@Win4% 00g c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dllh shell32.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll shell32.dll shell32.dll shell32.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dllO c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll shell32.dll shell32.dll c:\windows\system32\imageres.dll\ c:\windows\system32\imageres.dll] c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll shell32.dll c:\windows\system32\imageres.dll shell32.dllw shell32.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll shell32.dll shell32.dll shell32.dll shell32.dll shell32.dll shell32.dll shell32.dll shell32.dll c:\windows\system32\imageres.dllc c:\windows\system32\imageres.dll c:\windows\system32\shutdown.exe"%systemroot%\system32\svrmgrnc.dll;%systemroot%\system32\windowspowershell\v1.0\powershell.exe%windir%\explorer.exe^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8808\office6\wpsofficeicon.dll%^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8808\office6\wpsofficeicon.dll ^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8808\office6\wpsofficeicon.dll'^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8808\office6\wpsofficeicon.dll c:\windows\system32\imageres.dllA(c:\program files (x86)\xiaoyu\xiaoyu.exe9c:\users\administrator\appdata\roaming\_S\x86\kuaizip.exe9c:\users\administrator\appdata\roaming\_S\x86\kuaizip.exe^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8808\office6\wpsofficeicon.dllA4c:\users\administrator\desktop\purecodec20181130.exe c:\windows\system32\imageres.dllBhf2Mm WPS201~1.LNKJ ユMmMm.زWPS 2019.lnkA;c:\program files\premiumsoft\navicat premium 12\navicat.exeFc:\users\administrator\appdata\local\kingsoft\wps office\ksolaunch.exeA0c:\program files (x86)\teamviewer\teamviewer.exeA6c:\program files (x86)\tsbrowser\tsbrowserlauncher.exeA7c:\program files (x86)\tencent\tim\bin\qqsclauncher.exeA9c:\users\administrator\appdata\roaming\_S\x86\kuaizip.exeA;d:\program files (x86)\vmware\vmware workstation\vmware.exeA0c:\program files (x86)\tencent\wechat\wechat.exeAFc:\program files (x86)\oray\sunlogin\sunloginclient\sunloginclient.exeAAc:\users\administrator\desktop\microsoft .net framework 4.5.2.exec:\users\administrator\appdata\roaming\microsoft\installer\{82198c0b-d6f2-4fbb-8dd6-fa570c672778}\newshortcut2_12d0040082484d07a84d0c1697ca37f7.exe0c:\program files (x86)\tencent\wechat\wechat.exe%windir%\system32\cmd.exeFc:\program files (x86)\oray\sunlogin\sunloginclient\sunloginclient.exe;c:\users\administrator\appdata\roaming\xiaoyu\bqpb\bqpb.exeFc:\users\administrator\appdata\roaming\xiaoyu\11ab_gwall\xytpopoth.exec:\users\administrator\appdata\roaming\microsoft\installer\{82198c0b-d6f2-4fbb-8dd6-fa570c672778}\newshortcut2_12d0040082484d07a84d0c1697ca37f7.exe c:\windows\syswow64\werfault.exeLc:\users\administrator\appdata\roaming\kuaiya\11cd-allall\kuaiyatpopxktt.exe imageres.dll= imageres.dllA shell32.dll imageres.dll shell32.dll shell32.dllXc:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8808\office6\qingnse.dll c:\windows\system32\imageres.dllC c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dll c:\windows\system32\imageres.dllH c:\windows\system32\imageres.dll c:\windows\system32\imageres.dllI c:\windows\system32\imageres.dll c:\windows\system32\imageres.dllAd:\360drvmgrinstaller_beta.exec:\windows\system32\msiexec.exe3c:\program files\windows nt\accessories\wordpad.exeA#d:\filezilla_3.38.1_win64_setup.exe c:\windows\system32\imageres.dllk c:\windows\system32\imageres.dll%windir%\system32\imageres.dll shell32.dll9c:\users\administrator\appdata\roaming\_S\x86\kuaizip.exec:\windows\system32\msxml3.dll c:\windows\system32\imageres.dllAUd:\chineseall_products\chineseall_digitallib\win-64bit\tomcat-digital\bin\tomcat7.exeAVd:\chineseall_products\chineseall_digitallib\win-64bit\tomcat-digital\bin\tomcat7w.exe6c:\program files (x86)\tsbrowser\tsbrowserlauncher.exe%windir%\system32\notepad.exe/c:\program files\internet explorer\iexplore.exe0c:\program files (x86)\teamviewer\teamviewer.exe c:\windows\system32\imageres.dllc:\windows\system32\zipfldr.dll c:\windows\system32\sendmail.dll/Lc:\users\administrator\appdata\roaming\kuaiya\11ef-allall\kuaiyatpopxktt.exeLc:\users\administrator\appdata\roaming\kuaiya\11ab-allall\kuaiyatpopxktt.exe/c:\program files\java\jdk1.8.0_121\bin\java.exec:\windows\system32\mmc.exe>c:\users\administrator\appdata\roaming\xynote\68hlqgw\xymn.exe^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8894\office6\wpsofficeicon.dll .c:\program files (x86)\tsbrowser\tsbrowser.exe^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8894\office6\wpsofficeicon.dll'^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8894\office6\wpsofficeicon.dll^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8894\office6\wpsofficeicon.dll Xc:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8894\office6\qingnse.dllUc:\users\administrator\appdata\local\temp\1\jds788965515.tmp\jre-8u221-windows-au.exe;c:\program files\premiumsoft\navicat premium 12\navicat.exec:\windows\system32\display.dll^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8894\office6\wpsofficeicon.dll%networkexplorer.dll c:\windows\system32\imageres.dll/c:\program files\internet explorer\iexplore.exec:\windows\system32\notepad.exeADc:\users\administrator\desktop\mysql-navicat_for_mysql_10.0.11.0.exeA4c:\program files (x86)\navicat for mysql\navicat.exe4c:\program files (x86)\navicat for mysql\navicat.exe?c:\users\administrator\appdata\roaming\kuaiya\kzippb\kuaipb.exe1%programfiles%\windows nt\accessories\wordpad.exe c:\windows\system32\imageres.dll c:\windows\system32\imageres.dllAJc:\$recycle.bin\s-1-5-21-1242754773-2862960173-4029343502-500\$re3hh3k.exeAJc:\$recycle.bin\s-1-5-21-1242754773-2862960173-4029343502-500\$rehr5if.exeJc:\$recycle.bin\s-1-5-21-1242754773-2862960173-4029343502-500\$rehr5if.exe9c:\users\administrator\appdata\roaming\_S\x86\kuaizip.exe c:\windows\system32\imageres.dll#%programfiles%\windows mail\wab.exe9c:\users\administrator\appdata\roaming\_S\x86\kuaizip.exe shell32.dll^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8894\office6\wpsofficeicon.dll^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8894\office6\wpsofficeicon.dll& shell32.dllc:\windows\system32\wscript.exeA?c:\users\administrator\desktop\editplus_3.4.1.1091_xiazaiba.exeA.c:\program files (x86)\editplus 3\editplus.exec:\windows\hh.exe.c:\program files (x86)\editplus 3\editplus.exe.c:\program files (x86)\editplus 3\editplus.exe imageres.dll= imageres.dll imageres.dll imageres.dll< imageres.dll imageres.dll imageres.dll; imageres.dllp imageres.dll2c:\program files\java\jre1.8.0_121\bin\javacpl.exe c:\windows\system32\iscsicpl.exe#c:\windows\system32\tsworkspace.dllc:\windows\system32\inetcpl.cply c:\windows\system32\imageres.dll'c:\windows\system32\actioncentercpl.dll c:\windows\system32\telephon.cpl c:\windows\system32\imageres.dll c:\windows\system32\powercpl.dllc:\windows\system32\wucltux.dll c:\windows\system32\imageres.dll,c:\windows\system32\firewallcontrolpanel.dll(c:\windows\system32\accessibilitycpl.dllc:\windows\system32\intl.cpl8c:\windows\system32\main.cpl8c:\windows\system32\vault.dll c:\windows\system32\timedate.cplc:\windows\system32\main.cplc:\windows\system32\devmgr.dll7$c:\windows\system32\devicecenter.dll"c:\windows\system32\taskbarcpl.dll!c:\windows\system32\netcenter.dllc:\windows\system32\mmsys.cpl c:\windows\system32\imageres.dllZc:\windows\system32\display.dll,c:\windows\system32\speech\speechux\sapi.cplvc:\windows\system32\usercpl.dllc:\windows\system32\diagcpl.dll(c:\windows\system32\userlanguagescpl.dll c:\windows\system32\colorcpl.exe c:\windows\system32\autoplay.dllc:\windows\system32\fontext.dll shell32.dll appwiz.cpl appwiz.cpl shell32.dllJ3c:\program files\filezilla ftp client\filezilla.exetc:\users\administrator\appdata\roaming\microsoft\installer\{82198c0b-d6f2-4fbb-8dd6-fa570c672778}\arpproducticon.exeTc:\programdata\package cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exeTc:\programdata\package cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exeNc:\windows\installer\{fd42ee05-18f9-459f-935d-770e75b3bee5}\arpproducticon.exeFc:\users\administrator\appdata\local\kingsoft\wps office\ksolaunch.exe.c:\progra~1\difx\048b92ba3327cef8\difxappa.dll0c:\program files (x86)\tencent\tim\timuninst.ico c:\windows\system32\imageres.dll1c:\program files\java\jre1.8.0_121\bin\javaws.exe1c:\program files\java\jdk1.8.0_121\bin\javaws.exeBc:\windows\installer\{590655e2-d31e-44e9-9c46-b8ff2320c1e0}\arpicoph& DqdɆ !9qj{+vFzQ&ARPI$.{7828FF97-81E3-483D-9713-05049FB1D8C9}p+3 3 'nXKP9H@lz [ySoftware\Wow6432Node\Micosoft\Windows\CurrentVeion\Uninst8FF97-81!  