Technical Information
- [HKLM\System\CurrentControlSet\Services\W32Print] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\W32Print] 'ImagePath' = 'C:\PaperSecu\svcpaper64.exe'
- [HKLM\SYSTEM\CurrentControlSet\Services\paperhkdrv] 'ImagePath' = 'C:\PAPERSECU\paperhk64.sys'
- 'W32Print' C:\PaperSecu\svcpaper64.exe
- 'paperhkdrv' C:\PAPERSECU\paperhk64.sys
- %WINDIR%\explorer.exe
- <SYSTEM32>\dwm.exe
- <SYSTEM32>\taskhost.exe
- iexplore.exe
- firefox.exe
- firefox.exe process, advapi32.dll module
- %TEMP%\nsg5d9b.tmp
- C:\papersecu\skin\eng\btn_con_2_default.bmp
- C:\papersecu\skin\eng\btn_con_1_over.bmp
- C:\papersecu\skin\eng\btn_con_1_down.bmp
- C:\papersecu\skin\eng\btn_con_1_default.bmp
- C:\papersecu\skin\eng\btn_cancel_over.bmp
- C:\papersecu\skin\eng\btn_cancel_down.bmp
- C:\papersecu\skin\eng\btn_cancel_default.bmp
- C:\papersecu\skin\eng\btn_bar_min_over.bmp
- C:\papersecu\skin\eng\btn_bar_min_down.bmp
- C:\papersecu\skin\eng\btn_bar_min_default.bmp
- C:\papersecu\skin\eng\btn_bar_max_over.bmp
- C:\papersecu\skin\eng\btn_bar_max_down.bmp
- C:\papersecu\skin\eng\btn_bar_max_default.bmp
- C:\papersecu\skin\eng\btn_bar_close_over.bmp
- C:\papersecu\skin\eng\btn_bar_close_down.bmp
- C:\papersecu\skin\eng\btn_bar_close_default.bmp
- C:\papersecu\skin\eng\btn_appcancel_over.bmp
- C:\papersecu\skin\eng\btn_appcancel_down.bmp
- C:\papersecu\skin\eng\btn_appcancel_default.bmp
- C:\papersecu\skin\eng\btn_login_default.bmp
- C:\papersecu\skin\eng\bg_table_2.bmp
- C:\papersecu\skin\eng\bg_table.bmp
- C:\papersecu\skin\eng\btn_con_3_down.bmp
- C:\papersecu\skin\eng\btn_con_2_down.bmp
- C:\papersecu\skin\eng\btn_getpolicy_over.bmp
- C:\papersecu\skin\eng\btn_getpolicy_down.bmp
- C:\papersecu\skin\eng\btn_getpolicy_default.bmp
- C:\papersecu\skin\eng\btn_exceptwater_over.bmp
- C:\papersecu\skin\eng\btn_exceptwater_down.bmp
- C:\papersecu\skin\eng\btn_exceptwater_disable.bmp
- C:\papersecu\skin\eng\btn_exceptwater_default.bmp
- C:\papersecu\skin\eng\btn_exceptclose_over.bmp
- C:\papersecu\skin\eng\btn_exceptclose_down.bmp
- C:\papersecu\skin\eng\btn_exceptclose_default.bmp
- C:\papersecu\skin\eng\btn_done_over.bmp
- C:\papersecu\skin\eng\btn_done_down.bmp
- C:\papersecu\skin\eng\btn_done_default.bmp
- C:\papersecu\skin\eng\btn_doprint_over.bmp
- C:\papersecu\skin\eng\btn_doprint_down.bmp
- C:\papersecu\skin\eng\btn_doprint_default.bmp
- C:\papersecu\skin\eng\btn_con_img.bmp
- C:\papersecu\skin\eng\btn_con_3_over.bmp
- C:\papersecu\skin\eng\btn_con_3_default.bmp
- C:\papersecu\skin\pop_logininfo_bar_right.bmp
- C:\papersecu\skin\eng\btn_con_2_over.bmp
- C:\papersecu\skin\sd_yes_voer.bmp
- C:\papersecu\skin\sd_yes_default.bmp
- C:\papersecu\skin\sd_no_over.bmp
