Technical Information
- %TEMP%\nss2.tmp\nsF.tmp ipseccmd -p Block0 -r Block0 -f 118.145.31.*+0 -n BLOCK -x
- %PROGRAM_FILES%\baidu\ipseccmd.exe -p Block9 -r Block9 -f 221.194.142.*+0 -n BLOCK -x
- %PROGRAM_FILES%\baidu\msfsg.exe uncompress -s dsop7.xml -d setup513839.exe
- %PROGRAM_FILES%\baidu\ipseccmd.exe -p Block0 -r Block0 -f 118.145.31.*+0 -n BLOCK -x
- %TEMP%\nss2.tmp\nsD.tmp ipseccmd -p Block8 -r Block8 -f 220.181.126.*+0 -n BLOCK -x
- %PROGRAM_FILES%\baidu\ipseccmd.exe -p Block7 -r Block7 -f 125.39.102.*+0 -n BLOCK -x
- %TEMP%\nss2.tmp\nsE.tmp ipseccmd -p Block9 -r Block9 -f 221.194.142.*+0 -n BLOCK -x
- %PROGRAM_FILES%\baidu\ipseccmd.exe -p Block8 -r Block8 -f 220.181.126.*+0 -n BLOCK -x
- %PROGRAM_FILES%\baidu\msfsg.exe md5 -s newnetgar.dll -d newnetgar.dll
- %PROGRAM_FILES%\baidu\msfsg.exe md5 -s spass.dll -d spass.dll
- %PROGRAM_FILES%\baidu\dsetup.exe install
- %PROGRAM_FILES%\baidu\msfsg.exe md5 -s sumpod-nos.sys -d sumpod-nos.sys
- %TEMP%\is-UQ77N.tmp\setup513839.tmp /SL5="$C0104,823075,54272,%PROGRAM_FILES%\baidu\setup513839.exe" /VERYSILENT /NORESTART
- %PROGRAM_FILES%\baidu\setup513839.exe /VERYSILENT /NORESTART
- %PROGRAM_FILES%\baidu\msfsg.exe md5 -s dsetup.exe -d dsetup.exe
- %PROGRAM_FILES%\baidu\msfsg.exe md5 -s passthru.dll -d passthru.dll
- %TEMP%\nss2.tmp\nsC.tmp ipseccmd -p Block7 -r Block7 -f 125.39.102.*+0 -n BLOCK -x
- %PROGRAM_FILES%\baidu\ipseccmd.exe -p Block1 -r BlockTCP -f 119.147.91.*+0 -n BLOCK -x
- %TEMP%\nss2.tmp\ns6.tmp ipseccmd -p Block1 -r BlockTCP -f 119.147.91.*+0 -n BLOCK -x
- %PROGRAM_FILES%\baidu\ipseccmd.exe -p Block2 -r BlockNEW -f 119.188.4.*+0 -n BLOCK -x
- %TEMP%\nss2.tmp\ns7.tmp ipseccmd -p Block2 -r BlockNEW -f 119.188.4.*+0 -n BLOCK -x
- %PROGRAM_FILES%\baidu\msfsg.exe uncompress -s s0001.xml -d ipseccmd.exe
- <Current directory>\uuse-0001.exe
- %TEMP%\nss2.tmp\ns5.tmp sc start PolicyAgent
- %PROGRAM_FILES%\baidu\msfsg.exe md5 -s ipseccmd.exe -d ipseccmd.exe -l 10000000
- %PROGRAM_FILES%\baidu\ipseccmd.exe -p Block5 -r Block5 -f 124.238.244.*+0 -n BLOCK -x
- %TEMP%\nss2.tmp\nsA.tmp ipseccmd -p Block5 -r Block5 -f 124.238.244.*+0 -n BLOCK -x
- %PROGRAM_FILES%\baidu\ipseccmd.exe -p Block6 -r Block6 -f 125.39.100.*+0 -n BLOCK -x
- %TEMP%\nss2.tmp\nsB.tmp ipseccmd -p Block6 -r Block6 -f 125.39.100.*+0 -n BLOCK -x
- %PROGRAM_FILES%\baidu\ipseccmd.exe -p Block3 -r BlockTWO -f 122.70.130.*+0 -n BLOCK -x
- %TEMP%\nss2.tmp\ns8.tmp ipseccmd -p Block3 -r BlockTWO -f 122.70.130.*+0 -n BLOCK -x
- %PROGRAM_FILES%\baidu\ipseccmd.exe -p Block4 -r BlockTHREE -f 124.238.243.*+0 -n BLOCK -x
- %TEMP%\nss2.tmp\ns9.tmp ipseccmd -p Block4 -r BlockTHREE -f 124.238.243.*+0 -n BLOCK -x
- <SYSTEM32>\rundll32.exe <SYSTEM32>\idecomp.dll RundllInstall NetHomeIDE
- <SYSTEM32>\runonce.exe -r