C(! C`O`X0X}$0PX001SPSOYMGm=Microsoft Corporationa 'C:\Program Files\Microsoft SQL Server\G<a id="launchhelpurl">http://go.microsoft.com/fwlink/?LinkId=55742</a> UUUU4@@] %D:\AVA\WIN2008X64sXꁨR[ň\SQL2005_x64\1SPS0%G`q /Microsoft SQL Server Management Studio Express PI1SPSS} d- 9.00.4035.001SPS'\HB^]BCC:\Windows\Installer\{7828FF97-81E3-483D-9713-05049FB1D8C9}\ARPIco(ph& DqdɆ !9qj{+vFzQ&ARPI$.{DB53BC6A-2CBA-4523-ACCD-4B06DE12CB94}p+3 3 'nXKP9H@lz [ySoftware\Wow6432Node\Micosoft\Windows\CurrentVeion\Uninst3BC6A-2C!  C(! C`O`X0X}$0PX001SPSOYMGm=Microsoft Corporationa 'C:\Program Files\Microsoft SQL Server\G<a id="launchhelpurl">http://go.microsoft.com/fwlink/?LinkId=52153</a> UUUU4@@ 8D:\AVA\WIN2008X64sXꁨR[ň\SQL2005_x64\SQL_2005_x64\setup\1SPS0%G`Y #Microsoft SQL Server Native Client I1SPSS} d- 9.00.1399.061SPS'\HB^]BCC:\Windows\Installer\{DB53BC6A-2CBA-4523-ACCD-4B06DE12CB94}\ARPIcodph& DqdɆ !9qj{+vFzQ&$ARPI$"{071c9b48-7c32-4621-a0ac-3f809523288f}p+3 3 'nXKP9H@lz [ySoftware\Wow6432Node\Micosoft\Windows\CurrentVe/ion\Uninstc9b48-7c!  C(! C`O`X0X}$0PX00 1SPSOYMGm=Microsoft Corporation UUUU(@@u 1C:\Users\ADMINI~1\AppData\Local\Temp\IXP001.TMP\1SPS0%G`q 0Microsoft Visual C++ 2005 Redistributable (x64) pA1SPSS} d% 8.0.56336Gc:\windows\installer\{19cf3c43-217f-40bb-a3ab-1d3b2cb08da5}\arpicon.icoBc:\windows\installer\{b6825f5e-5b85-4724-a100-0a9aaa24b072}\arpico;d:\program files (x86)\vmware\vmware workstation\vmware.exeNc:\windows\installer\{ec56bd64-b710-4178-9c42-994a18ea6d96}\arpproducticon.exe8c:\users\administrator\appdata\roaming\_S\x86\uninst.exe(c:\program files (x86)\xiaoyu\uninst.exe(c:\program files (x86)\xiaoyu\uninst.exe2c:\program files (x86)\7654browser\7654browser.exeAd:\ludashisetup.exeAd:\sunloginclient_9.8.1.exeBPO :i+00/D:\2RwvFc TeamViewer_10.0.39052.0Setup_zhcn.1425958194.exe M,M,.9YTeamViewer_10.0.39052.0Setup_zhcn.1425958194.exe@BPO :i+00/D:\`2xm8zM9 tim_pc.exeF zM.zM..X4Utim_pc.exeAd:\teamviewer_setup.exeA$d:\rfid\tsbrowser_788_3.0.8.8@st.exeA1d:\rfid\Ʉ\f[\ls005-1--3.0.0.191\acs.netengine.exeBPO :i+00/D:\N1N%rfid: M5N%.(Qs0rfidR5NFIɄ\f[: MCNFI.+'Ʉ\f[x1N-LS005-1--3.0.0.191V LM&N-.X-}LS005-1--3.0.0.191"n2&M@ ACS.Manager.exeP &MX@LM&.[-*ACS.Manager.exeA7d:\rfid\Ʉ\f[\ls005-1--3.0.0.191\manager\acs.manager.exe7d:\rfid\Ʉ\f[\ls005-1--3.0.0.191\manager\acs.manager.exe+d:\rfid\ls005-3--3.0.0.191\acs.testdemo.exe imageres.dll imageres.dll imageres.dll imageres.dll9c:\users\administrator\appdata\roaming\_S\x86\kuaizip.exe8c:\users\administrator\appdata\roaming\_S\x86\update.exeA,d:\rfid\sip2server\socketKmՋ]wQ\sockettool.exe%windir%\system32\cmd.exe c:\windows\system32\imageres.dll^ c:\windows\system32\imageres.dll c:\windows\system32\netshell.dll !:i+00qǬp2_'N^jf!_' +0%:G68~L `XprN*YQIntel(R) I350 Gigabit Network Connection #2 +0%:G68~Lvan.dll netshell.dll netshell.dll netshell.dll netshell.dll netshell.dll netshell.dll netshell.dll netshell.dll netshell.dll$ !:i+00qǬp2_'N^jf!_'So1ACSz% ^ Rnp N*YQ 2Intel(R) I350 Gigabit Network ConnectionSo1ACSz%Q~ 3 !:i+00qǬp2_'N^jf!_'4i@ ) b VrtN*YQ 4VMware Virtual Ethernet Adapter for VMnet84i@ ) !:i+00qǬp2_'N^jf!_'CB&DL9( b VrtN*YQ 3VMware Virtual Ethernet Adapter for VMnet1CB&DL9( A=d:\rfid\ls005-1--3.0.0.191\ls005-1--3.0.0.191\acs.manager.exeA?d:\rfid\ls005-1--3.0.0.191\ls005-1--3.0.0.191\acs.netengine.exeAEd:\rfid\ls005-1--3.0.0.191\ls005-1--3.0.0.191\manager\acs.manager.exeEd:\rfid\ls005-1--3.0.0.191\ls005-1--3.0.0.191\manager\acs.manager.exeA+d:\rfid\Ʉ\f[\ls005-1--3.0.0.191\ls005-1.exeA9d:\rfid\ls005-1--3.0.0.191\ls005-1--3.0.0.191\ls005-1.exe%windir%\system32\taskmgr.exeE c:\windows\system32\imageres.dlll shell32.dllHd:\app\administrator\product\11.2.0\dbhome_1\assistants\images\netca.icoHd:\app\administrator\product\11.2.0\dbhome_1\assistants\images\netca.ico twinui.dll%c:\users\administrator\appdata\roaming\microsoft\installer\{82198c0b-d6f2-4fbb-8dd6-fa570c672778}\newshortcut1_f6943307b6d04daaadb0fa570769f8f3.exec:\users\administrator\appdata\roaming\microsoft\installer\{82198c0b-d6f2-4fbb-8dd6-fa570c672778}\newshortcut1_f6943307b6d04daaadb0fa570769f8f3.exe;%systemroot%\system32\windowspowershell\v1.0\powershell.exe+d:\rfid\Ʉ\f[\ls005-1--3.0.0.191\ls005-1.exe9d:\rfid\ls005-1--3.0.0.191\ls005-1--3.0.0.191\ls005-1.exeA$d:\rfid\Ʉ\f[\opac\images\favicon.ico c:\windows\system32\imageres.dll shell32.dlli%windir%\system32\mspaint.exe!