86)\360\Total Security\QHVer.dll (22 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\Antiadwa.dll.locale (89 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\clsid.dat (22 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\appmon.dat (19 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\wpz.dat (835 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\Utils\ModuleUpdate.exe (6238 bytes)
    %Program Files% (x86)\360\Total Security\config\lang\es\SysSweeper.ui.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\regmon.dat (44 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\deepscan\dsr.dat (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\AntiAdwa.dll.locale (34 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\safemon\wdk.ini (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\deepscan\ssr.dat (32 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\safemon\wd.ini (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\AntiAdwa.dll.locale (38 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\Sxin.dll.locale (16 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\safemon\SelfProtectAPI2.dll.locale (15 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\safemon\360SPTool.exe.locale (31 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\Sxin.dll.locale (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\yhregd.dll.locale (11 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\libaw.dat (9605 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\appd.dll.locale (13 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\libaw.dat (9605 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\ipc\appmon.dat (19 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\UrlSettings.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\360ipc.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\360procmon.dll.locale (100 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\NetDefender.dll.locale (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\MenuEx64.dll (8092 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\360netd.dat (29 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\theme.xml (63 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\ipc\yhregd.dll.locale (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\CleanPlus.dll (2461 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\deepscan\DsRes.dll (748 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\safemon\safemon.dll.locale (21 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\360UDisk\360UDisk_theme.ui (1281 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\safemon\360SafeCamera.tpi.locale (1 bytes)
    %Program Files% (x86)\360\Total Security\safemon\wd.ini (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\chrome\360webshield.exe.locale (15 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\CheckSM.exe (673 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\appmon.dat (21 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\LibSDI.dat (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\ipc\appd.dll.locale (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\libvi.dat (521 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\tools\Tools_theme.ui (7385 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\safemon\udisk.locale (470 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\360SafeCamera.tpi.locale (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\drvmon.dat (4 bytes)
    %Program Files% (x86)\360\Total Security\updatecfg.ini (623720 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\360InternationTray\image\toast_speed_medium.png (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360Tray.exe (4650 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\360ipc.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\config\lang\en\SysSweeper.ui.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\AntiAdwa.dll.locale (89 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\360netr.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\UrlSettings.dll.locale (12 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\deepscan\dsr.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\dynlbase.dll (8581 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\360liveupdate\360liveupdate_theme.ui (673 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\ipc\360netr.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\DataDriv.dat (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360compro.dll (5083 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\deepscan\DsRes64.dll (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (113 bytes)
    %Program Files% (x86)\360\Total Security\ipc\SXIn64.dll (3361 bytes)
    %Program Files% (x86)\360\Total Security\safemon\QHSafeTray.exe (7726 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\chrome\360webshield.exe (1676 bytes)
    %Program Files% (x86)\360\Total Security\safemon\webprotection_firefox\plugins\nptswp.dll (1425 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (119 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\sbmon.dll (3836 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\drvmon.dat (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (112 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\libaw.dat (1385 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\360InternationTray\360InternationTray_theme.ui (673 bytes)
    %Program Files% (x86)\360\Total Security\Uninstall.exe (10177 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\filemgr.dll.locale (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360DeskAna.exe (4315 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\Sxin64.dll.locale (16 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\360AV\360AV_theme.ui (673 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\libaw.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\360netr.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\Dumpuper.exe.locale (1 bytes)
    %Program Files% (x86)\360\Total Security\safemon\webprotection_firefox\icon.png (6 bytes)
