Technical Information
- [<HKLM>\System\CurrentControlSet\Services\VOneMgrSvc] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\VOneMgrSvc] 'ImagePath' = '%ProgramFiles(x86)%\VONE\TopSecSV\VOneMgrSvc.exe'
- [<HKLM>\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- 'VOneMgrSvc' %ProgramFiles(x86)%\VONE\TopSecSV\VOneMgrSvc.exe
- %TEMP%\nsm6d73.tmp
- %ProgramFiles(x86)%\vone\topsecsv\svclientnasetup.exe
- %TEMP%\nsm6d74.tmp\ns88c4.tmp
- %TEMP%\nsm8cd5.tmp
- %TEMP%\nsm8cd6.tmp\system.dll
- %ProgramFiles(x86)%\vone\topsecsv\svclientnaversion.ini
- %TEMP%\nsm8cd6.tmp\nsexec.dll
- %TEMP%\nsm8cd6.tmp\ns8d15.tmp
- %TEMP%\nsm8cd6.tmp\killproc.dll
- %TEMP%\nsm8cd6.tmp\ns9254.tmp
- %WINDIR%\syswow64\instdrv64.exe
- %TEMP%\nsm8cd6.tmp\ns9744.tmp
- %WINDIR%\syswow64\vonemgrsvc.log
- %ProgramFiles(x86)%\vone\topsecsv\topvdev-x64.sys
- %ProgramFiles(x86)%\vone\topsecsv\topvdev-x64.cat
- %ProgramFiles(x86)%\vone\topsecsv\instdrv64.exe
- %WINDIR%\syswow64\checkversion.dll
- %WINDIR%\syswow64\topvdev-x64.sys
- %WINDIR%\syswow64\topvdev-x64.inf
- %WINDIR%\syswow64\topvdev-x64.cat
- %ProgramFiles(x86)%\vone\topsecsv\svvniccleaner.exe
- %TEMP%\nsm8cd6.tmp\nsb86c.tmp
- %TEMP%\nsm8cd6.tmp\nsc1ee.tmp
- %TEMP%\nsm8cd6.tmp\nsca1a.tmp
- %TEMP%\{11277e4d-52db-5d38-933c-9a5e9bddfb35}\set2cf9.tmp
- %ProgramFiles(x86)%\vone\topsecsv\language\¼òìåöðîä.ini
- %ProgramFiles(x86)%\vone\topsecsv\language\¼òìåöðîä.default
- %ProgramFiles(x86)%\vone\topsecsv\language\english.ini
- %ProgramFiles(x86)%\vone\topsecsv\hdsnflag.ini
- %ProgramFiles(x86)%\vone\topsecsv\updatesrv.ini
- %TEMP%\nsm6d74.tmp\nsscm.dll
- %TEMP%\nsm6d74.tmp\killproc.dll
- %ProgramFiles(x86)%\vone\topsecsv\svclientversion.ini
- %TEMP%\nsm6d74.tmp\simplesc.dll
- %ProgramFiles(x86)%\vone\topsecsv\vonemgrsvc.exe
- %ProgramFiles(x86)%\vone\topsecsv\sendnaquitmsg.exe
- %TEMP%\nsm6d74.tmp\nsexec.dll
- %TEMP%\nsm6d74.tmp\ns6f97.tmp
- %WINDIR%\syswow64\logdll.dll
- %WINDIR%\syswow64\sharemem.dll
- %WINDIR%\syswow64\batman.dll
- %TEMP%\{11277e4d-52db-5d38-933c-9a5e9bddfb35}\set2e51.tmp
- %ProgramFiles(x86)%\vone\topsecsv\topvdev-x64.inf
- %TEMP%\nsm6d74.tmp\ns7533.tmp
- %ProgramFiles(x86)%\vone\topsecsv\gdiplus.dll
- %ProgramFiles(x86)%\vone\topsecsv\sv_client.exe
- %ProgramFiles(x86)%\vone\topsecsv\resourcedll.dll
- %ProgramFiles(x86)%\vone\topsecsv\config.ini
- %ProgramFiles(x86)%\vone\topsecsv\cleanconfig.exe
- %ProgramFiles(x86)%\vone\topsecsv\keytype.ini
- %ProgramFiles(x86)%\vone\topsecsv\reporter.exe
- %ProgramFiles(x86)%\vone\topsecsv\repair.exe
