Technical Information
- %WINDIR%\win.ini
- [HKLM\System\CurrentControlSet\Services\.Winhlpsvr] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\.Winhlpsvr] 'ImagePath' = '"%CommonProgramFiles(x86)%\System\winrdgv3.exe"'
- [HKLM\System\CurrentControlSet\Services\TsdEncrypt] 'Start' = '00000000'
- [HKLM\System\CurrentControlSet\Services\TsdEncrypt] 'ImagePath' = 'system32\drivers\TsdEncrypt.sys'
- [HKLM\System\CurrentControlSet\Services\TFsfltdrv] 'ImagePath' = '<DRIVERS>\tfsfltdrv.sys'
- '.Winhlpsvr' "%CommonProgramFiles(x86)%\System\winrdgv3.exe"
- '.Winhlpsvr' %CommonProgramFiles(x86)%\System\winrdgv3.exe
- 'TsdEncrypt' <DRIVERS>\TsdEncrypt.sys
- 'TFsfltdrv' <DRIVERS>\tfsfltdrv.sys
- %WINDIR%\syswow64\msvcp140_1.dll
- %WINDIR%\syswow64\vcruntime140.dll
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="winrdlv3" dir=in action=allow program="<SYSTEM32>\winrdlv3.exe"
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name="winrdlv3" dir=out action=allow program="<SYSTEM32>\winrdlv3.exe"
- [HKLM\System\CurrentControlSet\Services\TsdEncrypt] 'Group' = 'FSFilter Encryption'
- %TEMP%\nsla2d4.tmp
- %WINDIR%\syswow64\endata\aw_1023.dat
- %WINDIR%\syswow64\endata\aw_1024.dat
- %WINDIR%\syswow64\endata\aw_1025.dat
- %WINDIR%\syswow64\endata\aw_1026.dat
- %WINDIR%\syswow64\endata\aw_1027.dat
- %WINDIR%\syswow64\endata\aw_1028.dat
- %WINDIR%\syswow64\endata\aw_1029.dat
- %WINDIR%\syswow64\endata\aw_1021.dat
- %WINDIR%\syswow64\endata\aw_1022.dat
- %WINDIR%\syswow64\endata\aw_1030.dat
- %WINDIR%\syswow64\endata\aw_1034.dat
- %WINDIR%\syswow64\endata\aw_1035.dat
- %WINDIR%\syswow64\endata\aw_1036.dat
- %WINDIR%\syswow64\endata\aw_1037.dat
- %WINDIR%\syswow64\endata\aw_1039.dat
- %WINDIR%\syswow64\endata\aw_1040.dat
- %WINDIR%\syswow64\endata\aw_1042.dat
- %WINDIR%\syswow64\endata\aw_1032.dat
- %WINDIR%\syswow64\endata\aw_1033.dat
- %WINDIR%\syswow64\endata\aw_1020.dat
- %WINDIR%\syswow64\endata\aw_1019.dat
- %WINDIR%\syswow64\endata\aw_1018.dat
- %WINDIR%\syswow64\endata\aw2_1005.dat
- %WINDIR%\syswow64\endata\aw2_1006.dat
- %WINDIR%\syswow64\endata\aw2_1007.dat
- %WINDIR%\syswow64\endata\aw2_1008.dat
- %WINDIR%\syswow64\endata\aw2_1009.dat
- %WINDIR%\syswow64\endata\aw2_1010.dat
- %WINDIR%\syswow64\endata\aw_1001.dat
- %WINDIR%\syswow64\endata\aw_1002.dat
- %WINDIR%\syswow64\endata\aw2_1004.dat
- %WINDIR%\syswow64\endata\aw_1003.dat
- %WINDIR%\syswow64\endata\aw_1006.dat
- %WINDIR%\syswow64\endata\aw_1007.dat
- %WINDIR%\syswow64\endata\aw_1008.dat
- %WINDIR%\syswow64\endata\aw_1010.dat
- %WINDIR%\syswow64\endata\aw_1012.dat
- %WINDIR%\syswow64\endata\aw_1015.dat
- %WINDIR%\syswow64\endata\aw_1016.dat
- %WINDIR%\syswow64\endata\aw_1017.dat
- %WINDIR%\syswow64\endata\aw_1004.dat
- %WINDIR%\syswow64\endata\aw_1043.dat
- %WINDIR%\syswow64\endata\aw_1045.dat
- %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\metadata\c86bd7751d53f10f65aaad66bbdf33c7
- %WINDIR%\syswow64\endata\aw_1046.dat
- %WINDIR%\syswow64\position\qtposition_positionpoll.dll
- %WINDIR%\syswow64\position\qtposition_serialnmea.dll
- %WINDIR%\syswow64\position\qtposition_winrt.dll
- %WINDIR%\syswow64\qmltooling\qmldbg_debugger.dll
- %WINDIR%\syswow64\qmltooling\qmldbg_inspector.dll
- %WINDIR%\syswow64\qmltooling\qmldbg_local.dll