- C:\papersecu\skin\sd_no_down.bmp
- C:\papersecu\skin\sd_no_default.bmp
- C:\papersecu\skin\sd_cancel_over.bmp
- C:\papersecu\skin\sd_cancel_down.bmp
- C:\papersecu\skin\sd_cancel_default.bmp
- C:\papersecu\skin\pop_title_bar_title.bmp
- C:\papersecu\skin\pop_title_bar_sp_title.bmp
- C:\papersecu\skin\pop_title_bar_bg.bmp
- C:\papersecu\skin\pop_loginnotice_line_part.bmp
- C:\papersecu\skin\pop_loginnotice_content_bg.bmp
- C:\papersecu\skin\pop_loginnotice_btn_over.bmp
- C:\papersecu\skin\pop_loginnotice_btn_down.bmp
- C:\papersecu\skin\pop_loginnotice_btn_default.bmp
- C:\papersecu\skin\pop_loginnotice_bar_title.bmp
- C:\papersecu\skin\pop_logininfo_content_part.bmp
- C:\papersecu\skin\pop_logininfo_content_logo.bmp
- C:\papersecu\skin\pop_logininfo_content_bg.bmp
- C:\papersecu\skin\eng\bg_info_2.bmp
- C:\papersecu\skin\eng\bg_menu.bmp
- C:\papersecu\skin\eng\bg_info_3.bmp
- C:\papersecu\skin\status_comm_success.bmp
- C:\papersecu\skin\sd_yes_dwon.bmp
- C:\papersecu\skin\eng\bg_info_1.bmp
- C:\papersecu\skin\eng\bg_content_3.bmp
- C:\papersecu\skin\eng\bg_content_2.bmp
- C:\papersecu\skin\eng\bg_content.bmp
- C:\papersecu\skin\eng\bg_border.bmp
- C:\papersecu\skin\trayicon.ico
- C:\papersecu\skin\logout.ico
- C:\papersecu\skin\login_r.ico
- C:\papersecu\skin\login.ico
- C:\papersecu\skin\icon1.ico
- C:\papersecu\skin\basic.ico
- C:\papersecu\skin\secu.ico
- C:\papersecu\skin\secu (2).ico
- C:\papersecu\skin\watermark_setting_bg_3.bmp
- C:\papersecu\skin\watermark_setting_bg_2.bmp
- C:\papersecu\skin\watermark_setting_bg_1.bmp
- C:\papersecu\skin\status_install_success.bmp
- C:\papersecu\skin\status_install_failed.bmp
- C:\papersecu\skin\status_comm_failed.bmp
- C:\papersecu\skin\pop_logininfo_bar_title.bmp
- C:\papersecu\skin\eng\btn_login_down.bmp
- C:\papersecu\skin\eng\info_img_2.bmp
- C:\papersecu\skin\eng\status_comm_success.bmp
- C:\papersecu\skin\eng\status_comm_failed.bmp
- C:\papersecu\skin\eng\sd_yes_voer.bmp
- C:\papersecu\skin\eng\sd_yes_dwon.bmp
- C:\papersecu\skin\eng\sd_yes_default.bmp
- C:\papersecu\skin\eng\sd_no_over.bmp
- C:\papersecu\skin\eng\sd_no_down.bmp
- C:\papersecu\skin\eng\sd_no_default.bmp
- C:\papersecu\skin\eng\sd_cancel_over.bmp
- C:\papersecu\skin\eng\sd_cancel_down.bmp
- C:\papersecu\skin\eng\sd_cancel_default.bmp
- C:\papersecu\skin\eng\pop_title_bar_title.bmp
- C:\papersecu\skin\eng\pop_title_bar_sp_title.bmp
- C:\papersecu\skin\eng\pop_title_bar_bg.bmp
- C:\papersecu\skin\eng\pop_loginnotice_line_part.bmp
- C:\papersecu\skin\eng\pop_loginnotice_content_bg.bmp
- C:\papersecu\skin\eng\pop_loginnotice_btn_over.bmp
- C:\papersecu\skin\eng\pop_loginnotice_btn_down.bmp
- C:\papersecu\skin\eng\pop_loginnotice_btn_default.bmp