    %Program Files% (x86)\360\Total Security\safemon\gamemode.tpi (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360UDisk.tpi (1524 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\deepscan\ssr.dat (45 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\wdk.ini (3 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\safemon\chrome\360webshield.exe.locale (15 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\LibSDI.dat (601 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\dsark64.sys (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\ipc\360netd.dat (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\sweeper\SysSweeper.dll (8234 bytes)
    %Program Files% (x86)\360\Total Security\CombineExt.dll (673 bytes)
    %Program Files% (x86)\360\Total Security\safemon\360compro.dll (4185 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\deepscan\dsconz.dat (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\appd.dll.locale (13 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\safemon\Safemon.dll.locale (20 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\yhregd.dll.locale (9 bytes)
    %Program Files% (x86)\360\Total Security\safemon\360.dat (13 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\safemon\drvmon.dat (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\DsArk.sys (835 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\safemon\chrome\360webshield.exe.locale (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\art.dat (16 bytes)
    C:\Windows\System32\drivers\360AvFlt.sys (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\360ipc.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\deepscan\art.dat (16 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\ipc\regmon.dat (44 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\qex\MacroDef.enc (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\360avflt64.sys (2419 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\AVE\360ave_ex.def (3361 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\somkernl.dll (27085 bytes)
    %Program Files% (x86)\360\Total Security\360NetBase64.dll (2105 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\webprotection_firefox\install.rdf (4 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\safemon\UDiskScanEngine.dll.locale (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\FeedBack.ini (263 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\deepscan\dsurls.dat (844 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\Dumpuper.exe.locale (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\safemon\drvmon.dat (4 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\360netd.dat (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (114 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\deepscan\DsRes64.dll (1438 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\Sxin64.dll.locale (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\Sxin.dll.locale (14 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\UDiskScanEngine.dll.locale (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360InternationTray\image\toast_speed_medium.png (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\appmon.dat (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\UrlSettings.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\sc.con (512 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\AVCheck.dll (2130 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\deepscan\ssr.dat (45 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\safemon\360SPTool.exe.locale (32 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\Qshieldz.dat (170 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\safemon.dll.locale (19 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\safemon\SelfProtectAPI2.dll.locale (13 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\filemgr.dll.locale (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\360netd.dat (29 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\libaw.dat (9605 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\360procmon.dll.locale (101 bytes)
    %Program Files% (x86)\360\Total Security\ipc\ipcService.dll (3361 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\QHWatchdog.exe (1043 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\LiveUpdate360.exe (6582 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\csp.dat (8 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\safemon\chrome\360webshield.exe.locale (15 bytes)
    %Program Files% (x86)\360\Total Security\cacert.pem (1281 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\UrlSettings.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dsconz.dat (12 bytes)
    %Program Files% (x86)\360\Total Security\FeedBack.ini (263 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\ipc\yhregd.dll.locale (11 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\filemon.dat (18 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\360SafeCamera.tpi.locale (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\WscReg.exe (26008 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\ipc\filemgr.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\scanproxy.dll (5928 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\ipc\appmon.dat (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\wdk.ini (3 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\ipc\filemgr.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\SelfProtectAPI2.dll.locale (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\wd.ini (7 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\safemon\udisk.locale (550 bytes)
    %Program Files% (x86)\360\Total Security\safemon\router.ini (274 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\SelfProtectAPI2.dll.locale (12 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\ipc\Sxin64.dll.locale (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\Sites64.dll (20376 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\scanstub.dll (1216 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\wd.ini (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\fr8.dat (2 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\safemon\360SafeCamera.tpi.locale (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\CleanPlus64.exe (10117 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\regmon.dat (46 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\wdk.ini (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\udisk.locale (550 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\deepscan\dsurls.dat (844 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\libdefa.dat (162 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\360SafeCamera.tpi.locale (2 bytes)
