Technical Information
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'GrpConv' = 'grpconv -o'
- [<HKLM>\System\CurrentControlSet\Services\NSecRTS] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\NSecRTS] 'ImagePath' = '"%CommonProgramFiles(x86)%\NSEC\NSecRTS.exe" -r'
- [<HKLM>\System\CurrentControlSet\Services\nFsFlt] 'ImagePath' = 'system32\DRIVERS\nFsFlt64.sys'
- [<HKLM>\System\CurrentControlSet\Services\NSecKrnl] 'ImagePath' = '%CommonProgramFiles(x86)%\NSEC\drivers\nskrnl\NSecKrnl64.sys'
- 'NSecRTS' "%CommonProgramFiles(x86)%\NSEC\NSecRTS.exe" -r
- 'nFsFlt' system32\DRIVERS\nFsFlt64.sys
- 'NSecKrnl' %CommonProgramFiles(x86)%\NSEC\drivers\nskrnl\NSecKrnl64.sys
- '%WINDIR%\syswow64\net.exe' stop nFsFlt
- Handler for all processes: %CommonProgramFiles(x86)%\NSEC\DtCore32.dll
- Handler for all processes: %CommonProgramFiles(x86)%\NSEC\x64\DtCore64.dll
- [<HKLM>\System\CurrentControlSet\Services\nFsFlt] 'Group' = 'FSFilter Activity Monitor'
- %TEMP%\rarsfx0\setup_ip_82.156.255.141.exe
- %CommonProgramFiles(x86)%\nsec\drivers\nnfp\nnfp_win10_x86.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nnfp\nnfp_win10_x64.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nfsflt\win10\nfsflt64.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nfsflt\win10\nfsflt64.inf
- %CommonProgramFiles(x86)%\nsec\drivers\nfsflt\win10\nfsflt32.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nfsflt\win10\nfsflt32.inf
- %CommonProgramFiles(x86)%\nsec\drivers\nfsflt\nfsflt64.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nfsflt\nfsflt32.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nnfp\nnfp_win7_x86.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nfsflt\nfsflt32.inf
- %CommonProgramFiles(x86)%\nsec\des\nxdes64.dll
- %CommonProgramFiles(x86)%\nsec\des\nxdes32.dll
- %CommonProgramFiles(x86)%\nsec\des\nefs64.dll
- %CommonProgramFiles(x86)%\nsec\des\nefs32.dll
- %CommonProgramFiles(x86)%\nsec\des\desh64.dll
- %CommonProgramFiles(x86)%\nsec\drivers\nfsflt\nfsflt64.inf
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows7_20.jpg
- %CommonProgramFiles(x86)%\nsec\drivers\nnfp\nnfp_win8_x64.sys
- %CommonProgramFiles(x86)%\nsec\libcrypto-1_1.dll
- %CommonProgramFiles(x86)%\nsec\knurt.dll
- %CommonProgramFiles(x86)%\nsec\instrap.exe
- %CommonProgramFiles(x86)%\nsec\import_root_cert.exe
- %CommonProgramFiles(x86)%\nsec\imdec3.dll
- %CommonProgramFiles(x86)%\nsec\imdec2.dll
- %CommonProgramFiles(x86)%\nsec\imced.dll
- %CommonProgramFiles(x86)%\nsec\des\desh32.dll
- %CommonProgramFiles(x86)%\nsec\drivers\nnfp\nnfp_win7_x64.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nskrnl\nseckrnl64.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nskrnl\nseckrnl32.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nsdiskcrypt\win10\nsdiskcrypt-x86.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nsdiskcrypt\win10\nsdiskcrypt-x64.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nsdiskcrypt\nsdiskcrypt-x86.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nsdiskcrypt\nsdiskcrypt-x64.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nnfp\nnfp_winxp_x86.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nskrnl\win10\nseckrnl32.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nnfp\nnfp_win8_x86.sys
- %CommonProgramFiles(x86)%\nsec\data\workstat_template.db
- %CommonProgramFiles(x86)%\nsec\data\wc-sig_template.db
- %CommonProgramFiles(x86)%\nsec\data\smartsnap_template.db
- %CommonProgramFiles(x86)%\nsec\winimdeca.dll
- %CommonProgramFiles(x86)%\nsec\data\nslogon\nsecscreen.xml
- %CommonProgramFiles(x86)%\nsec\data\language.xml
- %CommonProgramFiles(x86)%\nsec\buildin.cfg
- %CommonProgramFiles(x86)%\nsec\winspolex32.dll
- %CommonProgramFiles(x86)%\nsec\winsomgr.dll
- %CommonProgramFiles(x86)%\nsec\winshdltaskex.dll
- %CommonProgramFiles(x86)%\nsec\libcurl.dll
- %CommonProgramFiles(x86)%\nsec\data\nslogon\guest.png
- %CommonProgramFiles(x86)%\nsec\windtecore32.dll
- %CommonProgramFiles(x86)%\nsec\windiskmgr.dll