- %ProgramFiles(x86)%\vone\topsecsv\resmgr.exe
- %ProgramFiles(x86)%\vone\topsecsv\secchecker.dll
- %ProgramFiles(x86)%\vone\topsecsv\tar.exe
- %TEMP%\nsm6d74.tmp\system.dll
- %TEMP%\nsm6d74.tmp\ns78bd.tmp
- %TEMP%\{11277e4d-52db-5d38-933c-9a5e9bddfb35}\set2fd8.tmp
- %TEMP%\nsm6d74.tmp\ns6f97.tmp
- %TEMP%\nsm6d74.tmp\ns7533.tmp
- %TEMP%\nsm6d74.tmp\ns78bd.tmp
- %TEMP%\nsm8cd6.tmp\ns8d15.tmp
- %TEMP%\nsm8cd6.tmp\ns9254.tmp
- %TEMP%\nsm8cd6.tmp\ns9744.tmp
- %TEMP%\nsm8cd6.tmp\nsb86c.tmp
- %TEMP%\nsm8cd6.tmp\nsc1ee.tmp
- from %WINDIR%\syswow64\instdrv64.exe to %WINDIR%\syswow64\instdrv.exe
- from %ProgramFiles(x86)%\vone\topsecsv\topvdev-x64.sys to %ProgramFiles(x86)%\vone\topsecsv\topvdev.sys
- from %ProgramFiles(x86)%\vone\topsecsv\topvdev-x64.inf to %ProgramFiles(x86)%\vone\topsecsv\topvdev.inf
- from %ProgramFiles(x86)%\vone\topsecsv\topvdev-x64.cat to %ProgramFiles(x86)%\vone\topsecsv\topvdev.cat
- from %ProgramFiles(x86)%\vone\topsecsv\instdrv64.exe to %ProgramFiles(x86)%\vone\topsecsv\instdrv.exe
- from %WINDIR%\syswow64\topvdev-x64.sys to %WINDIR%\syswow64\topvdev.sys
- from %WINDIR%\syswow64\topvdev-x64.inf to %WINDIR%\syswow64\topvdev.inf
- from %WINDIR%\syswow64\topvdev-x64.cat to %WINDIR%\syswow64\topvdev.cat
- from %TEMP%\{11277e4d-52db-5d38-933c-9a5e9bddfb35}\set2cf9.tmp to %TEMP%\{11277e4d-52db-5d38-933c-9a5e9bddfb35}\topvdev.cat
- from %TEMP%\{11277e4d-52db-5d38-933c-9a5e9bddfb35}\set2e51.tmp to %TEMP%\{11277e4d-52db-5d38-933c-9a5e9bddfb35}\topvdev.inf
- from %TEMP%\{11277e4d-52db-5d38-933c-9a5e9bddfb35}\set2fd8.tmp to %TEMP%\{11277e4d-52db-5d38-933c-9a5e9bddfb35}\topvdev.sys
- %WINDIR%\syswow64\instdrv64.exe
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK microsoft.com
- 'localhost':35972
- ClassName: '#32770' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- ClassName: '' WindowName: 'SSL VPN Client'
- '%TEMP%\nsm6d74.tmp\ns6f97.tmp' "%ProgramFiles(x86)%\VONE\TopSecSV\SendNAQuitMsg.exe" -closeAX
- '%TEMP%\nsm8cd6.tmp\ns8d15.tmp' "%ProgramFiles(x86)%\VONE\TopSecSV\SendNAQuitMsg.exe" -closeAX
- '%TEMP%\nsm8cd6.tmp\nsca1a.tmp' %WINDIR%\sysWOW64\instdrv.exe install %WINDIR%\sysWOW64\Topvdev.inf *TOPSEC_VNIC
- '%ProgramFiles(x86)%\vone\topsecsv\svvniccleaner.exe' -clean006vnic
- '%TEMP%\nsm8cd6.tmp\nsc1ee.tmp' "%ProgramFiles(x86)%\VONE\TopSecSV\SVVnicCleaner.exe" -clean006vnic
- '%ProgramFiles(x86)%\vone\topsecsv\svvniccleaner.exe' -clean005vnic
- '%TEMP%\nsm8cd6.tmp\nsb86c.tmp' "%ProgramFiles(x86)%\VONE\TopSecSV\SVVnicCleaner.exe" -clean005vnic
- '%WINDIR%\syswow64\instdrv.exe' remove *TOPSEC_VNIC
