Creates the following files:
- %WINDIR%\inf\oem4.inf
- %WINDIR%\inf\oem4.PNF
- %WINDIR%\inf\INFCACHE.0
- %WINDIR%\inf\oem3.PNF
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\Preferred
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ec702f375e1b12d218f67ab9ef19ca23_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %WINDIR%\inf\oem3.inf
- <DRIVERS>\SET7.tmp
- <SYSTEM32>\netplayone\MyIEData\SysDat.bin
- %TEMP%\~nsu.tmp\Au_.exe
- %APPDATA%\NetHome\main.ini
- <SYSTEM32>\netplayone\netplayone.dll
- <DRIVERS>\SET8.tmp
- %APPDATA%\MyIEData\main.ini
- <SYSTEM32>\netplayone\MyIEData\main.ini
- %PROGRAM_FILES%\baidu\mpflt.inf
- %PROGRAM_FILES%\baidu\newnetgar.dll
- %PROGRAM_FILES%\baidu\spass.dll
- %PROGRAM_FILES%\baidu\mpflt_m.inf
- %PROGRAM_FILES%\baidu\siglow.dll
- %PROGRAM_FILES%\baidu\dsetup.exe
- %PROGRAM_FILES%\baidu\siglow.sys
- %PROGRAM_FILES%\baidu\SysDat.bin
- <SYSTEM32>\nethome32.dll
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\072922b6-b36d-4d9e-b63c-467f04a9bf5a
- %PROGRAM_FILES%\baidu\uninst13.exe
- %PROGRAM_FILES%\baidu\msfsg.exe
- %TEMP%\nsa2.tmp\System.dll
- %PROGRAM_FILES%\baidu\tempnethome13.ini
Deletes the following files:
- %PROGRAM_FILES%\baidu\tempnethome13.ini
- %PROGRAM_FILES%\baidu\mpflt.inf
- %PROGRAM_FILES%\baidu\newnetgar.dll
- %PROGRAM_FILES%\baidu\SysDat.bin
- %PROGRAM_FILES%\baidu\spass.dll
- %PROGRAM_FILES%\baidu\mpflt_m.inf
- %PROGRAM_FILES%\baidu\uninst13.exe
- %TEMP%\nsa2.tmp\System.dll
- %PROGRAM_FILES%\baidu\siglow.dll
- %PROGRAM_FILES%\baidu\dsetup.exe
- %PROGRAM_FILES%\baidu\siglow.sys
Moves the following system files:
- from %WINDIR%\inf\INFCACHE.2 to %WINDIR%\inf\OLDCACHE.000
- from %WINDIR%\inf\INFCACHE.1 to %WINDIR%\inf\INFCACHE.2
Moves the following files:
- from <DRIVERS>\SET8.tmp to <DRIVERS>\siglow.sys
- from <DRIVERS>\SET7.tmp to <DRIVERS>\siglow.dll
Deletes itself.