Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\NSecRTS] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\NSecRTS] 'ImagePath' = '"%CommonProgramFiles(x86)%\NSEC\NSecRTS.exe" -r'
- [HKLM\SYSTEM\CurrentControlSet\Services\nsdiskcrypt] 'ImagePath' = '%CommonProgramFiles(x86)%\NSEC\drivers\nsdiskcrypt\win10\nsdiskcrypt-x64.sys'
- 'NSecRTS' "%CommonProgramFiles(x86)%\NSEC\NSecRTS.exe" -r
- 'nsdiskcrypt' %CommonProgramFiles(x86)%\NSEC\drivers\nsdiskcrypt\win10\nsdiskcrypt-x64.sys
- Handler for all processes: %CommonProgramFiles(x86)%\NSEC\DtCore32.dll
- %CommonProgramFiles(x86)%\nsec\api-ms-win-crt-utility-l1-1-1.dll
- %CommonProgramFiles(x86)%\nsec\buildin.cfg
- %CommonProgramFiles(x86)%\nsec\cldlib.dll
- %CommonProgramFiles(x86)%\nsec\curlib.dll
- %CommonProgramFiles(x86)%\nsec\dcformat.exe
- %CommonProgramFiles(x86)%\nsec\dcmount.dll
- %CommonProgramFiles(x86)%\nsec\devcon32.dll
- %CommonProgramFiles(x86)%\nsec\dtcore32.dll
- %CommonProgramFiles(x86)%\nsec\x64\winfsp-x64.dll
- %CommonProgramFiles(x86)%\nsec\dtcore321.dll
- %CommonProgramFiles(x86)%\nsec\htmlparser32.dll
- %CommonProgramFiles(x86)%\nsec\imagehelperex.dll
- %CommonProgramFiles(x86)%\nsec\imceb.dll
- %CommonProgramFiles(x86)%\nsec\imdec2.dll
- %CommonProgramFiles(x86)%\nsec\import_root_cert.exe
- %CommonProgramFiles(x86)%\nsec\instrap.exe
- %CommonProgramFiles(x86)%\nsec\ipcs.dll
- %CommonProgramFiles(x86)%\nsec\7zr.exe
- %CommonProgramFiles(x86)%\nsec\actag.dat
- %CommonProgramFiles(x86)%\nsec\x64\winonedlp.dll
- %CommonProgramFiles(x86)%\nsec\x64\winfs.dll
- %CommonProgramFiles(x86)%\nsec\libapr-1.dll
- %CommonProgramFiles(x86)%\nsec\plugins\rd\nsecrd.exe
- %CommonProgramFiles(x86)%\nsec\plugins\rd\setcad.exe
- %CommonProgramFiles(x86)%\nsec\plugins\rd\setpasswd.exe
- %CommonProgramFiles(x86)%\nsec\plugins\rd\testauth.exe
- %CommonProgramFiles(x86)%\nsec\plugins\rd\uvnckeyboardhelper.exe
- %CommonProgramFiles(x86)%\nsec\plugins\rd\uvnc_settings.exe
- %CommonProgramFiles(x86)%\nsec\knurt.dll
- %CommonProgramFiles(x86)%\nsec\plugins\rd\logging.dll
- %CommonProgramFiles(x86)%\nsec\fixit.exe
- %CommonProgramFiles(x86)%\nsec\plugins\rd\vnchooks.dll
- %CommonProgramFiles(x86)%\nsec\ui\nsecex.exe
- %CommonProgramFiles(x86)%\nsec\x64\devcon64.dll
- %CommonProgramFiles(x86)%\nsec\x64\dtcore64.dll
- %CommonProgramFiles(x86)%\nsec\x64\htmlparser64.dll
- %CommonProgramFiles(x86)%\nsec\x64\nsecrts.exe
- %CommonProgramFiles(x86)%\nsec\x64\windtecore64.dll
- %CommonProgramFiles(x86)%\nsec\plugins\rd\workgrpdomnt4.dll
- %CommonProgramFiles(x86)%\nsec\plugins\xphelper\normaliz.dll
- %CommonProgramFiles(x86)%\nsec\plugins\speccy2s.exe
- %CommonProgramFiles(x86)%\nsec\drivers\nskrnl\nseckrnl32.sys
- %CommonProgramFiles(x86)%\nsec\libapriconv-1.dll
- %CommonProgramFiles(x86)%\nsec\winbaksvc.dll
- %CommonProgramFiles(x86)%\nsec\windessvc.dll
- %CommonProgramFiles(x86)%\nsec\windiskmgr.dll
- %CommonProgramFiles(x86)%\nsec\windowsupdate.dll
- %CommonProgramFiles(x86)%\nsec\windtecore32.dll
- %CommonProgramFiles(x86)%\nsec\winfs.dll
- %CommonProgramFiles(x86)%\nsec\winfsp-x86.dll