- C:\papersecu\skin\eng\pop_logininfo_content_part.bmp
- C:\papersecu\skin\eng\pop_loginnotice_bar_title.bmp
- C:\papersecu\skin\eng\status_install_failed.bmp
- C:\papersecu\skin\eng\status_install_success.bmp
- C:\papersecu\debug\20240430_secugate.log
- %TEMP%\nsg5d9c.tmp\nsexec.dll
- C:\papersecu\sysback\secuprintdrvinfo.dat
- C:\papersecu\sysback\secuprintdrvidx.dat
- C:\papersecu\sysback\secuprinttle.dat
- C:\papersecu\sysback\secuprintfr.dat
- C:\papersecu\sysback\chkauth.dat
- C:\papersecu\sysback\secuprinteif.dat
- C:\papersecu\sysback\secuprintrc.dat
- C:\papersecu\skin\eng\trayicon.ico
- C:\papersecu\skin\btn_doprint_down.bmp
- C:\papersecu\skin\eng\logout.ico
- C:\papersecu\skin\eng\login_r.ico
- C:\papersecu\skin\eng\login.ico
- C:\papersecu\skin\eng\icon1.ico
- C:\papersecu\skin\eng\basic.ico
- C:\papersecu\skin\eng\secu.ico
- C:\papersecu\skin\eng\watermark_setting_bg_3.bmp
- C:\papersecu\skin\eng\watermark_setting_bg_2.bmp
- C:\papersecu\skin\eng\watermark_setting_bg_1.bmp
- C:\papersecu\skin\eng\btn_print_default.bmp
- C:\papersecu\skin\eng\btn_login_over.bmp
- C:\papersecu\skin\eng\pop_logininfo_bar_title.bmp
- C:\papersecu\skin\eng\pop_logininfo_content_bg.bmp
- C:\papersecu\skin\eng\info_bar.bmp
- C:\papersecu\skin\eng\icon_list.bmp
- C:\papersecu\skin\eng\icon_detail.bmp
- C:\papersecu\skin\eng\btn_watermark_apply_over.bmp
- C:\papersecu\skin\eng\btn_watermark_apply_down.bmp
- C:\papersecu\skin\eng\btn_watermark_apply_disable.bmp
- C:\papersecu\skin\eng\btn_watermark_apply_default.bmp
- C:\papersecu\skin\eng\btn_viewhistory_over.bmp
- C:\papersecu\skin\eng\btn_viewhistory_down.bmp
- C:\papersecu\skin\eng\btn_viewhistory_default.bmp
- C:\papersecu\skin\eng\btn_reset_over.bmp
- C:\papersecu\skin\eng\btn_reset_down.bmp
- C:\papersecu\skin\eng\btn_reset_default.bmp
- C:\papersecu\skin\eng\btn_refresh_over.bmp
- C:\papersecu\skin\eng\btn_refresh_down.bmp
- C:\papersecu\skin\eng\btn_refresh_default.bmp
- C:\papersecu\skin\eng\btn_print_over.bmp
- C:\papersecu\skin\eng\btn_print_down.bmp
- C:\papersecu\skin\eng\info_img_1.bmp
- C:\papersecu\skin\eng\pop_logininfo_content_logo.bmp
- C:\papersecu\skin\eng\info_img_3.bmp
- C:\papersecu\skin\eng\info_img_4.bmp
- C:\papersecu\skin\eng\line_part.bmp
- C:\papersecu\skin\eng\pop_logininfo_bar_bg.bmp
- C:\papersecu\skin\eng\part_btn_content_bar.bmp
- C:\papersecu\skin\eng\part_btn_content.bmp
- C:\papersecu\skin\eng\menu_3_over.bmp
- C:\papersecu\skin\eng\menu_3_expand.bmp
- C:\papersecu\skin\eng\menu_3_default.bmp
- C:\papersecu\skin\eng\menu_2_over.bmp
- C:\papersecu\skin\eng\menu_2_expand.bmp
- C:\papersecu\skin\eng\menu_2_default.bmp
- C:\papersecu\skin\eng\menu_1_over.bmp