- <SYSTEM32>\sc.exe start PolicyAgent
- %PROGRAM_FILES%\baidu\is-SQPF6.tmp
- %PROGRAM_FILES%\baidu\is-098OM.tmp
- %PROGRAM_FILES%\baidu\is-VFL72.tmp
- <SYSTEM32>\hardpol\MyIEData\main.ini
- %PROGRAM_FILES%\baidu\spass.dll
- %PROGRAM_FILES%\baidu\dsetup.exe
- %PROGRAM_FILES%\baidu\passthru.dll
- %PROGRAM_FILES%\baidu\is-JUCEV.tmp
- %PROGRAM_FILES%\baidu\is-VPG88.tmp
- %PROGRAM_FILES%\baidu\is-D3PUT.tmp
- %TEMP%\is-I944M.tmp\spass.dll
- %PROGRAM_FILES%\baidu\is-F5LM6.tmp
- %PROGRAM_FILES%\baidu\is-QGQ27.tmp
- %PROGRAM_FILES%\baidu\is-LLHEN.tmp
- %PROGRAM_FILES%\baidu\is-V86O2.tmp
- %WINDIR%\inf\INFCACHE.0
- %WINDIR%\inf\oem4.PNF
- %WINDIR%\inf\oem4.inf
- <SYSTEM32>\SET14.tmp
- <SYSTEM32>\idecomp.dll
- %APPDATA%\MyIEData\main.ini
- <DRIVERS>\SET15.tmp
- %WINDIR%\inf\oem3.PNF
- %PROGRAM_FILES%\baidu\sumpod-nos.sys
- %PROGRAM_FILES%\baidu\newnetgar.dll
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\cf979f30-0db4-4cca-a77b-49332ea150ba
- %WINDIR%\inf\oem3.inf
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ec702f375e1b12d218f67ab9ef19ca23_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\Preferred
- %TEMP%\nsk4.tmp\ioSpecial.ini
- %TEMP%\nss2.tmp\Internet.dll
- %TEMP%\nss2.tmp\AccessControl.dll
- %TEMP%\nsk4.tmp\modern-wizard.bmp
- %TEMP%\nss2.tmp\nsExec.dll
- %PROGRAM_FILES%\baidu\ipseccmd.exe
- %TEMP%\nsk4.tmp\InstallOptions.dll
- %TEMP%\nss2.tmp\nsRandom.dll
- %PROGRAM_FILES%\baidu\s0001.xml
- %PROGRAM_FILES%\baidu\msfsg.exe
- %PROGRAM_FILES%\baidu\dsop7.xml
- <Current directory>\uuse-0001.exe
- %PROGRAM_FILES%\baidu\un1201214502315.exe
- %PROGRAM_FILES%\baidu\temp555.ini
- %TEMP%\nss2.tmp\System.dll
- %TEMP%\nss2.tmp\nsF.tmp
- %TEMP%\nss2.tmp\nsE.tmp
- %TEMP%\nss2.tmp\nsD.tmp
- %PROGRAM_FILES%\baidu\setup513839.exe
- %TEMP%\is-I944M.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-I944M.tmp\_isetup\_RegDLL.tmp
- %TEMP%\is-UQ77N.tmp\setup513839.tmp
- %TEMP%\nss2.tmp\nsC.tmp
- %TEMP%\nss2.tmp\ns7.tmp
- %TEMP%\nss2.tmp\ns6.tmp
- %TEMP%\nss2.tmp\ns5.tmp
- %TEMP%\nss2.tmp\ns8.tmp
- %TEMP%\nss2.tmp\nsB.tmp
- %TEMP%\nss2.tmp\nsA.tmp
- %TEMP%\nss2.tmp\ns9.tmp
- %TEMP%\nss2.tmp\nsD.tmp
- %TEMP%\nss2.tmp\nsC.tmp
- %TEMP%\nss2.tmp\nsB.tmp
- %PROGRAM_FILES%\baidu\msfsg.exe
- %TEMP%\nss2.tmp\nsF.tmp
- %TEMP%\nss2.tmp\nsE.tmp
- %TEMP%\nss2.tmp\ns7.tmp
- %TEMP%\nss2.tmp\ns6.tmp
- %TEMP%\nss2.tmp\ns5.tmp
- %TEMP%\nss2.tmp\nsA.tmp
- %TEMP%\nss2.tmp\ns9.tmp
- %TEMP%\nss2.tmp\ns8.tmp
- from %WINDIR%\inf\INFCACHE.2 to %WINDIR%\inf\OLDCACHE.000
- from %WINDIR%\inf\INFCACHE.1 to %WINDIR%\inf\INFCACHE.2
- 'tj.#ogle.cn':80
- tj.#ogle.cn/svr.asp?t=####################################
- DNS ASK tj.#ogle.cn
- 'localhost':1044
- '23#.#55.255.250':1900
- ClassName: '' WindowName: '??????...'
- ClassName: 'Shell_TrayWnd' WindowName: ''