- %CommonProgramFiles(x86)%\nsec\winimdeca.dll
- %CommonProgramFiles(x86)%\nsec\webxml.dat
- %CommonProgramFiles(x86)%\nsec\plugins\rd\ldapauthnt4.dll
- %CommonProgramFiles(x86)%\nsec\urllib.dll
- %CommonProgramFiles(x86)%\nsec\winperfmon.dll
- %CommonProgramFiles(x86)%\nsec\winsomgr.dll
- %CommonProgramFiles(x86)%\nsec\winwatmrk.dll
- C:\nsec\cache.ini
- D:\nsec\cache.ini
- C:\nsec\debug\log\instrap.exe-user_2023-08-14.log
- <Current directory>\»úæ÷â루çëîððþ¸ä£©.txt
- %CommonProgramFiles(x86)%\nsec\winonedlp.dll
- %CommonProgramFiles(x86)%\nsec\winnetac.dll
- %CommonProgramFiles(x86)%\nsec\plugins\rd\mslogonacl.exe
- %CommonProgramFiles(x86)%\nsec\taskcollections.dll
- %CommonProgramFiles(x86)%\nsec\nsec.exe
- %CommonProgramFiles(x86)%\nsec\libcurl.dll
- %CommonProgramFiles(x86)%\nsec\libexpat.dll
- %CommonProgramFiles(x86)%\nsec\libssl-1_1.dll
- %CommonProgramFiles(x86)%\nsec\messagecenter.exe
- %CommonProgramFiles(x86)%\nsec\msvcr100.dll
- %CommonProgramFiles(x86)%\nsec\msvcr120.dll
- %CommonProgramFiles(x86)%\nsec\mxml1.dll
- %CommonProgramFiles(x86)%\nsec\trustednetwork.dll
- %CommonProgramFiles(x86)%\nsec\libaprutil-1.dll
- %CommonProgramFiles(x86)%\nsec\libcrypto-1_1.dll
- %CommonProgramFiles(x86)%\nsec\nsecrts.exe
- %CommonProgramFiles(x86)%\nsec\nshellext32.dll
- %CommonProgramFiles(x86)%\nsec\nslogon.exe
- %CommonProgramFiles(x86)%\nsec\nvnserver.exe
- %CommonProgramFiles(x86)%\nsec\onenac.dll
- %CommonProgramFiles(x86)%\nsec\osutil.dll
- %CommonProgramFiles(x86)%\nsec\softgenmgr.dll
- %CommonProgramFiles(x86)%\nsec\nfpcore.dll
- %CommonProgramFiles(x86)%\nsec\nfcore.dll
- %CommonProgramFiles(x86)%\nsec\plugins\rd\ldapauth9x.dll
- %CommonProgramFiles(x86)%\nsec\plugins\rd\ldapauth.dll
- %CommonProgramFiles(x86)%\nsec\plugins\rd\authssp.dll
- %CommonProgramFiles(x86)%\nsec\data\wc-sig_template.db
- %CommonProgramFiles(x86)%\nsec\data\workstat_template.db
- %CommonProgramFiles(x86)%\nsec\des\desh32.dll
- %CommonProgramFiles(x86)%\nsec\des\desh64.dll
- %CommonProgramFiles(x86)%\nsec\des\nefs32.dll
- %CommonProgramFiles(x86)%\nsec\des\nefs64.dll
- %CommonProgramFiles(x86)%\nsec\data\language.xml
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows10_20.jpg
- %CommonProgramFiles(x86)%\nsec\data\smartsnap_template.db
- %CommonProgramFiles(x86)%\nsec\des\nxdes32.dll
- %CommonProgramFiles(x86)%\nsec\drivers\nfsflts\win10\nfsflt64.inf
- %CommonProgramFiles(x86)%\nsec\drivers\nfsflts\win10\nfsflt64.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nfsflts\nfsflt32.inf
- %CommonProgramFiles(x86)%\nsec\drivers\nfsflts\nfsflt32.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nfsflts\nfsflt64.inf
- %CommonProgramFiles(x86)%\nsec\drivers\nfsflts\nfsflt64.sys
- %CommonProgramFiles(x86)%\nsec\des\nxdes64.dll
- %CommonProgramFiles(x86)%\nsec\drivers\nfsflts\win10\nfsflt32.inf
- %CommonProgramFiles(x86)%\nsec\drivers\nfsflts\win10\nfsflt32.sys
- C:\nsec\debug\log\nsecrts.exe-user_2023-08-14.log
- %CommonProgramFiles(x86)%\nsec\drivers\nnfp\win10\nnfp_win10_x64.sys
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows7_30.jpg