- %CommonProgramFiles(x86)%\nsec\nslogon.exe
- %CommonProgramFiles(x86)%\nsec\nshellext32.dll
- %CommonProgramFiles(x86)%\nsec\nsecrts.exe
- %CommonProgramFiles(x86)%\nsec\nsec.exe
- %CommonProgramFiles(x86)%\nsec\nfpcore.dll
- %CommonProgramFiles(x86)%\nsec\winmrkx32.dll
- %CommonProgramFiles(x86)%\nsec\drivers\nskrnl\win10\nseckrnl64.sys
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows10.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows10_20.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows10_10.jpg
- %CommonProgramFiles(x86)%\nsec\data\des\desbackup_init.db
- %CommonProgramFiles(x86)%\nsec\data\db_template\doc_txt_db_template.db
- %CommonProgramFiles(x86)%\nsec\data\db_bk\readme.txt
- %CommonProgramFiles(x86)%\nsec\data\av_feature.xml
- %CommonProgramFiles(x86)%\nsec\data\actag.dat
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows7_5.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows10_15.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows7_30.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\arrow.png
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows7_15.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows7_10.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows7.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows10_5.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows10_30.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows10_25.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows7_25.jpg
- %CommonProgramFiles(x86)%\nsec\plugins\rd\ldapauth.dll
- %WINDIR%\temp\uddad8e.tmp
- %CommonProgramFiles(x86)%\nsec\libssl\nt5\libssl-1_1.dll
- %CommonProgramFiles(x86)%\nsec\x64\nsecrts.exe
- %CommonProgramFiles(x86)%\nsec\x64\dtcore64.dll
- %CommonProgramFiles(x86)%\nsec\ui\nsecex.exe
- %CommonProgramFiles(x86)%\nsec\res\tray_offline.ico
- %CommonProgramFiles(x86)%\nsec\res\tray.ico
- %CommonProgramFiles(x86)%\nsec\res\icon_gray.png
- %CommonProgramFiles(x86)%\nsec\res\icon.png
- %CommonProgramFiles(x86)%\nsec\plugins\all2txt\a2txt.exe
- %CommonProgramFiles(x86)%\nsec\x64\windtecore64.dll
- %CommonProgramFiles(x86)%\nsec\plugins\all2txt\a2trtf.dll
- %CommonProgramFiles(x86)%\nsec\plugins\all2txt\a2tpdf.dll
- %CommonProgramFiles(x86)%\nsec\plugins\all2txt\a2thtm.dll
- %CommonProgramFiles(x86)%\nsec\plugins\all2txt\a2thlp.dll
- %CommonProgramFiles(x86)%\nsec\plugins\all2txt\a2t.key
- %CommonProgramFiles(x86)%\nsec\plugins\all2txt\a2t.id
- %CommonProgramFiles(x86)%\nsec\plugins\xphelper\normaliz.dll
- %CommonProgramFiles(x86)%\nsec\libssl-1_1.dll
- %CommonProgramFiles(x86)%\nsec\x64\winmrkx64.dll
- %ProgramFiles(x86)%\microsoft research\nsec\nshellext64.dll
- %ProgramFiles(x86)%\microsoft research\nsec\nshellext32.dll
- %CommonProgramFiles(x86)%\nsec\data\recordcached.db
- %CommonProgramFiles(x86)%\nsec\data\recordcached.db-journal
- %CommonProgramFiles(x86)%\nsec\dtcore321.dll
- %CommonProgramFiles(x86)%\nsec\data\cfg.xml
- %CommonProgramFiles(x86)%\nsec\data\xconfig.db
- %CommonProgramFiles(x86)%\nsec\plugins\all2txt\a2txtassem.dll
- %CommonProgramFiles(x86)%\nsec\x64\nshellext64.dll
- C:\nsec\debug\log\fixit.exe-system_2021-05-04.log
- C:\nsec\debug\log\nsecrts.exe-system_2021-05-04.log
- <DRIVERS>\set3b5a.tmp
- C:\nsec\debug\log\nsecrts.exe-user_2021-05-04.log
- C:\nsec\debug\log\instrap.exe-user_2021-05-04.log
- D:\nsec\cache.ini
- C:\nsec\cache.ini
- %WINDIR%\temp\udd476b.tmp
- %CommonProgramFiles(x86)%\nsec\x64\winspolex64.dll
- %CommonProgramFiles(x86)%\nsec\plugins\speccy2.exe
- %CommonProgramFiles(x86)%\nsec\plugins\rd\workgrpdomnt4.dll
- %CommonProgramFiles(x86)%\nsec\plugins\rd\vnchooks.dll
- %CommonProgramFiles(x86)%\nsec\nss\libnspr4.dll
- %CommonProgramFiles(x86)%\nsec\nss\nssdbm3.dll
- %CommonProgramFiles(x86)%\nsec\nss\nssckbi.dll
- %CommonProgramFiles(x86)%\nsec\nss\nss3.dll
- %CommonProgramFiles(x86)%\nsec\nss\nspr4.dll
- %CommonProgramFiles(x86)%\nsec\nss\mozcrt19.dll
- %CommonProgramFiles(x86)%\nsec\nss\libplds4.dll
- %CommonProgramFiles(x86)%\nsec\libssl\nt5\libcrypto-1_1.dll