- '%TEMP%\nsm8cd6.tmp\ns9744.tmp' "%WINDIR%\sysWOW64\instdrv.exe" remove *TOPSEC_VNIC
- '%ProgramFiles(x86)%\vone\topsecsv\vonemgrsvc.exe' -i
- '%WINDIR%\syswow64\instdrv.exe' -hwids *TOPSEC_VNIC
- '%TEMP%\nsm8cd6.tmp\ns9254.tmp' "%WINDIR%\sysWOW64\instdrv.exe" remove *TOPSEC_VNIC
- '%TEMP%\nsm6d74.tmp\ns88c4.tmp' "%ProgramFiles(x86)%\VONE\TopSecSV\SVClientNASetup.exe"
- '%ProgramFiles(x86)%\vone\topsecsv\sendnaquitmsg.exe' -closeAX
- '%TEMP%\nsm6d74.tmp\ns7533.tmp' "%ProgramFiles(x86)%\VONE\TopSecSV\VOneMgrSvc.exe" -i
- '%ProgramFiles(x86)%\vone\topsecsv\vonemgrsvc.exe' -r VOneMgrSvc
- '%TEMP%\nsm6d74.tmp\ns78bd.tmp' "%ProgramFiles(x86)%\VONE\TopSecSV\VOneMgrSvc.exe" -r VOneMgrSvc
- '%ProgramFiles(x86)%\vone\topsecsv\vonemgrsvc.exe'
- '%WINDIR%\syswow64\instdrv.exe' install %WINDIR%\sysWOW64\Topvdev.inf *TOPSEC_VNIC
- '%ProgramFiles(x86)%\vone\topsecsv\svclientnasetup.exe'
- '%TEMP%\nsm6d74.tmp\ns6f97.tmp' "%ProgramFiles(x86)%\VONE\TopSecSV\SendNAQuitMsg.exe" -closeAX' (with hidden window)
- '%TEMP%\nsm8cd6.tmp\ns9254.tmp' "%WINDIR%\sysWOW64\instdrv.exe" remove *TOPSEC_VNIC' (with hidden window)
- '%TEMP%\nsm6d74.tmp\ns78bd.tmp' "%ProgramFiles(x86)%\VONE\TopSecSV\VOneMgrSvc.exe" -r VOneMgrSvc' (with hidden window)
- '%TEMP%\nsm6d74.tmp\ns88c4.tmp' "%ProgramFiles(x86)%\VONE\TopSecSV\SVClientNASetup.exe"' (with hidden window)
- '%TEMP%\nsm8cd6.tmp\ns9744.tmp' "%WINDIR%\sysWOW64\instdrv.exe" remove *TOPSEC_VNIC' (with hidden window)
- '%TEMP%\nsm8cd6.tmp\ns8d15.tmp' "%ProgramFiles(x86)%\VONE\TopSecSV\SendNAQuitMsg.exe" -closeAX' (with hidden window)
- '%TEMP%\nsm6d74.tmp\ns7533.tmp' "%ProgramFiles(x86)%\VONE\TopSecSV\VOneMgrSvc.exe" -i' (with hidden window)
- '%WINDIR%\syswow64\instdrv.exe' -hwids *TOPSEC_VNIC' (with hidden window)
- '%TEMP%\nsm8cd6.tmp\nsc1ee.tmp' "%ProgramFiles(x86)%\VONE\TopSecSV\SVVnicCleaner.exe" -clean006vnic' (with hidden window)
- '%TEMP%\nsm8cd6.tmp\nsb86c.tmp' "%ProgramFiles(x86)%\VONE\TopSecSV\SVVnicCleaner.exe" -clean005vnic' (with hidden window)
- '%TEMP%\nsm8cd6.tmp\nsca1a.tmp' %WINDIR%\sysWOW64\instdrv.exe install %WINDIR%\sysWOW64\Topvdev.inf *TOPSEC_VNIC' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' advfirewall set global statefulpptp disable' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' advfirewall set global statefulpptp disable
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{19354408-a580-6099-947c-df15c160851a} Global\{2fe89995-c949-0ad3-1259-770bed9d4a22} <DRIVERSTORE>\Temp\{2a0aa313-9af3-39ee-51d5-b27a...