- %CommonProgramFiles(x86)%\nsec\data\db_template\doc_txt_db_template.db
- %CommonProgramFiles(x86)%\nsec\data\des\desbackup_init.db
- %CommonProgramFiles(x86)%\nsec\data\nslogon\arrow.png
- %CommonProgramFiles(x86)%\nsec\data\nslogon\guest.png
- %CommonProgramFiles(x86)%\nsec\data\nslogon\nsecscreen.xml
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows10.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows10_10.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows7_5.jpg
- %CommonProgramFiles(x86)%\nsec\data\av_feature.xml
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows10_15.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows10_30.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows10_5.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows7.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows7_10.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows7_15.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows7_20.jpg
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows7_25.jpg
- %CommonProgramFiles(x86)%\nsec\data\db_bk\readme.txt
- %CommonProgramFiles(x86)%\nsec\data\nslogon\windows10_25.jpg
- %CommonProgramFiles(x86)%\nsec\winpcinfo.dll
- %CommonProgramFiles(x86)%\nsec\drivers\nnfp\win10\nnfp_win10_x86.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nnfp\nnfp_win8_x64.sys
- %CommonProgramFiles(x86)%\nsec\nss\nssckbi.dll
- %CommonProgramFiles(x86)%\nsec\nss\nssdbm3.dll
- %CommonProgramFiles(x86)%\nsec\nss\nssutil3.dll
- %CommonProgramFiles(x86)%\nsec\nss\plc4.dll
- %CommonProgramFiles(x86)%\nsec\nss\plds4.dll
- %CommonProgramFiles(x86)%\nsec\nss\smime3.dll
- %CommonProgramFiles(x86)%\nsec\nss\softokn3.dll
- %CommonProgramFiles(x86)%\nsec\drivers\nnfp\nnfp_win7_x64.sys
- %CommonProgramFiles(x86)%\nsec\nss\nss3.dll
- %CommonProgramFiles(x86)%\nsec\nss\nspr4.dll
- %CommonProgramFiles(x86)%\nsec\plugins\all2txt\a2t.key
- %CommonProgramFiles(x86)%\nsec\plugins\all2txt\a2thlp.dll
- %CommonProgramFiles(x86)%\nsec\plugins\all2txt\a2thtm.dll
- %CommonProgramFiles(x86)%\nsec\plugins\all2txt\a2tpdf.dll
- %CommonProgramFiles(x86)%\nsec\plugins\all2txt\a2trtf.dll
- %CommonProgramFiles(x86)%\nsec\plugins\all2txt\a2txt.exe
- %CommonProgramFiles(x86)%\nsec\plugins\rd\authadmin.dll
- %CommonProgramFiles(x86)%\nsec\nss\sqlite3.dll
- %CommonProgramFiles(x86)%\nsec\plugins\7z\7z.exe
- %CommonProgramFiles(x86)%\nsec\drivers\nnfp\nnfp_win7_x86.sys
- %CommonProgramFiles(x86)%\nsec\plugins\7z\7z.dll
- %CommonProgramFiles(x86)%\nsec\data\recordcache_template.db
- %CommonProgramFiles(x86)%\nsec\drivers\nnfp\nnfp_win8_x86.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nnfp\nnfp_winxp_x86.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nsdiskcrypt\win10\nsdiskcrypt-x64.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nsdiskcrypt\win10\nsdiskcrypt-x86.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nsdiskcrypt\nsdiskcrypt-x64.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nsdiskcrypt\nsdiskcrypt-x86.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nskrnl\win10\nseckrnl32.sys
