Technical Information
- '%TEMP%\nsh2.tmp\nsF.tmp' ipseccmd -p Block0 -r Block0 -f 118.145.31.*+0 -n BLOCK -x
- '%PROGRAM_FILES%\baidu\ipseccmd.exe' -p Block9 -r Block9 -f 221.194.142.*+0 -n BLOCK -x
- '%PROGRAM_FILES%\baidu\msfsg.exe' uncompress -s dsop7.xml -d setup139287.exe
- '%PROGRAM_FILES%\baidu\ipseccmd.exe' -p Block0 -r Block0 -f 118.145.31.*+0 -n BLOCK -x
- '%TEMP%\nsh2.tmp\nsD.tmp' ipseccmd -p Block8 -r Block8 -f 220.181.126.*+0 -n BLOCK -x
- '%PROGRAM_FILES%\baidu\ipseccmd.exe' -p Block7 -r Block7 -f 125.39.102.*+0 -n BLOCK -x
- '%TEMP%\nsh2.tmp\nsE.tmp' ipseccmd -p Block9 -r Block9 -f 221.194.142.*+0 -n BLOCK -x
- '%PROGRAM_FILES%\baidu\ipseccmd.exe' -p Block8 -r Block8 -f 220.181.126.*+0 -n BLOCK -x
- '%PROGRAM_FILES%\baidu\msfsg.exe' md5 -s newnetgar.dll -d newnetgar.dll
- '%PROGRAM_FILES%\baidu\msfsg.exe' md5 -s spass.dll -d spass.dll
- '%PROGRAM_FILES%\baidu\dsetup.exe' install
- '%PROGRAM_FILES%\baidu\msfsg.exe' md5 -s sumpod-nos.sys -d sumpod-nos.sys
- '%TEMP%\is-QM58A.tmp\setup139287.tmp' /SL5="$C0106,822829,54272,%PROGRAM_FILES%\baidu\setup139287.exe" /VERYSILENT /NORESTART
- '%PROGRAM_FILES%\baidu\setup139287.exe' /VERYSILENT /NORESTART
- '%PROGRAM_FILES%\baidu\msfsg.exe' md5 -s dsetup.exe -d dsetup.exe
- '%PROGRAM_FILES%\baidu\msfsg.exe' md5 -s passthru.dll -d passthru.dll
- '%TEMP%\nsh2.tmp\nsC.tmp' ipseccmd -p Block7 -r Block7 -f 125.39.102.*+0 -n BLOCK -x
- '%PROGRAM_FILES%\baidu\ipseccmd.exe' -p Block1 -r BlockTCP -f 119.147.91.*+0 -n BLOCK -x
- '%TEMP%\nsh2.tmp\ns6.tmp' ipseccmd -p Block1 -r BlockTCP -f 119.147.91.*+0 -n BLOCK -x
- '%PROGRAM_FILES%\baidu\ipseccmd.exe' -p Block2 -r BlockNEW -f 119.188.4.*+0 -n BLOCK -x
- '%TEMP%\nsh2.tmp\ns7.tmp' ipseccmd -p Block2 -r BlockNEW -f 119.188.4.*+0 -n BLOCK -x
- '%PROGRAM_FILES%\baidu\msfsg.exe' uncompress -s s0001.xml -d ipseccmd.exe
- '<Current directory>\uuse-5955.exe'
- '%TEMP%\nsh2.tmp\ns5.tmp' sc start PolicyAgent
- '%PROGRAM_FILES%\baidu\msfsg.exe' md5 -s ipseccmd.exe -d ipseccmd.exe -l 10000000
- '%PROGRAM_FILES%\baidu\ipseccmd.exe' -p Block5 -r Block5 -f 124.238.244.*+0 -n BLOCK -x
- '%TEMP%\nsh2.tmp\nsA.tmp' ipseccmd -p Block5 -r Block5 -f 124.238.244.*+0 -n BLOCK -x
- '%PROGRAM_FILES%\baidu\ipseccmd.exe' -p Block6 -r Block6 -f 125.39.100.*+0 -n BLOCK -x
- '%TEMP%\nsh2.tmp\nsB.tmp' ipseccmd -p Block6 -r Block6 -f 125.39.100.*+0 -n BLOCK -x
- '%PROGRAM_FILES%\baidu\ipseccmd.exe' -p Block3 -r BlockTWO -f 122.70.130.*+0 -n BLOCK -x
- '%TEMP%\nsh2.tmp\ns8.tmp' ipseccmd -p Block3 -r BlockTWO -f 122.70.130.*+0 -n BLOCK -x
- '%PROGRAM_FILES%\baidu\ipseccmd.exe' -p Block4 -r BlockTHREE -f 124.238.243.*+0 -n BLOCK -x
- '%TEMP%\nsh2.tmp\ns9.tmp' ipseccmd -p Block4 -r BlockTHREE -f 124.238.243.*+0 -n BLOCK -x
- '<SYSTEM32>\runonce.exe' -r
- '<SYSTEM32>\sc.exe' start PolicyAgent
- %PROGRAM_FILES%\baidu\is-SIOS4.tmp
- %PROGRAM_FILES%\baidu\is-O845P.tmp
- %PROGRAM_FILES%\baidu\is-B6P5C.tmp
- %PROGRAM_FILES%\baidu\is-NNSH3.tmp
- %PROGRAM_FILES%\baidu\passthru.dll
- <SYSTEM32>\hardpol\MyIEData\main.ini
- %PROGRAM_FILES%\baidu\is-GE3K4.tmp
- %PROGRAM_FILES%\baidu\is-CFJI5.tmp
- %TEMP%\is-RS2OO.tmp\spass.dll
- %TEMP%\is-RS2OO.tmp\_isetup\_shfoldr.dll