%systemroot%\system32\ntshrui.dll"%systemroot%\system32\imageres.dll "%systemroot%\system32\imageres.dllNc:\windows\system32\mspaint.exe,c:\program files\mozilla firefox\firefox.exe>c:\users\administrator\appdata\roaming\kuaiya\kzippb\~38e7.tmpJc:\users\administrator\appdata\roaming\kuaiya\kuaiyarenwulankytipsluf3.exeSc:\users\administrator\appdata\local\temp\jds801982719.tmp\jre-8u231-windows-au.exe^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8976\office6\wpsofficeicon.dll%^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8976\office6\wpsofficeicon.dll ^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8976\office6\wpsofficeicon.dll'^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8976\office6\wpsofficeicon.dll ^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8976\office6\wpsofficeicon.dllA1c:\users\administrator\desktop\firefox-latest.exeA,c:\program files\mozilla firefox\firefox.exeXc:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8976\office6\qingnse.dll&%windir%\system32\inetsrv\inetmgr6.exe%windir%\system32\iscsicpl.dll%%windir%\system32\inetsrv\inetmgr.exe%windir%\syswow64\odbcint.dlla%windir%\system32\odbcint.dlla;%systemroot%\syswow64\windowspowershell\v1.0\powershell.exe%windir%\system32\blbuires.dll?%systemroot%\system32\windowspowershell\v1.0\powershell_ise.exe%windir%\system32\wsecedit.dll%windir%\system32\filemgmt.dll%windir%\system32\scw.exe"%systemroot%\system32\svrmgrnc.dll"%systemroot%\system32\authfwgp.dll%windir%\system32\mycomput.dll%windir%\system32\mdsched.exe#%windir%\system32\miguiresource.dll c:\windows\system32\openwith.exeB`^>XV6 Teu.lnk@ ハMXV6.3Teu.lnkc:\windows\system32\url.dll shell32.dll shell32.dll shell32.dll imageres.dllJ imageres.dllK imageres.dllI imageres.dllH imageres.dllE imageres.dll$ imageres.dllF imageres.dllD imageres.dllC imageres.dllB imageres.dll& shell32.dllP shell32.dllu shell32.dll shell32.dllv imageres.dllc:\windows\explorer.exe c:\windows\system32\openwith.exeB!PO :i+00/D:\N1SU!rfid: M5SU!.(FarfidR5PNCɄ\f[: MCPNC.+eɄ\f[N5P-9e z^8 JM/RP-9.Tne z^l1fV0NavicatPremiumN fV0fV0.zZNavicatPremium2AyQ1 navicat112_premium_cs_x64.exel yQN1fV0.|F navicat112_premium_cs_x64.exe, imageres.dllA8c:\program files\premiumsoft\navicat premium\navicat.exe0d:\rfid\Ʉ\f[\e z^\navicatpremium\patchnavicat.exe8c:\program files\premiumsoft\navicat premium\navicat.exeA0d:\rfid\acs\ls005-1--3.0.0.207\acs.netengine.exeA.d:\rfid\acs\ls005-1--3.0.0.207\acs.manager.exeA6d:\rfid\acs\ls005-1--3.0.0.207\manager\acs.manager.exe6d:\rfid\acs\ls005-1--3.0.0.207\manager\acs.manager.exe%windir%\system32\notepad.exe#c:\windows\system32\dsmusertask.exeBd:\rfid\acs\ls005-3--3.0.0.206\ls005-3--3.0.0.206\acs.testdemo.exeTc:\users\administrator\appdata\local\temp\jds1988739156.tmp\jre-8u381-windows-au.exe]vc:\users\administrator\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\server manager.lnkj4zc:\users\administrator\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\windows powershell.lnk5uc:\users\administrator\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\file explorer.lnkׯ6'c:\users\administrator\desktop\\|O~{.lnk{]8c:\users\administrator\desktop\sip2-60000.bat - _wce_.lnkr+c:\users\administrator\desktop\wps 2019.lnkB.c:\users\public\desktop\navicat premium 12.lnkC)c:\users\administrator\desktop\wps h5.lnkMU*D)c:\users\public\desktop\teamviewer 14.lnk>zE0c:\users\administrator\desktop\TS.bat - _wce_.lnk(c:\users\administrator\desktop\gOmȉhV.lnkH [c:\users\public\desktop\tim.lnk G%c:\users\administrator\desktop\_S.lnk2c:\users\public\desktop\vmware workstation pro.lnk$Ic:\users\public\desktop\_O.lnk5P*Jc:\users\public\desktop\Teu.lnkD.c:\users\administrator\desktop\chromegOmȉhV.lnkH@*F2c:\users\administrator\desktop\plsql developer.lnkD*M>c:\programdata\microsoft\windows\start menu\programs\_O\_O.lnkG΢lc:\users\administrator\appdata\roaming\microsoft\windows\start menu\programs\system tools\command prompt.lnkvO@c:\programdata\microsoft\windows\start menu\programs\Teu\Teu.lnkD2c:\users\administrator\desktop\plsql developer.lnkD*-c:\users\administrator\links\recentplaces.lnkO^-c:\users\administrator\links\recentplaces.lnkO^(c:\users\administrator\links\desktop.lnk"(c:\users\administrator\links\desktop.lnk"*c:\users\administrator\links\downloads.lnkr*c:\users\administrator\links\downloads.lnkrkc:\users\administrator\appdata\roaming\microsoft\windows\start menu\programs\system tools\control panel.lnkׯac:\users\administrator\appdata\roaming\microsoft\windows\start menu\programs\system tools\run.lnkׯ.c:\users\administrator\desktop\chromegOmȉhV.lnkH@*dc:\users\administrator\appdata\roaming\microsoft\windows\start