- %CommonProgramFiles(x86)%\nsec\nss\plc4.dll
- %CommonProgramFiles(x86)%\nsec\nss\freebl3.dll
- %CommonProgramFiles(x86)%\nsec\nss\certutil.exe
- %CommonProgramFiles(x86)%\nsec\nfcore.dll
- %CommonProgramFiles(x86)%\nsec\msvcr120.dll
- %CommonProgramFiles(x86)%\nsec\msvcr100.dll
- %CommonProgramFiles(x86)%\nsec\libssl\nt6\libssl-1_1.dll
- %CommonProgramFiles(x86)%\nsec\libssl\nt6\libcrypto-1_1.dll
- %CommonProgramFiles(x86)%\nsec\nss\libplc4.dll
- %CommonProgramFiles(x86)%\nsec\messagecenter.exe
- %CommonProgramFiles(x86)%\nsec\nss\plds4.dll
- %CommonProgramFiles(x86)%\nsec\nss\sqlite3.dll
- %CommonProgramFiles(x86)%\nsec\nss\smime3.dll
- %CommonProgramFiles(x86)%\nsec\plugins\rd\uvnckeyboardhelper.exe
- %CommonProgramFiles(x86)%\nsec\plugins\rd\uvnc_settings.exe
- %CommonProgramFiles(x86)%\nsec\plugins\rd\testauth.exe
- %CommonProgramFiles(x86)%\nsec\plugins\rd\setpasswd.exe
- %CommonProgramFiles(x86)%\nsec\plugins\rd\setcad.exe
- %CommonProgramFiles(x86)%\nsec\plugins\rd\logging.dll
- %CommonProgramFiles(x86)%\nsec\nss\softokn3.dll
- %CommonProgramFiles(x86)%\nsec\plugins\rd\ldapauthnt4.dll
- %CommonProgramFiles(x86)%\nsec\nss\nssutil3.dll
- %CommonProgramFiles(x86)%\nsec\plugins\rd\authadmin.dll
- %CommonProgramFiles(x86)%\nsec\plugins\rd\authssp.dll
- %CommonProgramFiles(x86)%\nsec\plugins\rd\nsecrd.exe
- %CommonProgramFiles(x86)%\nsec\plugins\rd\mslogonacl.exe
- %CommonProgramFiles(x86)%\nsec\plugins\7z\7z.exe
- %CommonProgramFiles(x86)%\nsec\plugins\7z\7z.dll
- %CommonProgramFiles(x86)%\nsec\plugins\rd\ldapauth9x.dll
- %CommonProgramFiles(x86)%\nsec\data\xconfig.db-journal
- %CommonProgramFiles(x86)%\nsec\imagehelperex.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\x64\nshellext64.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nfsflt\win10\nfsflt64.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nfsflt\win10\nfsflt32.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nfsflt\nfsflt64.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nfsflt\nfsflt32.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\des\nxdes64.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\des\nxdes32.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\des\nefs64.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\des\desh64.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nnfp\nnfp_win10_x86.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\des\desh32.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\dcmount.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\dcformat.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\7zr.exe
- %ProgramFiles(x86)%\cached backup\updateinfo.xml
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\res\tray_offline.ico
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\des\nefs32.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\nslogon\windows7_5.jpg
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nnfp\nnfp_win7_x64.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\imdec2.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\imced.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\imagehelperex.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\fixit.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\dtcore32.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nskrnl\win10\nseckrnl64.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nskrnl\win10\nseckrnl32.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\res\tray.ico
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nnfp\nnfp_win10_x64.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nsdiskcrypt\win10\nsdiskcrypt-x86.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nsdiskcrypt\win10\nsdiskcrypt-x64.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nsdiskcrypt\nsdiskcrypt-x86.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nsdiskcrypt\nsdiskcrypt-x64.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nnfp\nnfp_winxp_x86.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nnfp\nnfp_win8_x86.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nnfp\nnfp_win8_x64.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nskrnl\nseckrnl32.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nnfp\nnfp_win7_x86.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\res\icon_gray.png