- %WINDIR%\syswow64\qmltooling\qmldbg_messages.dll
- %WINDIR%\syswow64\platforminputcontexts\qtvirtualkeyboardplugin.dll
- %WINDIR%\syswow64\platforms\qwindows.dll
- %WINDIR%\syswow64\qmltooling\qmldbg_native.dll
- %WINDIR%\syswow64\qmltooling\qmldbg_profiler.dll
- %WINDIR%\syswow64\qmltooling\qmldbg_quickprofiler.dll
- %WINDIR%\syswow64\qmltooling\qmldbg_server.dll
- %WINDIR%\syswow64\qmltooling\qmldbg_tcp.dll
- %WINDIR%\syswow64\zdefaultskin\zminiui.xml
- %WINDIR%\syswow64\zdefaultskin\zdefaultskin.ui
- %TEMP%\nsba2e5.tmp\nsexec.dll
- %WINDIR%\syswow64\qmltooling\qmldbg_nativedebugger.dll
- %WINDIR%\syswow64\qmltooling\qmldbg_preview.dll
- %WINDIR%\syswow64\imageformats\qwebp.dll
- %WINDIR%\syswow64\imageformats\qwbmp.dll
- %WINDIR%\syswow64\imageformats\qtiff.dll
- %WINDIR%\syswow64\endata\aw_1049.dat
- %WINDIR%\syswow64\endata\aw_1050.dat
- %WINDIR%\syswow64\endata\awa_1001.dat
- %WINDIR%\syswow64\endata\dt_1.dat
- %WINDIR%\syswow64\endata\dt_2.dat
- %WINDIR%\syswow64\endata\dt_3.dat
- %WINDIR%\syswow64\endata\dt_4.dat
- %WINDIR%\syswow64\endata\h_1.dat
- %WINDIR%\syswow64\endata\aw_1047.dat
- %WINDIR%\syswow64\endata\h_2.dat
- %WINDIR%\syswow64\iconengines\qsvgicon.dll
- %WINDIR%\syswow64\imageformats\qgif.dll
- %WINDIR%\syswow64\imageformats\qicns.dll
- %WINDIR%\syswow64\imageformats\qico.dll
- %WINDIR%\syswow64\imageformats\qjpeg.dll
- %WINDIR%\syswow64\imageformats\qpdf.dll
- %WINDIR%\syswow64\imageformats\qsvg.dll
- %WINDIR%\syswow64\imageformats\qtga.dll
- %WINDIR%\syswow64\endata\h_3.dat
- %WINDIR%\syswow64\endata\aw2_1002.dat
- %WINDIR%\syswow64\endata\aw_1044.dat
- %WINDIR%\syswow64\endata\aw2_1001.dat
- %WINDIR%\syswow64\app_hotdefault.png
- %WINDIR%\syswow64\ocular\msusersystemservercfgclass.dat
- %WINDIR%\syswow64\ocular\msusersystemservercfgclass2.dat
- %WINDIR%\syswow64\ocular\agenttask\agenttasklist.dat
- %WINDIR%\syswow64\config\systemprofile\appdata\roaming\tencent\qqpcmgr\qmdellog.dat
- %WINDIR%\syswow64\config\systemprofile\appdata\roaming\tencent\teniodl\1501\cache\download.db
- %WINDIR%\syswow64\channel.dat
- %WINDIR%\syswow64\config.ini
- %WINDIR%\syswow64\ocular\msmidtierserverclass3.dat
- %WINDIR%\syswow64\ocular\msodhash3.dat
- %WINDIR%\syswow64\dcsys.res
- %WINDIR%\syswow64\download.png
- %WINDIR%\syswow64\qt5qmlworkerscript.dll
- %WINDIR%\syswow64\qt5serialport.dll
- %WINDIR%\syswow64\api-ms-win-core-localization-l1-2-8.dll
- %WINDIR%\syswow64\api-ms-win-shcore-scaling-l1-1-1.dll
- %WINDIR%\syswow64\apk_icon.png
- %WINDIR%\syswow64\app_cancel.png
- %WINDIR%\syswow64\dcsysu.res
- %WINDIR%\syswow64\display.amd.20150715.scindex
- %WINDIR%\syswow64\ocular\msmailboxidentify.dat
- %WINDIR%\syswow64\ocular\msmailboxcalss.dat
- %WINDIR%\syswow64\ocular\msagentclass.dat
- %TEMP%\nsba2e5.tmp\system.dll
- <SYSTEM32>\winwdgv364.dll
- %CommonProgramFiles(x86)%\system\systecv3.exe
- %CommonProgramFiles(x86)%\system\winrdgv3.exe
- %WINDIR%\bakoav3.sys
- %WINDIR%\bakrdgv3.sys
- %WINDIR%\bakrdlv3.sys
- %WINDIR%\bakstec3.sys
- %TEMP%\nsba2e5.tmp\nsprocess.dll
- %WINDIR%\bakwdgv3.sys
- %WINDIR%\linstsvr.exe
- %WINDIR%\syswow64\bakrdgv3.sys
- %WINDIR%\syswow64\bakstec3.sys
- %WINDIR%\syswow64\winoav3.dll
- %WINDIR%\syswow64\winrdlv3.exe
- %WINDIR%\syswow64\winwdgv3.dll