menu\programs\accessories\notepad.lnktbc:\users\administrator\appdata\roaming\microsoft\windows\start menu\programs\internet explorer.lnkJg'c:\users\administrator\desktop\\|O~{.lnk{].c:\users\public\desktop\navicat premium 12.lnk4c:\users\administrator\desktop\navicat for mysql.lnk v4c:\users\administrator\desktop\navicat for mysql.lnk vLc:\programdata\microsoft\windows\start menu\programs\accessories\wordpad.lnk*+c:\users\administrator\desktop\editplus.lnkbc:\users\administrator\appdata\roaming\microsoft\windows\start menu\programs\editplus\editplus.lnkVc:\users\administrator\appdata\roaming\microsoft\windows\start menu\programs\_S\_S.lnklc:\users\administrator\appdata\roaming\microsoft\windows\start menu\programs\system tools\command prompt.lnkvRc:\programdata\microsoft\windows\start menu\programs\system tools\task manager.lnk`JFc:\programdata\microsoft\windows\start menu\programs\teamviewer 14.lnk>zJc:\programdata\microsoft\windows\start menu\programs\accessories\paint.lnkZ oc:\users\administrator\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\firefox.lnk&mc:\users\administrator\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\gOmȉhV.lnk`sdc:\users\administrator\appdata\roaming\microsoft\windows\start menu\programs\wps office\wps 2019.lnkx %c:\users\administrator\desktop\_S.lnkV(c:\users\administrator\desktop\gOmȉhV.lnkHF#c:\users\public\desktop\firefox.lnk$Zc:\programdata\microsoft\windows\start menu\programs\administrative tools\iis6 manager.lnkrʧ]c:\programdata\microsoft\windows\start menu\programs\administrative tools\iscsi initiator.lnkxYc:\programdata\microsoft\windows\start menu\programs\administrative tools\iis manager.lnknʧhc:\programdata\microsoft\windows\start menu\programs\administrative tools\odbc data sources (32-bit).lnkt3 hc:\programdata\microsoft\windows\start menu\programs\administrative tools\odbc data sources (64-bit).lnkt*fc:\programdata\microsoft\windows\start menu\programs\administrative tools\windows powershell (x86).lnkcc:\programdata\microsoft\windows\start menu\programs\administrative tools\windows server backup.lnkRdc:\programdata\microsoft\windows\start menu\programs\administrative tools\windows powershell ise.lnkjc:\programdata\microsoft\windows\start menu\programs\administrative tools\windows powershell ise (x86).lnkoc:\programdata\microsoft\windows\start menu\programs\administrative tools\security configuration management.lnkbVc:\programdata\microsoft\windows\start menu\programs\administrative tools\services.lnkkc:\programdata\microsoft\windows\start menu\programs\administrative tools\security configuration wizard.lnkdj\c:\programdata\microsoft\windows\start menu\programs\administrative tools\server manager.lnkjuc:\programdata\microsoft\windows\start menu\programs\administrative tools\windows firewall with advanced security.lnkJac:\programdata\microsoft\windows\start menu\programs\administrative tools\computer management.lnkec:\programdata\microsoft\windows\start menu\programs\administrative tools\memory diagnostics tool.lnkt\c:\programdata\microsoft\windows\start menu\programs\administrative tools\task scheduler.lnkl7c:\users\administrator\desktop\TSstartup.bat - _wce_.lnkeA7c:\users\administrator\desktop\start.bat - _wce_ (2).lnk4 A%c:\users\administrator\desktop\_S.lnk/]Hc:\users\public\desktop\Teu.lnkп)c:\users\administrator\desktop\VfN{tTS.url|D#c:\users\public\desktop\firefox.lnk[#c:\users\public\desktop\firefox.lnk%Uc:\users\administrator\appdata\roaming\microsoft\windows\start menu\programs\/TR_S.lnk/]+c:\users\public\desktop\navicat premium.lnkiW\+c:\users\public\desktop\navicat premium.lnkiWdc:\users\administrator\appdata\roaming\microsoft\windows\start menu\programs\accessories\notepad.lnk#c:\users\public\desktop\firefox.lnkɎmc:\users\administrator\appdata\roaming\microsoft\windows\start menu\programs\startup\start.bat - _wce_ (2).lnk4 mc:\users\administrator\appdata\roaming\microsoft\windows\start menu\programs\startup\TSstartup.bat - _wce_.lnke#c:\users\public\desktop\firefox.lnk%#c:\users\public\desktop\firefox.lnk΄%!c:\users\public\desktop\Teu.lnkHDc:\programdata\microsoft\windows\start menu\programs\Teu\Teu.lnkH#c:\users\public\desktop\firefox.lnkξI#c:\users\public\desktop\firefox.lnkD&#c:\users\public\desktop\Teu܏ zc6R.lnkRKHc:\programdata\microsoft\windows\start menu\programs\Teu܏ zc6R\Teu܏ zc6R.lnkRP#c:\users\public\desktop\firefox.lnkd&#c:\users\public\desktop\firefox.lnk΄&0#c:\users\public\desktop\firefox.lnkΤ&0* c:\windows\system32\imageres.dllc!1 c:\windows\system32\imageres.dll!2 c:\windows\system32\shutdown.exe!3"%systemroot%\system32\svrmgrnc.dll!4;%systemroot%\system32\windowspowershell\v1.0\powershell.exe!5%windir%\explorer.exe!6^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8808\office6\wpsofficeicon.dll%!7^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8808\office6\wpsofficeicon.dll !8^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8808\office6\wpsofficeicon.dll'!9^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8808\office6\wpsofficeicon.dll !: c:\windows\system32\imageres.dll!;(c:\program files (x86)\xiaoyu\xiaoyu.exe!<9c:\users\administrator\appdata\roaming\_S\x86\kuaizip.exe!=9c:\users\administrator\appdata\roaming\_S\x86\kuaizip.exe!>^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8808\office6\wpsofficeicon.dll!?4c:\users\administrator\desktop\purecodec20181130.exe~ @ c:\windows\system32\imageres.dll!AFc:\users\administrator\appdata\local\kingsoft\wps office\ksolaunch.exe7B;c:\program files\premiumsoft\navicat premium 12\navicat.exe@ CFc:\users\administrator\appdata\local\kingsoft\wps office\ksolaunch.exe!D0c:\program files (x86)\teamviewer\teamviewer.exe 81 E6c:\program files (x86)\tsbrowser\tsbrowserlauncher.exeF7c:\program files (x86)\tencent\tim\bin\qqsclauncher.exejG9c:\users\administrator\appdata\roaming\_S\x86\kuaizip.exe?H;d:\program files (x86)\vmware\vmware workstation\vmware.exe6 I0c:\program files (x86)\tencent\wechat\wechat.exeȧJFc:\program files (x86)\oray\sunlogin\sunloginclient\sunloginclient.exepוK6c:\program files (x86)\tsbrowser\tsbrowserlauncher.exeFAc:\users\administrator\desktop\microsoft .net framework 4.5.2.exeX:Lc:\users\administrator\appdata\roaming\microsoft\installer\{82198c0b-d6f2-4fbb-8dd6-fa570c672778}\newshortcut2_12d0040082484d07a84d0c1697ca37f7.exe!M0c:\program files (x86)\tencent\wechat\wechat.exeȧN%windir%\system32\cmd.exe!OFc:\program files (x86)\oray\sunlogin\sunloginclient\sunloginclient.exepוP;c:\users\administrator\appdata\roaming\xiaoyu\bqpb\bqpb.exe!QFc:\users\administrator\appdata\roaming\xiaoyu\11ab_gwall\xytpopoth.exe!Rc:\users\administrator\appdata\roaming\microsoft\installer\{82198c0b-d6f2-4fbb-8dd6-fa570c672778}\newshortcut2_12d0040082484d07a84d0c1697ca37f7.exe!S c:\windows\syswow64\werfault.exe!TLc:\users\administrator\appdata\roaming\kuaiya\11cd-allall\kuaiyatpopxktt.exe!U imageres.dll=!V imageres.dllA!W shell32.dll!X imageres.dll !Y shell32.dll!Z shell32.dll![Xc:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8808\office6\qingnse.dll!\ c:\windows\system32\imageres.dllC!] c:\windows\system32\imageres.dll!^ c:\windows\system32\imageres.dll!_ c:\windows\system32\imageres.dll!` c:\windows\system32\imageres.dllH!a c:\windows\system32\imageres.dll!b c:\windows\system32\imageres.dllI!c c:\windows\system32\imageres.dll!d c:\windows\system32\imageres.dll!ed:\360drvmgrinstaller_beta.exe(fc:\windows\system32\msiexec.exe g3c:\program files\windows nt\accessories\wordpad.exe h#d:\filezilla_3.38.1_win64_setup.exeEi c:\windows\system32\imageres.dllkj c:\windows\system32\imageres.dllk%windir%\system32\imageres.dlll shell32.dllm9c:\users\administrator\appdata\roaming\_S\x86\kuaizip.exenc:\windows\system32\msxml3.dllo c:\windows\system32\imageres.dllpUd:\chineseall_products\chineseall_digitallib\win-64bit\tomcat-digital\bin\tomcat7.exea qVd:\chineseall_products\chineseall_digitallib\win-64bit\tomcat-digital\bin\tomcat7w.exea r6c:\program files (x86)\tsbrowser\tsbrowserlauncher.exes%windir%\system32\notepad.exe t/c:\program files\internet explorer\iexplore.exepu0c:\program files (x86)\teamviewer\teamviewer.exe | v c:\windows\system32\imageres.dllwc:\windows\system32\zipfldr.dllx c:\windows\system32\sendmail.dll/yLc:\users\administrator\appdata\roaming\kuaiya\11ef-allall\kuaiyatpopxktt.exezLc:\users\administrator\appdata\roaming\kuaiya\11ab-allall\kuaiyatpopxktt.exe{(c:\program files (x86)\xiaoyu\xiaoyu.exe5</c:\program files\java\jdk1.8.0_121\bin\java.exe|c:\windows\system32\mmc.exe}>c:\users\administrator\appdata\roaming\xynote\68hlqgw\xymn.exe~^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8894\office6\wpsofficeicon.dll .c:\program files (x86)\tsbrowser\tsbrowser.exe^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8894\office6\wpsofficeicon.dll'^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8894\office6\wpsofficeicon.dll^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8894\office6\wpsofficeicon.dll Xc:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8894\office6\qingnse.dllUc:\users\administrator\appdata\local\temp\1\jds788965515.tmp\jre-8u221-windows-au.exe;c:\program files\premiumsoft\navicat premium 12\navicat.exe@ c:\windows\system32\display.dll^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8894\office6\wpsofficeicon.dll%networkexplorer.dll c:\windows\system32\imageres.dll/c:\program files\internet explorer\iexplore.exec:\windows\system32\notepad.exeDc:\users\administrator\desktop\mysql-navicat_for_mysql_10.0.11.0.exe4c:\program files (x86)\navicat for mysql\navicat.exeHe4c:\program files (x86)\navicat for mysql\navicat.exeHe?c:\users\administrator\appdata\roaming\kuaiya\kzippb\kuaipb.exe1%programfiles%\windows nt\accessories\wordpad.exe c:\windows\system32\imageres.dllx c:\windows\system32\imageres.dllxJc:\$recycle.bin\s-1-5-21-1242754773-2862960173-4029343502-500\$re3hh3k.exe,FJc:\$recycle.bin\s-1-5-21-1242754773-2862960173-4029343502-500\$rehr5if.exexJc:\$recycle.bin\s-1-5-21-1242754773-2862960173-4029343502-500\$rehr5if.exex9c:\users\administrator\appdata\roaming\_S\x86\kuaizip.exe_ c:\windows\system32\imageres.dll_#%programfiles%\windows mail\wab.exe_9c:\users\administrator\appdata\roaming\_S\x86\kuaizip.exe_ shell32.dll_^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8894\office6\wpsofficeicon.dll_^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8894\office6\wpsofficeicon.dll&_ shell32.dllFc:\windows\system32\wscript.exe?c:\users\administrator\desktop\editplus_3.4.1.1091_xiazaiba.exe.c:\program files (x86)\editplus 3\editplus.exec:\windows\hh.exe.c:\program files (x86)\editplus 3\editplus.exe.c:\program files (x86)\editplus 3\editplus.exe imageres.dll= imageres.dll imageres.dll imageres.dll< imageres.dll imageres.dll imageres.dll; imageres.dllp imageres.dll2c:\program files\java\jre1.8.0_121\bin\javacpl.exe c:\windows\system32\iscsicpl.exe#c:\windows\system32\tsworkspace.dllc:\windows\system32\inetcpl.cply c:\windows\system32\imageres.dll'c:\windows\system32\actioncentercpl.dll c:\windows\system32\telephon.cpl c:\windows\system32\imageres.dll c:\windows\system32\powercpl.dllc:\windows\system32\wucltux.dll c:\windows\system32\imageres.dll,c:\windows\system32\firewallcontrolpanel.dll(c:\windows\system32\accessibilitycpl.dllc:\windows\system32\intl.cpl8c:\windows\system32\main.cpl8c:\windows\system32\vault.dll c:\windows\system32\timedate.cplc:\windows\system32\main.cplc:\windows\system32\devmgr.dll7$c:\windows\system32\devicecenter.dll"c:\windows\system32\taskbarcpl.dll!c:\windows\system32\netcenter.dllc:\windows\system32\mmsys.cpl c:\windows\system32\imageres.dllZc:\windows\system32\display.dll,c:\windows\system32\speech\speechux\sapi.cplvc:\windows\system32\usercpl.dllc:\windows\system32\diagcpl.dll(c:\windows\system32\userlanguagescpl.dll c:\windows\system32\colorcpl.exe c:\windows\system32\autoplay.dllc:\windows\system32\fontext.dll shell32.dll appwiz.cpl appwiz.cpl shell32.dllJ(c:\program files (x86)\xiaoyu\uninst.exe2c:\program files (x86)\7654browser\7654browser.exed:\ludashisetup.exe(GMd:\sunloginclient_9.8.1.exe8zM3d:\teamviewer_10.0.39052.0setup_zhcn.1425958194.exe8M d:\tim_pc.exexwMd:\teamviewer_setup.exeXM$d:\rfid\tsbrowser_788_3.0.8.8@st.exeg1d:\rfid\Ʉ\f[\ls005-1--3.0.0.191\acs.netengine.exeFY/d:\rfid\Ʉ\f[\ls005-1--3.0.0.191\acs.manager.exe&Z7d:\rfid\Ʉ\f[\ls005-1--3.0.0.191\manager\acs.manager.exe&Z7d:\rfid\Ʉ\f[\ls005-1--3.0.0.191\manager\acs.manager.exe+d:\rfid\ls005-3--3.0.0.191\acs.testdemo.exeo imageres.dllk imageres.dllk imageres.dllk imageres.dllk9c:\users\administrator\appdata\roaming\_S\x86\kuaizip.exe?8c:\users\administrator\appdata\roaming\_S\x86\update.exe=,d:\rfid\sip2server\socketKmՋ]wQ\sockettool.exel%windir%\system32\cmd.exe! c:\windows\system32\imageres.dll^ c:\windows\system32\imageres.dll c:\windows\system32\netshell.dllvan.dll netshell.dll netshell.dll netshell.dll netshell.dll netshell.dll netshell.dll netshell.dll netshell.dll netshell.dll =d:\rfid\ls005-1--3.0.0.191\ls005-1--3.0.0.191\acs.manager.exe&Zk ?d:\rfid\ls005-1--3.0.0.191\ls005-1--3.0.0.191\acs.netengine.exeFYkEd:\rfid\ls005-1--3.0.0.191\ls005-1--3.0.0.191\manager\acs.manager.exe&ZjEd:\rfid\ls005-1--3.0.0.191\ls005-1--3.0.0.191\manager\acs.manager.exe+d:\rfid\Ʉ\f[\ls005-1--3.0.0.191\ls005-1.exeY9d:\rfid\ls005-1--3.0.0.191\ls005-1--3.0.0.191\ls005-1.exeYk%windir%\system32\taskmgr.exeE