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\res\icon.png
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\all2txt\a2t.key
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\db_bk\readme.txt
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\nslogon\windows10.jpg
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\nslogon\nsecscreen.xml
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\nslogon\guest.png
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\nslogon\arrow.png
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\language.xml
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\des\desbackup_init.db
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\imdec3.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\nslogon\windows10_15.jpg
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\av_feature.xml
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\actag.dat
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\buildin.cfg
- %CommonProgramFiles(x86)%\nsec\7zr.exe.tmp
- %ProgramFiles(x86)%\cached backup\3.7.51.8341.7z.tmp
- %ProgramFiles(x86)%\cached backup\update.xml.tmp
- C:\nsec\debug\log\setup_ip_82.156.255.141.exe_2021-05-04.log
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\db_template\doc_txt_db_template.db
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nskrnl\nseckrnl64.sys
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\nslogon\windows10_20.jpg
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\nslogon\windows10_5.jpg
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\nslogon\windows10_25.jpg
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\all2txt\a2t.id
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nfsflt\win10\nfsflt64.inf
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nfsflt\win10\nfsflt32.inf
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nfsflt\nfsflt64.inf
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\drivers\nfsflt\nfsflt32.inf
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\workstat_template.db
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\nslogon\windows10_30.jpg
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\wc-sig_template.db
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\nslogon\windows10_10.jpg
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\nslogon\windows7_30.jpg
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\nslogon\windows7_25.jpg
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\nslogon\windows7_20.jpg
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\nslogon\windows7_15.jpg
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\nslogon\windows7_10.jpg
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\nslogon\windows7.jpg
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\data\smartsnap_template.db
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nss\plc4.dll
- %CommonProgramFiles(x86)%\nsec\dtcore32.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\knurt.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\rd\workgrpdomnt4.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\rd\vnchooks.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\rd\uvnc_settings.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\rd\uvnckeyboardhelper.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\rd\testauth.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\rd\setpasswd.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\rd\setcad.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\rd\mslogonacl.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\xphelper\normaliz.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\rd\logging.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\rd\ldapauthnt4.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\rd\ldapauth9x.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\rd\ldapauth.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\rd\authssp.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\rd\authadmin.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\rd\nsecrd.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\import_root_cert.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\ui\nsecex.exe