    %Program Files% (x86)\360\Total Security\ipc\SxWrapper.dll (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\UDiskScanEngine.dll.locale (8 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\ipc\filemon.dat (17 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\ipc\regmon.dat (44 bytes)
    %Program Files% (x86)\360\Total Security\sweeper\TrashClean.dll (1425 bytes)
    %Program Files% (x86)\360\Total Security\scanproxy.dll (3361 bytes)
    %Program Files% (x86)\360\Total Security\softmgr\360Downloads.ini (269 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\safemon\udisk.locale (444 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\deepscan\dsconz.dat (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\deepscan\ssr.dat (45 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\safemon\safemon.dll.locale (19 bytes)
    %Program Files% (x86)\360\Total Security\softmgr\stsuglist.dat (601 bytes)
    %Program Files% (x86)\360\Total Security\FeedBack.exe (6841 bytes)
    C:\Users\Public\Desktop\360 Total Security.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\deepscan\DsRes.dll (637 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\libsdi.dat (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\ipc\appd.dll.locale (12 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\wifisafeEncrypt.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\dslw\dslw.dat (768 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\MiniUI.dll (9134 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\deepscan\dsconz.dat (12 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\ipc\360ipc.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\appd.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\libdefa.dat (673 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\drvmon.dat (4 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\sc.con (512 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360boxmain.exe (5580 bytes)
    %Program Files% (x86)\360\Total Security\netmon\gameidentify.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\sweeper\SysSweeper.dat (727 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360Box.sys (1417 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\ipc\filemgr.dll.locale (11 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\safemon\UDiskScanEngine.dll.locale (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\deepscan\ssr.dat (47 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\qutmipc.sys (185 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\Cloudsec3.dll (7385 bytes)
    %Program Files% (x86)\360\Total Security\config\defaultskin\MiniUI.xml (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\libdefa.dat (160 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\feedback\FeedBack_theme.ui (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\sndw.dat (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\FsrMgr.dll (4112 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\deepscan\ssr.dat (48 bytes)
    %Program Files% (x86)\360\Total Security\EfiProc.dll (57 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\BAPIDRV.sys (1729 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\defaultskin\defaultskin.ui (198 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\safemon\wdk.ini (3 bytes)
    %Program Files% (x86)\360\Total Security\QHSafeScanner.exe (4185 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\deepscan\dsurls.dat (844 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\safemon\chrome\360webshield.exe.locale (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\CleanPlus.exe (7161 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\heavygate.dll (7402 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\ipc\360netr.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\ipc\appmon.dat (19 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\deepscan\dsr.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\drvmon.dat (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\PopSoftEng.dll (5139 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\wduicfg.dat (10 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\ipc\360ipc.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\safemon\chrome\360webshield.exe.locale (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\EfiMon.sys (23 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\safemon\360SPTool.exe.locale (30 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\softmgr\safespeedboot.dat (25 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\I18N64.dll (969 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\libdefa.dat (160 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\qex\qex.vdb.enc (4185 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\ipc\Sxin64.dll.locale (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\7z.dll (9721 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\appmon.dat (21 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\ipc\360ipc.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\writeable_test_495427.dat (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\360procmon.dll.locale (98 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\deepscan\ssr.dat (45 bytes)
    %Program Files% (x86)\360\Total Security\LiveUpd360.dll (2321 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\SelfProtectAPI2.dll (3279 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\ipc\yhregd.dll.locale (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\chrome\360webshield.exe.locale (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\QHSafeScanner.exe (8221 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\acls.ini (1 bytes)
    %Program Files% (x86)\360\Total Security\360P2SP.dll (5873 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\ipc\360netd.dat (29 bytes)