- %WINDIR%\syswow64\ocular\oagent.ini
- %WINDIR%\syswow64\ocular\opolicy.ini
- %WINDIR%\bakwdgv364.sys
- %WINDIR%\syswow64\app_default.png
- %WINDIR%\syswow64\app_load.gif
- %WINDIR%\syswow64\bearer\qgenericbearer.dll
- %WINDIR%\syswow64\app_mmove.png
- %WINDIR%\syswow64\cmdline\zh_cn.txt
- %WINDIR%\syswow64\cmdline\zh_hk.txt
- %WINDIR%\syswow64\cmdline\zh_tw.txt
- %WINDIR%\syswow64\languages\en_us.ini
- %WINDIR%\syswow64\languages\zh_cn.ini
- %WINDIR%\syswow64\languages\zh_hk.ini
- %WINDIR%\syswow64\languages\zh_tw.ini
- %WINDIR%\syswow64\360zip\360zipw.dll
- %WINDIR%\syswow64\cmdline\en_us.txt
- %WINDIR%\syswow64\qt\labs\folderlistmodel\plugins.qmltypes
- %WINDIR%\syswow64\qt\labs\platform\plugins.qmltypes
- %WINDIR%\syswow64\qt\labs\platform\qmldir
- %WINDIR%\syswow64\qt\labs\platform\qtlabsplatformplugin.dll
- %WINDIR%\syswow64\qt\labs\settings\plugins.qmltypes
- %WINDIR%\syswow64\qt\labs\settings\qmldir
- %WINDIR%\syswow64\qt\labs\settings\qmlsettingsplugin.dll
- %WINDIR%\syswow64\uninsfile\istask.dll
- %WINDIR%\syswow64\qt\labs\folderlistmodel\qmldir
- %WINDIR%\syswow64\qt\labs\folderlistmodel\qmlfolderlistmodelplugin.dll
- %WINDIR%\syswow64\360zip\360zipver.dll
- %WINDIR%\syswow64\360zip\360zip.ini
- %WINDIR%\syswow64\zipnew.dat
- %WINDIR%\syswow64\channels.config
- %WINDIR%\syswow64\cjson.dll
- %WINDIR%\syswow64\crashreport.dll
- %WINDIR%\syswow64\dgpver.dat
- %WINDIR%\syswow64\huaweisecurec.dll
- %WINDIR%\syswow64\id_error.png
- %WINDIR%\syswow64\id_load.gif
- %WINDIR%\syswow64\id_ok.png
- %WINDIR%\syswow64\app_retry.png
- %WINDIR%\syswow64\knewuplive.ini
- %WINDIR%\syswow64\kpdfconverter1611.kid
- %WINDIR%\syswow64\libegl.dll
- %WINDIR%\syswow64\nodrv.png
- %WINDIR%\syswow64\officetemplate.kid
- %WINDIR%\syswow64\otherfile_icon.png
- %WINDIR%\syswow64\rarnew.dat
- %WINDIR%\syswow64\uplive.svr
- %WINDIR%\syswow64\uvcon.cfg
- %WINDIR%\syswow64\kpdfconverter.kid
- %WINDIR%\syswow64\config\zconfig.xml
- %WINDIR%\syswow64\config\systemprofile\appdata\locallow\microsoft\cryptneturlcache\content\c86bd7751d53f10f65aaad66bbdf33c7
- %TEMP%\nsba2e5.tmp\nsexec.dll
- %TEMP%\nsba2e5.tmp\nsprocess.dll
- %TEMP%\nsba2e5.tmp\system.dll
- %WINDIR%\syswow64\ocular\agenttask\agenttasklist.dat
- '20#.#38.197.191':8237
- '20#.#38.197.191':8237
- '%CommonProgramFiles(x86)%\system\systecv3.exe' SW_HIDE
- '%CommonProgramFiles(x86)%\system\winrdgv3.exe'
- '%CommonProgramFiles(x86)%\system\winrdgv3.exe' SW_HIDE
- '%WINDIR%\syswow64\winrdlv3.exe' SW_HIDE
- '%WINDIR%\syswow64\winrdlv3.exe' winwdgv3.dll,RunMonitor32
- '%WINDIR%\syswow64\winrdlv3.exe' winoav3.dll,RunAgent32
- '%WINDIR%\syswow64\cmd.exe' /c netsh advfirewall firewall add rule name="winrdlv3" dir=in action=allow program="<SYSTEM32>\winrdlv3.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c netsh advfirewall firewall add rule name="winrdlv3" dir=out action=allow program="<SYSTEM32>\winrdlv3.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c netsh advfirewall firewall add rule name="winrdlv3" dir=in action=allow program="<SYSTEM32>\winrdlv3.exe"
- '%WINDIR%\syswow64\cmd.exe' /c netsh advfirewall firewall add rule name="winrdlv3" dir=out action=allow program="<SYSTEM32>\winrdlv3.exe"
- '<SYSTEM32>\regsvr32.exe' /s trmenushl64.dll