- C:\papersecu\skin\eng\menu_1_expand.bmp
- C:\papersecu\skin\eng\menu_1_default.bmp
- C:\papersecu\skin\eng\logo.bmp
- C:\papersecu\skin\eng\login_title.bmp
- C:\papersecu\skin\eng\login_subtitle_blat.bmp
- C:\papersecu\skin\eng\login_msg.bmp
- C:\papersecu\skin\eng\login_line.bmp
- C:\papersecu\skin\eng\login_bg.bmp
- C:\papersecu\skin\eng\pop_logininfo_bar_right.bmp
- C:\papersecu\skin\pop_logininfo_bar_bg.bmp
- C:\papersecu\skin\part_btn_content_bar.bmp
- C:\papersecu\skin\part_btn_content.bmp
- C:\papersecu\lidllbroker.exe
- C:\papersecu\secuprtsso.dll
- C:\papersecu\spnacsso.exe
- C:\papersecu\litextfilter_count64.dll
- C:\papersecu\litextfilter_count32.dll
- C:\papersecu\liprtmgrpopup64.dll
- C:\papersecu\liprtmgrpopup32.dll
- C:\papersecu\lichoosecolor64.dll
- C:\papersecu\lichoosecolor32.dll
- C:\papersecu\lichkprtdrv.exe
- C:\papersecu\liprtctlmgr64.dll
- C:\papersecu\liprtctlmgr32.dll
- C:\papersecu\libp2t64.dll
- C:\papersecu\libp2t32.dll
- C:\papersecu\libsp0164.dll
- C:\papersecu\libsp01.dll
- C:\papersecu\lipaperhkext64.dll
- C:\papersecu\lipaperhkext32.dll
- C:\papersecu\lisearchdlg64.dll
- C:\papersecu\paperphk32.dll
- C:\papersecu\skin\bg_border.bmp
- C:\papersecu\paperphk64.dll
- C:\papersecu\paperprn.ini
- C:\papersecu\liconv2gray64.dll
- C:\papersecu\liconv2gray32.dll
- C:\papersecu\lisecuchkdll64.dll
- C:\papersecu\lisecuchkdll32.dll
- C:\papersecu\spsessionmgr32.exe
- C:\papersecu\srencrpt.dll
- C:\papersecu\spcorehk64.dll
- C:\papersecu\spcorehk32.dll
- C:\papersecu\nscif4sp64.dll
- C:\papersecu\nscif4sp32.dll
- C:\papersecu\spctrlotp.exe
- C:\papersecu\getssoinfo.dll
- C:\papersecu\eptrayutil.dll
- C:\papersecu\epadm2.ocx
- C:\papersecu\secuautoup64.exe
- C:\papersecu\secuautoup32.exe
- C:\papersecu\secuauth32.exe
- C:\papersecu\spver.dat
- C:\papersecu\libspcomm64.dll
- C:\papersecu\libspcomm32.dll
- C:\papersecu\liifbroker.exe
- C:\papersecu\limsgboxdll32.dll
- C:\papersecu\seculog32.exe
- C:\papersecu\litextfilter32.dll
- C:\papersecu\paperhk32.sys
- C:\papersecu\paperhk64.sys
- C:\papersecu\paperhk32.dll
- C:\papersecu\paperhk64.dll
- C:\papersecu\injhookdll32.exe
- C:\papersecu\injhookdll64.exe
- C:\papersecu\secujobctrl32.exe
- C:\papersecu\seculogin.exe
- C:\papersecu\pipopup.dll
- C:\papersecu\pipopup64.dll
- C:\papersecu\iniencman.exe
- C:\papersecu\instfile.ini
- C:\papersecu\libqrencode-3_x86.dll
- %TEMP%\nsg5d9c.tmp\execdos.dll
- C:\papersecu\upgrade\secuservicechange.exe
- %TEMP%\nsg5d9c.tmp\nsprocess.dll
- %TEMP%\nsg5d9c.tmp\system.dll
- C:\papersecu\remotecall.html
- C:\papersecu\librowserctrl.exe
- C:\papersecu\skin\bg_content.bmp
- C:\papersecu\paperdel64.exe
- C:\papersecu\limsgboxdll64.dll