    %Program Files% (x86)\360\Total Security\libleak.dat (46325 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360Base.dll (9004 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\wd.ini (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360InternationTray\image\toast_speed_veryfast.png (3 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\ipc\yhregd.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\360NetBase.dll (1425 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\Safemon.dll.locale (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360leakfix\360leakfix_theme.ui (1887 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\sysfilerepS.dll (2105 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\udisk.locale (482 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\deepscan\DsRes.dll (1146 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\deepscan\dsurls.dat (844 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\ImAVEng.dll (673 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\appd.dll.locale (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\UDiskScanEngine.dll.locale (8 bytes)
    %Program Files% (x86)\360\Total Security\safemon\iNetSafe.dll (1281 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\360netr.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\CleanPlus64.exe (7385 bytes)
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\360 Security Center\360 Total Security\Uninstall.lnk (1 bytes)
    %Program Files% (x86)\360\Total Security\config\lang\zh-CN\SysSweeper.ui.dat (601 bytes)
    %Program Files% (x86)\360\Total Security\filemon\AVCheck.dll (673 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\es\SysSweeper.ui.dat (125 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\theme.xml (63 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\deepscan\dsurls.dat (844 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (9 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\360AntiHacker.dll (62 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\360Quarant.dll (2105 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\deepscan\DsRes.dll (601 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\heavygate.dll (3073 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\AntiAdwa.dll.locale (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360SPTool.exe (2476 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\deepscan\dsconz.dat (12 bytes)
    %Program Files% (x86)\360\Total Security\safemon\execrule.dat (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\ipc\appd.dll.locale (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\ipc\yhregd.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\safemon\UDiskScanEngine.dll (1425 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\Dumpuper.exe.locale (1 bytes)
    %Program Files% (x86)\360\Total Security\360Verify.dll (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\deepscan\DsRes.dll (1655 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\UrlSettings.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\deepscan\ssr.dat (48 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (113 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360procmon.dll (3549 bytes)
    %Program Files% (x86)\360\Total Security\safemon\7z.dll (7433 bytes)
    %Program Files% (x86)\360\Total Security\safemon\WDSafeDown.exe (1425 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\dsws.dat (287 bytes)
    %Program Files% (x86)\360\Total Security\config\newui\themes\default\360InternationTray\image\toast_speed_veryfast.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\regmon.dat (44 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360InternationTray\360InternationTray_theme.ui (186 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\SelfProtectAPI2.dll.locale (13 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\dsr.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\deepscan\dsurls.dat (844 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\deepscan\dsurls.dat (844 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\endata\h_3.dat (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\dlproc.dll (5955 bytes)
    %Program Files% (x86)\360\Total Security\Safelive.dll (2105 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\LibSDI.dat (81 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\ipc\360netd.dat (29 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\ipc\filemgr.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\ipc\yhregd.dll.locale (10 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\safemon\360procmon.dll.locale (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\safemon\udisk.locale (338 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360sandbox\360sandbox_theme.ui (268 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\safemon\wdk.ini (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\LibSDI.dat (95 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\webprotection_firefox\chrome\content\browser.xul (560 bytes)
    %Program Files% (x86)\360\Total Security\i18n\ru\libdefa.dat (673 bytes)
    %Program Files% (x86)\360\Total Security\CleanPlus64.dll (1281 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\deepscan\dsurls.dat (844 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\360QuarantPlugin.dll (1281 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\Safelive.dll (3935 bytes)
    %Program Files% (x86)\360\Total Security\filemon\DataDriv.dat (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\appd.dll (7615 bytes)
    %Program Files% (x86)\360\Total Security\filemon\fr5.dat (9 bytes)
    %Program Files% (x86)\360\Total Security\ipc\X64For32Lib.dll (110 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\lang\hi\SysSweeper.ui.dat (1170 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\deepscan\dsconz.dat (12 bytes)
    %Program Files% (x86)\360\Total Security\360DeskAna64.exe (2105 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\deepscan\dsurls.dat (844 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\filemgr.dll.locale (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\360netr.dat (1 bytes)
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\360 Security Center\360 Total Security\360 Total Security.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\ipc\360netr.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\deepscan\dsurls.dat (844 bytes)
    %Program Files% (x86)\360\Total Security\i18n\en\Dumpuper.exe.locale (1 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\Qshieldz.dat (673 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\ipc\appmon.dat (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\cleancfg.dat (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360hipsPopWnd.dll (10184 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-TW\ipc\360netr.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\ipc\Sxin.dll.locale (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\safemon.dll (11070 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wifisafeEncrypt.js (5 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\libvi.dat (601 bytes)