- %CommonProgramFiles(x86)%\nsec\dcmount.dll
- %CommonProgramFiles(x86)%\nsec\dcformat.exe
- %ProgramFiles(x86)%\cached backup\fixit.exe
- %ProgramFiles(x86)%\cached backup\7zr.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\x64\winspolex64.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\x64\winmrkx64.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\x64\windtecore64.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\all2txt\a2txtassem.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\speccy2.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\x64\dtcore64.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\winspolex32.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\winsomgr.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\winshdltaskex.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\winmrkx32.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\winimdeca.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\windtecore32.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\x64\nsecrts.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\windiskmgr.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\all2txt\a2txt.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\all2txt\a2trtf.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\all2txt\a2tpdf.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\messagecenter.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nshellext32.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nsecrts.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nsec.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nfpcore.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nfcore.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\msvcr120.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\instrap.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nss\certutil.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\libssl\nt6\libssl-1_1.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\libssl\nt6\libcrypto-1_1.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\libssl\nt5\libssl-1_1.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\libssl\nt5\libcrypto-1_1.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\libssl-1_1.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\libcurl.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\libcrypto-1_1.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\msvcr100.dll
- %CommonProgramFiles(x86)%\nsec\fixit.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nss\freebl3.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nss\libplds4.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nss\libnspr4.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\all2txt\a2thtm.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\all2txt\a2thlp.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\7z\7z.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\plugins\7z\7z.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nss\sqlite3.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nss\softokn3.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nss\libplc4.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nss\smime3.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nslogon.exe
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nss\nssutil3.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nss\nssdbm3.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nss\nssckbi.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nss\nss3.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nss\nspr4.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nss\mozcrt19.dll