- C:\papersecu\svcpaper32.exe
- C:\papersecu\paperdel32.exe
- C:\papersecu\litextfilter64.dll
- C:\papersecu\lisecuauthdll64.dll
- C:\papersecu\lisecuauthdll32.dll
- C:\papersecu\secugate64.exe
- C:\papersecu\cpprtct.dll
- C:\papersecu\secugate32.exe
- C:\papersecu\libqrencode-3_x64.dll
- C:\papersecu\secuproperty32.exe
- C:\papersecu\verifyinj.exe
- C:\papersecu\remotecall_c.html
- C:\papersecu\cpprtct64.dll
- C:\papersecu\papersrv64.exe
- C:\papersecu\papersrv32.exe
- C:\papersecu\remotecall_e.html
- C:\papersecu\trayauthdll32.dll
- C:\papersecu\trayauth32.exe
- C:\papersecu\paperinj32.dll
- C:\papersecu\svcpaper64.exe
- C:\papersecu\lisearchdlg32.dll
- C:\papersecu\skin\bg_content_2.bmp
- C:\papersecu\skin\btn_watermark_apply_over.bmp
- C:\papersecu\skin\btn_getpolicy_over.bmp
- C:\papersecu\skin\btn_watermark_apply_down.bmp
- C:\papersecu\skin\btn_watermark_apply_disable.bmp
- C:\papersecu\skin\btn_watermark_apply_default.bmp
- C:\papersecu\skin\btn_viewhistory_over.bmp
- C:\papersecu\skin\btn_viewhistory_down.bmp
- C:\papersecu\skin\btn_viewhistory_default.bmp
- C:\papersecu\skin\btn_reset_over.bmp
- C:\papersecu\skin\btn_reset_down.bmp
- C:\papersecu\skin\btn_reset_default.bmp
- C:\papersecu\skin\btn_refresh_over.bmp
- C:\papersecu\skin\btn_refresh_down.bmp
- C:\papersecu\skin\btn_refresh_default.bmp
- C:\papersecu\skin\btn_print_over.bmp
- C:\papersecu\skin\btn_print_down.bmp
- C:\papersecu\skin\btn_print_default.bmp
- C:\papersecu\skin\btn_login_over.bmp
- C:\papersecu\skin\btn_login_down.bmp
- C:\papersecu\skin\btn_login_default.bmp
- C:\papersecu\skin\btn_getpolicy_default.bmp
- C:\papersecu\skin\icon_detail.bmp
- C:\papersecu\skin\icon_list.bmp
- C:\papersecu\skin\info_bar.bmp
- C:\papersecu\skin\info_img_1.bmp
- C:\papersecu\skin\menu_3_expand.bmp
- C:\papersecu\skin\menu_3_default.bmp
- C:\papersecu\skin\menu_2_over.bmp
- C:\papersecu\skin\menu_2_expand.bmp
- C:\papersecu\skin\menu_2_default.bmp
- C:\papersecu\skin\menu_1_over.bmp
- C:\papersecu\skin\menu_1_expand.bmp
- C:\papersecu\skin\menu_1_default.bmp
- C:\papersecu\skin\logo.bmp
- C:\papersecu\skin\login_title.bmp
- C:\papersecu\skin\login_subtitle_blat.bmp
- C:\papersecu\skin\login_msg.bmp
- C:\papersecu\skin\login_line.bmp
- C:\papersecu\skin\login_bg.bmp
- C:\papersecu\skin\line_part.bmp
- C:\papersecu\skin\info_img_4.bmp
- C:\papersecu\skin\info_img_3.bmp
- C:\papersecu\skin\info_img_2.bmp
- C:\papersecu\skin\menu_3_over.bmp
- C:\papersecu\skin\btn_getpolicy_down.bmp
- C:\papersecu\skin\btn_exceptwater_over.bmp
- C:\papersecu\skin\bg_content_3.bmp
- C:\papersecu\skin\btn_bar_min_over.bmp
- C:\papersecu\skin\btn_bar_min_down.bmp
- C:\papersecu\skin\btn_bar_min_default.bmp