c:\windows\system32\imageres.dlll shell32.dllHd:\app\administrator\product\11.2.0\dbhome_1\assistants\images\netca.icoHd:\app\administrator\product\11.2.0\dbhome_1\assistants\images\netca.ico twinui.dll%c:\users\administrator\appdata\roaming\microsoft\installer\{82198c0b-d6f2-4fbb-8dd6-fa570c672778}\newshortcut1_f6943307b6d04daaadb0fa570769f8f3.exec:\users\administrator\appdata\roaming\microsoft\installer\{82198c0b-d6f2-4fbb-8dd6-fa570c672778}\newshortcut1_f6943307b6d04daaadb0fa570769f8f3.exe;%systemroot%\system32\windowspowershell\v1.0\powershell.exe+d:\rfid\Ʉ\f[\ls005-1--3.0.0.191\ls005-1.exe9d:\rfid\ls005-1--3.0.0.191\ls005-1--3.0.0.191\ls005-1.exe0c:\program files (x86)\teamviewer\teamviewer.exe 81 v$d:\rfid\Ʉ\f[\opac\images\favicon.ico~= c:\windows\system32\imageres.dll= shell32.dlli; %windir%\system32\mspaint.exe1!!%systemroot%\system32\ntshrui.dll""%systemroot%\system32\imageres.dll #"%systemroot%\system32\imageres.dllN$c:\windows\system32\mspaint.exe%,c:\program files\mozilla firefox\firefox.exe 5&6c:\program files (x86)\tsbrowser\tsbrowserlauncher.exe3s>c:\users\administrator\appdata\roaming\kuaiya\kzippb\~38e7.tmp'Jc:\users\administrator\appdata\roaming\kuaiya\kuaiyarenwulankytipsluf3.exe(Sc:\users\administrator\appdata\local\temp\jds801982719.tmp\jre-8u231-windows-au.exe)^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8976\office6\wpsofficeicon.dll%*Fc:\users\administrator\appdata\local\kingsoft\wps office\ksolaunch.exe 2^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8976\office6\wpsofficeicon.dll +^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8976\office6\wpsofficeicon.dll',^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8976\office6\wpsofficeicon.dll -9c:\users\administrator\appdata\roaming\_S\x86\kuaizip.exeH6c:\program files (x86)\tsbrowser\tsbrowserlauncher.exeF^c:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8976\office6\wpsofficeicon.dll.1c:\users\administrator\desktop\firefox-latest.exex"/,c:\program files\mozilla firefox\firefox.exe 50Xc:\users\administrator\appdata\local\kingsoft\wps office\11.1.0.8976\office6\qingnse.dll1&%windir%\system32\inetsrv\inetmgr6.exe2%windir%\system32\iscsicpl.dll3%%windir%\system32\inetsrv\inetmgr.exe4%windir%\syswow64\odbcint.dlla5%windir%\system32\odbcint.dlla6;%systemroot%\syswow64\windowspowershell\v1.0\powershell.exe7%windir%\system32\blbuires.dll8?%systemroot%\system32\windowspowershell\v1.0\powershell_ise.exe9%windir%\system32\wsecedit.dll:%windir%\system32\filemgmt.dll;%windir%\system32\scw.exe<"%systemroot%\system32\svrmgrnc.dll="%systemroot%\system32\authfwgp.dll>%windir%\system32\mycomput.dll?%windir%\system32\mdsched.exe@#%windir%\system32\miguiresource.dllA c:\windows\system32\openwith.exeB9c:\users\administrator\appdata\roaming\_S\x86\kuaizip.exePHFc:\program files (x86)\oray\sunlogin\sunloginclient\sunloginclient.exez@Cc:\windows\system32\url.dllD shell32.dll E shell32.dllF shell32.dllG imageres.dllJH imageres.dllKI imageres.dllIJ imageres.dllHK imageres.dllEL imageres.dll$M imageres.dllFN imageres.dllDO imageres.dllCP imageres.dllBQ imageres.dll&R shell32.dllPS shell32.dlluT shell32.dllU shell32.dllvV imageres.dllWc:\windows\explorer.exeX c:\windows\system32\openwith.exeY9c:\users\administrator\appdata\roaming\_S\x86\kuaizip.exeP=d:\rfid\Ʉ\f[\e z^\navicatpremium\navicat112_premium_cs_x64.exeȍZ imageres.dll[8c:\program files\premiumsoft\navicat premium\navicat.exep"\0d:\rfid\Ʉ\f[\e z^\navicatpremium\patchnavicat.exe]8c:\program files\premiumsoft\navicat premium\navicat.exep"^0d:\rfid\acs\ls005-1--3.0.0.207\acs.netengine.exe_.d:\rfid\acs\ls005-1--3.0.0.207\acs.manager.exey`6d:\rfid\acs\ls005-1--3.0.0.207\manager\acs.manager.exey a6d:\rfid\acs\ls005-1--3.0.0.207\manager\acs.manager.exeib%windir%\system32\notepad.exeic#c:\windows\system32\dsmusertask.exe@dBd:\rfid\acs\ls005-3--3.0.0.206\ls005-3--3.0.0.206\acs.testdemo.exe7eFc:\program files (x86)\oray\sunlogin\sunloginclient\sunloginclient.exexKFc:\program files (x86)\oray\sunlogin\sunloginclient\sunloginclient.exexPFc:\program files (x86)\oray\sunlogin\sunloginclient\sunloginclient.exep= KFc:\program files (x86)\oray\sunlogin\sunloginclient\sunloginclient.exep= PTc:\users\administrator\appdata\local\temp\jds1988739156.tmp\jre-8u381-windows-au.exef