    %Program Files% (x86)\360\Total Security\config\lang\vi\SysSweeper.ui.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\wdk.ini (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\safemon\chrome\360webshield.exe.locale (15 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\ipc\Sxin64.dll.locale (14 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\safemon\wd.ini (8 bytes)
    %Program Files% (x86)\360\Total Security\ipc\appd.dll (5441 bytes)
    %Program Files% (x86)\360\Total Security\safemon\acls.ini (1 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\BAPIDRV64.sys (857 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\360SkinView.exe (3349 bytes)
    %Program Files% (x86)\360\Total Security\ipc\360Camera.sys (34 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\deepscan\art.dat (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\QVM\360QVM.dll (6596 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\deepscan\ssr.dat (48 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\Safemon.dll.locale (20 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\zh-CN\safemon\360procmon.dll.locale (97 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\yhregd.dll.locale (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\endata\lm_1001.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\QHActiveDefense.exe (6898 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\360procmon.dll.locale (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\deepscan\dsurls.dat (844 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\AVE\360ave_ex.def (577 bytes)
    %Program Files% (x86)\360\Total Security\leakrepair.dll (5441 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\vi\safemon\360SafeCamera.tpi.locale (1 bytes)
    %Program Files% (x86)\360\Total Security\config\lang\TR\SysSweeper.ui.dat (601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\FileMgr.dll (4470 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\mui\en\Strings.dat (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\tr\ipc\appmon.dat (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\safemon\CameraProtect\CameraGuard\bkg\pic_01.jpg (113 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360safemonpro.tpi (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\vi\AntiAdwa.dll.locale (601 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\libaw.dat (9605 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\BAPIDRV64.sys (2116 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\ipc\Sxin.dll.locale (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\pt\safemon\Safemon.dll.locale (20 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\Dumpuper.exe (5146 bytes)
    %Program Files% (x86)\360\Total Security\safemon\360UDisk.tpi (2321 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\CleanPlus64.dll (2209 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\wdk.ini (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\drvmon.dat (4 bytes)
    %Program Files% (x86)\360\Total Security\i18n\pt\safemon\360SafeCamera.tpi.locale (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\appmon.dat (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\libvi.dat (130 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\ipc\NetDefender.dll.locale (15 bytes)
    %Program Files% (x86)\360\Total Security\filemon\ptype.dat (2 bytes)
    %Program Files% (x86)\360\Total Security\ipc\sbmon.dll (2469 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\ipc\NetDefender.dll (1921 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wificonfig\ra1001.dat (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\wpz.dat (835 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\default_theme.ui (431 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\deepscan\dsr.dat (82 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\libdefa.dat (1281 bytes)
    %Program Files% (x86)\360\Total Security\i18n\es\ipc\appmon.dat (19 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\hi\safemon\wdk.ini (3 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\webprotection_firefox\plugins\nptswp.dll.locale (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\es\safemon\360procmon.dll.locale (101 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\libaw.dat (9605 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\deepscan\ssr.dat (32 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\WiFiSafe.dll (10177 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\ipc\filemon.dat (17 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\netmon\360GameIdentify.dll (2954 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\en\safemon\safemon.dll.locale (20 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-CN\safemon\SelfProtectAPI2.dll.locale (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\deepscan\qex\qex.vdb.enc (592 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\i18n\ru\ipc\appmon.dat (19 bytes)
    %Program Files% (x86)\360\Total Security\deepscan\qutmload.dll (691 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\config\newui\themes\default\360AV\360AV_theme.ui (190 bytes)
    %Program Files% (x86)\360\Total Security\i18n\tr\ipc\360netr.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\ipc\360ipc.dat (1 bytes)
    %Program Files% (x86)\360\Total Security\i18n\zh-TW\safemon\udisk.locale (338 bytes)
    %Program Files% (x86)\360\Total Security\i18n\hi\deepscan\dsurls.dat (844 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\filemon\fr1.dat (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\360_install_20150423064845_495427\temp_files\safemon\360AV.tpi (321 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "QHSafeTray" = "%Program Files% (x86)\360\Total Security\safemon\QHSafeTray.exe /start"

  5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  6. Find and delete all copies of the worm's file together with "autorun.inf" scripts on removable drives.
  7. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now