- %PROGRAM_FILES%\baidu\is-94IJD.tmp
- %PROGRAM_FILES%\baidu\is-7R5T4.tmp
- %PROGRAM_FILES%\baidu\is-I5MKO.tmp
- %PROGRAM_FILES%\baidu\is-POD4T.tmp
- %PROGRAM_FILES%\baidu\dsetup.exe
- %WINDIR%\inf\oem4.inf
- %WINDIR%\inf\oem3.PNF
- %WINDIR%\inf\oem3.inf
- %WINDIR%\inf\oem4.PNF
- <DRIVERS>\SET15.tmp
- <SYSTEM32>\SET14.tmp
- %WINDIR%\inf\INFCACHE.0
- %PROGRAM_FILES%\baidu\sumpod-nos.sys
- %PROGRAM_FILES%\baidu\newnetgar.dll
- %PROGRAM_FILES%\baidu\spass.dll
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ec702f375e1b12d218f67ab9ef19ca23_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\Preferred
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\2e7ba87a-9ed7-4749-b57c-b865192a08f1
- %TEMP%\nsh2.tmp\Internet.dll
- %TEMP%\nsh2.tmp\AccessControl.dll
- %TEMP%\nsh2.tmp\nsRandom.dll
- %TEMP%\nse4.tmp\ioSpecial.ini
- %PROGRAM_FILES%\baidu\ipseccmd.exe
- %TEMP%\nse4.tmp\InstallOptions.dll
- %TEMP%\nse4.tmp\modern-wizard.bmp
- %PROGRAM_FILES%\baidu\s0001.xml
- %PROGRAM_FILES%\baidu\msfsg.exe
- %PROGRAM_FILES%\baidu\dsop7.xml
- <Current directory>\uuse-5955.exe
- %PROGRAM_FILES%\baidu\un1204183018287.exe
- %PROGRAM_FILES%\baidu\temp1204183018287.ini
- %TEMP%\nsh2.tmp\System.dll
- %TEMP%\nsh2.tmp\nsExec.dll
- %TEMP%\nsh2.tmp\nsE.tmp
- %TEMP%\nsh2.tmp\nsD.tmp
- %TEMP%\nsh2.tmp\nsC.tmp
- %TEMP%\nsh2.tmp\nsF.tmp
- %TEMP%\is-RS2OO.tmp\_isetup\_RegDLL.tmp
- %TEMP%\is-QM58A.tmp\setup139287.tmp
- %PROGRAM_FILES%\baidu\setup139287.exe
- %TEMP%\nsh2.tmp\ns7.tmp
- %TEMP%\nsh2.tmp\ns6.tmp
- %TEMP%\nsh2.tmp\ns5.tmp
- %TEMP%\nsh2.tmp\ns8.tmp
- %TEMP%\nsh2.tmp\nsB.tmp
- %TEMP%\nsh2.tmp\nsA.tmp
- %TEMP%\nsh2.tmp\ns9.tmp
- %TEMP%\nsh2.tmp\nsD.tmp
- %TEMP%\nsh2.tmp\nsC.tmp
- %TEMP%\nsh2.tmp\nsB.tmp
- %PROGRAM_FILES%\baidu\msfsg.exe
- %TEMP%\nsh2.tmp\nsF.tmp
- %TEMP%\nsh2.tmp\nsE.tmp
- %TEMP%\nsh2.tmp\ns7.tmp
- %TEMP%\nsh2.tmp\ns6.tmp
- %TEMP%\nsh2.tmp\ns5.tmp
- %TEMP%\nsh2.tmp\nsA.tmp
- %TEMP%\nsh2.tmp\ns9.tmp
- %TEMP%\nsh2.tmp\ns8.tmp
- from %WINDIR%\inf\INFCACHE.2 to %WINDIR%\inf\OLDCACHE.000
- from %WINDIR%\inf\INFCACHE.1 to %WINDIR%\inf\INFCACHE.2
- from %PROGRAM_FILES%\baidu\is-NNSH3.tmp to %PROGRAM_FILES%\baidu\netsf_m.inf
- from %PROGRAM_FILES%\baidu\is-SIOS4.tmp to %PROGRAM_FILES%\baidu\netsf.inf
- from %PROGRAM_FILES%\baidu\is-O845P.tmp to %PROGRAM_FILES%\baidu\msfsg.exe
- from <DRIVERS>\SET15.tmp to <DRIVERS>\sumpod.sys
- from <SYSTEM32>\SET14.tmp to <SYSTEM32>\passthru.dll
- from %PROGRAM_FILES%\baidu\is-GE3K4.tmp to %PROGRAM_FILES%\baidu\SysDat.bin
- from %PROGRAM_FILES%\baidu\is-POD4T.tmp to %PROGRAM_FILES%\baidu\sumpod.sys
- from %PROGRAM_FILES%\baidu\is-94IJD.tmp to %PROGRAM_FILES%\baidu\dsetup.exe
- from %PROGRAM_FILES%\baidu\is-CFJI5.tmp to %PROGRAM_FILES%\baidu\passthru.dll
- from %PROGRAM_FILES%\baidu\is-B6P5C.tmp to %PROGRAM_FILES%\baidu\spass.dll
- from %PROGRAM_FILES%\baidu\is-7R5T4.tmp to %PROGRAM_FILES%\baidu\newnetgar.dll
- from %PROGRAM_FILES%\baidu\is-I5MKO.tmp to %PROGRAM_FILES%\baidu\sumpod-nos.sys
- 'tj.#ogle.cn':80
- tj.#ogle.cn/svr.asp?t=####################################
- DNS ASK tj.#ogle.cn
- ClassName: '(null)' WindowName: '??????...'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'