- C:\papersecu\skin\btn_bar_max_over.bmp
- C:\papersecu\skin\btn_bar_max_down.bmp
- C:\papersecu\skin\btn_bar_max_default.bmp
- C:\papersecu\skin\btn_bar_close_over.bmp
- C:\papersecu\skin\btn_bar_close_down.bmp
- C:\papersecu\skin\btn_bar_close_default.bmp
- C:\papersecu\skin\btn_appcancel_over.bmp
- C:\papersecu\skin\btn_appcancel_down.bmp
- C:\papersecu\skin\btn_appcancel_default.bmp
- C:\papersecu\skin\bg_table_2.bmp
- C:\papersecu\skin\bg_table.bmp
- C:\papersecu\skin\bg_menu.bmp
- C:\papersecu\skin\bg_info_3.bmp
- C:\papersecu\skin\bg_info_2.bmp
- C:\papersecu\skin\bg_info_1.bmp
- C:\papersecu\skin\btn_cancel_down.bmp
- C:\papersecu\skin\btn_cancel_over.bmp
- C:\papersecu\skin\btn_cancel_default.bmp
- C:\papersecu\skin\btn_con_1_default.bmp
- C:\papersecu\skin\btn_exceptwater_down.bmp
- C:\papersecu\skin\btn_con_1_down.bmp
- C:\papersecu\skin\btn_exceptwater_disable.bmp
- C:\papersecu\skin\btn_exceptwater_default.bmp
- C:\papersecu\skin\btn_exceptclose_over.bmp
- C:\papersecu\skin\btn_exceptclose_down.bmp
- C:\papersecu\skin\btn_exceptclose_default.bmp
- C:\papersecu\skin\btn_done_over.bmp
- C:\papersecu\skin\btn_done_down.bmp
- C:\papersecu\skin\btn_done_default.bmp
- C:\papersecu\sysback\pdfcidinfo.dat
- %TEMP%\nsg5d9c.tmp\simplefc.dll
- C:\papersecu\skin\btn_doprint_default.bmp
- C:\papersecu\skin\btn_con_img.bmp
- C:\papersecu\skin\btn_con_3_over.bmp
- C:\papersecu\skin\btn_con_3_down.bmp
- C:\papersecu\skin\btn_con_3_default.bmp
- C:\papersecu\skin\btn_con_2_over.bmp
- C:\papersecu\skin\btn_con_2_down.bmp
- C:\papersecu\skin\btn_con_2_default.bmp
- C:\papersecu\skin\btn_con_1_over.bmp
- C:\papersecu\skin\btn_doprint_over.bmp
- C:\papersecu\debug\20240430_seculogin.log
- C:\papersecu\upgrade\secuservicechange.exe
- %TEMP%\nsg5d9c.tmp\execdos.dll
- %TEMP%\nsg5d9c.tmp\nsexec.dll
- %TEMP%\nsg5d9c.tmp\nsprocess.dll
- %TEMP%\nsg5d9c.tmp\simplefc.dll
- %TEMP%\nsg5d9c.tmp\system.dll
- '10.#9.7.70':5432
- ClassName: 'papersrv' WindowName: 'PAPERSRV'
- 'C:\papersecu\upgrade\secuservicechange.exe' delete W32Print
- 'C:\papersecu\svcpaper64.exe'
- 'C:\papersecu\secugate64.exe' -s
- 'C:\papersecu\papersrv64.exe'
- 'C:\papersecu\seculogin.exe'
- 'C:\papersecu\injhookdll64.exe'
- 'C:\papersecu\upgrade\secuservicechange.exe' delete W32Print' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete W32Print' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' start W32Print' (with hidden window)
- 'C:\papersecu\injhookdll64.exe' ' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' delete W32Print
- '%WINDIR%\syswow64\sc.exe' create W32Print binpath= "C:\PaperSecu\svcpaper64.exe" start= auto DisplayName= "Windows Spooler"
- '%WINDIR%\syswow64\sc.exe' start W32Print