- %CommonProgramFiles(x86)%\nsec\nss\libplc4.dll
- %CommonProgramFiles(x86)%\nsec\nss\mozcrt19.dll
- %CommonProgramFiles(x86)%\nsec\nss\libplds4.dll
- %CommonProgramFiles(x86)%\nsec\libssl\nt5\libcrypto-1_1.dll
- %CommonProgramFiles(x86)%\nsec\libssl\nt5\libssl-1_1.dll
- %CommonProgramFiles(x86)%\nsec\libssl\nt6\libcrypto-1_1.dll
- %CommonProgramFiles(x86)%\nsec\libssl\nt6\libssl-1_1.dll
- %CommonProgramFiles(x86)%\nsec\nss\certutil.exe
- %CommonProgramFiles(x86)%\nsec\nss\freebl3.dll
- %CommonProgramFiles(x86)%\nsec\nss\libnspr4.dll
- %CommonProgramFiles(x86)%\nsec\drivers\nskrnl\win10\nseckrnl64.sys
- %CommonProgramFiles(x86)%\nsec\drivers\nskrnl\nseckrnl64.sys
- %CommonProgramFiles(x86)%\nsec\data\cfg.xml.tmp
- %CommonProgramFiles(x86)%\nsec\api-ms-win-crt-utility-l1-1-1.dll
- from %CommonProgramFiles(x86)%\nsec\data\cfg.xml.tmp to %CommonProgramFiles(x86)%\nsec\data\cfg.xml
- %CommonProgramFiles(x86)%\nsec\data\cfg.xml
- 'la##.####cn-beijing.ksyuncs.com':443
- 'oc##.dcocsp.cn':80
- '43.##3.190.188':28987
- http://oc##.dcocsp.cn/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAoEcNCWvIoSyJCm34Ju7Es%3D
- http://oc##.dcocsp.cn/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSmVYFXwi%2FRq9wx3PKhB8lC%2FFYUyAQUkZ9eMRWuEJ%2BtYMH3wcyqSDQvDCYCEAFZufkjTOnq%2FNVmggRnKgY%3D
- 'la##.####cn-beijing.ksyuncs.com':443
- '43.##3.190.188':28987
- DNS ASK la##.####cn-beijing.ksyuncs.com
- DNS ASK oc##.dcocsp.cn
- '%CommonProgramFiles(x86)%\nsec\instrap.exe'
- '%CommonProgramFiles(x86)%\nsec\nsecrts.exe'
- '%CommonProgramFiles(x86)%\nsec\nsecrts.exe' -i
- '%CommonProgramFiles(x86)%\nsec\nsecrts.exe' -r
- '%CommonProgramFiles(x86)%\nsec\x64\nsecrts.exe'
- '%CommonProgramFiles(x86)%\nsec\fixit.exe' -df
- '%CommonProgramFiles(x86)%\nsec\nss\certutil.exe' -A -t "TCu" -i "C:\PROGRA~2\COMMON~1\NSEC\Data/SSL/NSECNF~1.CER" -n "Data/SSL/NSEC NFCORE 2" -d sql:"%APPDATA%\THUNDE~1\Profiles\YRG4BO~1.DEF" -f pwfile
- '%CommonProgramFiles(x86)%\nsec\nss\certutil.exe' -A -t "TCu" -i "C:\PROGRA~2\COMMON~1\NSEC\Data/SSL/NSECNF~1.CER" -n "Data/SSL/NSEC NFCORE 2" -d sql:"%APPDATA%\Mozilla\Firefox\Profiles\LA5ZHZ~1.DEF" -f pwfile
- '%CommonProgramFiles(x86)%\nsec\instrap.exe' ' (with hidden window)
- '%CommonProgramFiles(x86)%\nsec\nsecrts.exe' -i' (with hidden window)
- '%CommonProgramFiles(x86)%\nsec\x64\nsecrts.exe' ' (with hidden window)
- '%CommonProgramFiles(x86)%\nsec\fixit.exe' -df' (with hidden window)
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\Microsoft Research\NSEC\NShellExt32.dll"' (with hidden window)
- '%CommonProgramFiles(x86)%\nsec\nss\certutil.exe' -A -t "TCu" -i "C:\PROGRA~2\COMMON~1\NSEC\Data/SSL/NSECNF~1.CER" -n "Data/SSL/NSEC NFCORE 2" -d sql:"%APPDATA%\THUNDE~1\Profiles\YRG4BO~1.DEF" -f pwfile' (with hidden window)
- '%CommonProgramFiles(x86)%\nsec\nss\certutil.exe' -A -t "TCu" -i "C:\PROGRA~2\COMMON~1\NSEC\Data/SSL/NSECNF~1.CER" -n "Data/SSL/NSEC NFCORE 2" -d sql:"%APPDATA%\Mozilla\Firefox\Profiles\LA5ZHZ~1.DEF" -f pwfile' (with hidden window)
- '%WINDIR%\syswow64\regsvr32.exe' /s "%ProgramFiles(x86)%\Microsoft Research\NSEC\NShellExt32.dll"