- %ProgramFiles(x86)%\cached backup\3.7.51.8341\nss\plds4.dll
- %ProgramFiles(x86)%\microsoft research\nsec\fixit.exe
- %WINDIR%\temp\udd476b.tmp
- %CommonProgramFiles(x86)%\nsec\data\xconfig.db-journal
- %CommonProgramFiles(x86)%\nsec\data\recordcached.db-journal
- %WINDIR%\temp\uddad8e.tmp
- from %ProgramFiles(x86)%\cached backup\update.xml.tmp to %ProgramFiles(x86)%\cached backup\update.xml
- from %ProgramFiles(x86)%\cached backup\3.7.51.8341.7z.tmp to %ProgramFiles(x86)%\cached backup\3.7.51.8341.7z
- from %CommonProgramFiles(x86)%\nsec\7zr.exe.tmp to %CommonProgramFiles(x86)%\nsec\7zr.exe
- from <DRIVERS>\set3b5a.tmp to <DRIVERS>\nfsflt64.sys
- %LOCALAPPDATA%\microsoft\windows\explorer\explorerstartuplog_runonce.etl
- %CommonProgramFiles(x86)%\nsec\data\xconfig.db-journal
- %CommonProgramFiles(x86)%\nsec\data\recordcached.db-journal
- '82.##6.255.141':28987
- '82.##6.255.141':38987
- 'ba##u.com':80
- 'localhost':58133
- '82.##6.255.141':28987
- DNS ASK ba##u.com
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\rarsfx0\setup_ip_82.156.255.141.exe'
- '%CommonProgramFiles(x86)%\nsec\nss\certutil.exe' -A -t "TCu" -i "C:\PROGRA~2\COMMON~1\NSEC\Data/SSL/NSECNF~1.CER" -n "Data/SSL/NSEC NFCORE 2" -d "%APPDATA%\Mozilla\Firefox\Profiles\GN7RYP~1.DEF"
- '%CommonProgramFiles(x86)%\nsec\nss\certutil.exe' -A -t "TCu" -i "C:\PROGRA~2\COMMON~1\NSEC\Data/SSL/NSECNF~1.CER" -n "Data/SSL/NSEC NFCORE 2" -d "%APPDATA%\THUNDE~1\Profiles\WJJ9AE~1.DEF"
- '%CommonProgramFiles(x86)%\nsec\x64\nsecrts.exe'
- '%CommonProgramFiles(x86)%\nsec\fixit.exe' -df
- '%CommonProgramFiles(x86)%\nsec\nsecrts.exe' -i
- '%CommonProgramFiles(x86)%\nsec\nsecrts.exe' -r
- '%CommonProgramFiles(x86)%\nsec\instrap.exe'
- '%CommonProgramFiles(x86)%\nsec\7zr.exe' x -y -aoa -o"%ProgramFiles(x86)%\Cached Backup" "%ProgramFiles(x86)%\Cached Backup\3.7.51.8341.7z"
- '%CommonProgramFiles(x86)%\nsec\nsecrts.exe'
- '%CommonProgramFiles(x86)%\nsec\plugins\speccy2.exe'
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\Microsoft Research\NSEC\NShellExt64.dll"' (with hidden window)
- '%CommonProgramFiles(x86)%\nsec\7zr.exe' x -y -aoa -o"%ProgramFiles(x86)%\Cached Backup" "%ProgramFiles(x86)%\Cached Backup\3.7.51.8341.7z"' (with hidden window)
- '%CommonProgramFiles(x86)%\nsec\instrap.exe' ' (with hidden window)
- '%CommonProgramFiles(x86)%\nsec\nsecrts.exe' -i' (with hidden window)
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\setupapi.dll,InstallHinfSection DefaultInstall 132 %CommonProgramFiles(x86)%\NSEC\drivers\nfsflt\nFsFlt64.inf' (with hidden window)
- '%CommonProgramFiles(x86)%\nsec\nss\certutil.exe' -A -t "TCu" -i "C:\PROGRA~2\COMMON~1\NSEC\Data/SSL/NSECNF~1.CER" -n "Data/SSL/NSEC NFCORE 2" -d "%APPDATA%\Mozilla\Firefox\Profiles\GN7RYP~1.DEF"' (with hidden window)
- '%CommonProgramFiles(x86)%\nsec\fixit.exe' -df' (with hidden window)
- '%WINDIR%\syswow64\net.exe' stop nFsFlt' (with hidden window)
- '%CommonProgramFiles(x86)%\nsec\x64\nsecrts.exe' ' (with hidden window)
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\Microsoft Research\NSEC\NShellExt32.dll"' (with hidden window)
- '%CommonProgramFiles(x86)%\nsec\nss\certutil.exe' -A -t "TCu" -i "C:\PROGRA~2\COMMON~1\NSEC\Data/SSL/NSECNF~1.CER" -n "Data/SSL/NSEC NFCORE 2" -d "%APPDATA%\THUNDE~1\Profiles\WJJ9AE~1.DEF"' (with hidden window)
- '%WINDIR%\syswow64\net1.exe' stop nFsFlt
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\setupapi.dll,InstallHinfSection DefaultInstall 132 %CommonProgramFiles(x86)%\NSEC\drivers\nfsflt\nFsFlt64.inf
- '<SYSTEM32>\runonce.exe' -r
- '<SYSTEM32>\grpconv.exe' -o
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\Microsoft Research\NSEC\NShellExt32.dll"
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\Microsoft Research\NSEC\NShellExt64.dll"
- '<SYSTEM32>\regsvr32.exe' /s "%ProgramFiles(x86)%\Microsoft Research\NSEC\NShellExt64.dll"
- '%WINDIR%\syswow64\ctfmon.exe'