マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.Siggen29.48059

Added to the Dr.Web virus database: 2024-10-08

Virus description added:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Shell' = '%ProgramFiles(x86)%\NISEC\NISEC_Tool.exe'
Sets the following service settings
  • [HKLM\System\CurrentControlSet\Services\WTKeySrv_Name] 'Start' = '00000002'
  • [HKLM\System\CurrentControlSet\Services\WTKeySrv_Name] 'ImagePath' = '%ProgramFiles(x86)%\NISEC\NISEC_Srv.exe'
Creates the following services
  • 'WTKeySrv_Name' %ProgramFiles(x86)%\NISEC\NISEC_Srv.exe
Modifies file system
Creates the following files
  • %TEMP%\glc58c9.tmp
  • %ProgramFiles(x86)%\nisec\hyperlink.ico
  • %ProgramFiles(x86)%\nisec\utility.dll
  • %ProgramFiles(x86)%\nisec\nisec_ui.dll
  • %ProgramFiles(x86)%\nisec\nisec_ukupdate.dll
  • %ProgramFiles(x86)%\nisec\nisec_safehelper.dll
  • %ProgramFiles(x86)%\nisec\nisec_pkcsimpl.dll
  • %ProgramFiles(x86)%\nisec\nisec_pkcsshell.dll
  • %ProgramFiles(x86)%\nisec\nisec_cspimpl32.dll
  • %ProgramFiles(x86)%\nisec\nisec_cspshell32.dll
  • %TEMP%\nsec7d2.tmp\userinfo.dll
  • %TEMP%\nsec7d2.tmp\system.dll
  • %TEMP%\nszc7b2.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh004f.tmp
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-3691498038-2086406363-2140527554-1000\cbaa2bce874b853762420fd11962e15f_0cb67e2f-dc95-45ca-8fb8-69bde8e3f814
  • %ProgramFiles(x86)%\nisec\uninstall.ico
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\printsupport\~glh004c.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\~glh004b.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\~glh004a.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\~glh0049.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\~glh0048.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\~glh0047.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\imageformats\~glh0046.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\platforms\~glh0045.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\languages\~glh0044.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\crypt\~glh0043.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\~glh0042.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\~glh0041.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\~glh0040.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh004e.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\config\~glh001d.tmp
  • %TEMP%\wrpd4ce.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0059.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0058.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0057.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0056.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0055.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0054.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0053.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0052.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0051.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0050.tmp
  • %ProgramFiles(x86)%\nisec\uninst.exe
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\nisec user tool\uninstall.lnk
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\nisec user tool\management tool.lnk
  • C:\users\public\desktop\nisecó㻧¹üàí¹¤¾ß.lnk
  • %ProgramFiles%\nisec\nisec_reg.exe
  • %ProgramFiles(x86)%\nisec\nisec_reg.exe
  • %ProgramFiles(x86)%\nisec\nisec_srv.exe
  • %ProgramFiles(x86)%\nisec\version.ini
  • %ProgramFiles(x86)%\nisec\nisec_tool.exe
  • <SYSTEM32>\ctplkcs.dll
  • %ProgramFiles%\nisec\utility.dll
  • %ProgramFiles%\nisec\nisec_ui.dll
  • %ProgramFiles%\nisec\nisec_safehelper.dll
  • %ProgramFiles%\nisec\nisec_pkcsimpl.dll
  • %ProgramFiles%\nisec\nisec_pkcsshell.dll
  • %ProgramFiles%\nisec\nisec_cspimpl64.dll
  • %ProgramFiles%\nisec\nisec_cspshell64.dll
  • %WINDIR%\syswow64\ctplkcs.dll
  • %TEMP%\wrpd4ef.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\~glh003f.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\printsupport\~glh004d.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\~glh003e.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\~glh003d.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\third\~glh003c.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh000c.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\~glh0019.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\third\~glh0018.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\third\~glh0017.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\config\~glh0016.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\config\~glh0015.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\config\~glh0014.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\configmanager\~glh0013.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\buriedpoint\~glh0012.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\buriedpoint\config\~glh0011.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh0010.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh000f.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh000e.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh000d.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh000b.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\logger\~glh001b.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh000a.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh0009.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh0008.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh0007.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\~glh0006.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\~glh0005.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\~glh0004.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\~glh0003.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\~glh0002.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0001.tmp
  • %TEMP%\~glh0000.tmp
  • %TEMP%\glg64be.tmp
  • %TEMP%\glj5918.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh005a.tmp
  • %TEMP%\wrpd4df.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\config\~glh001c.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh001f.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\logger\~glh001a.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\third\~glh003b.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\third\~glh003a.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\third\~glh0039.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\~glh0038.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\third\~glh0037.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\third\~glh0036.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\third\~glh0035.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\third\~glh0034.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\third\~glh0033.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\smartcoding\~glh0032.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\smartcoding\third\~glh0031.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\smartcoding\third\~glh0030.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\smartcoding\config\~glh002f.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\networkchannel\config\~glh002e.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\networkchannel\~glh002d.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\~glh002c.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh002b.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh002a.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0029.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0028.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0027.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0026.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0025.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0024.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0023.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0022.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0021.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0020.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh001e.tmp
  • %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh005b.tmp
Deletes the following files
  • %TEMP%\nsec7d2.tmp\system.dll
  • %TEMP%\nsec7d2.tmp\userinfo.dll
Moves the following files
  • from %TEMP%\~glh0000.tmp to %TEMP%\glf64fd.tmp
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\crypt\~glh0043.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\crypt\cryp_api.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\~glh0042.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\tczxsj.exe
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\~glh0041.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\tcwebctrl01.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\~glh0040.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\ssleay32.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\~glh003f.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\msvcr120.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\~glh003e.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\libeay32.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\~glh003d.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\tczxsj\libcurl.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\third\~glh003c.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\third\sqlite3.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\third\~glh003b.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\third\newtonsoft.json.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\third\~glh003a.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\third\getskppath.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\third\~glh0039.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\third\bwkpqtver.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\~glh0038.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\bc.sqllite.plugin.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\third\~glh0037.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\third\system.data.sqlite.xml
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\third\~glh0036.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\third\system.data.sqlite.linq.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\third\~glh0035.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\third\system.data.sqlite.ef6.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\third\~glh0034.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\third\system.data.sqlite.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\third\~glh0033.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\sqllite\third\sqlite.interop.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\smartcoding\~glh0032.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\smartcoding\bc.smartcoding.plugin.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\smartcoding\third\~glh0031.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\smartcoding\third\wxencrypt.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\smartcoding\config\~glh002f.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\smartcoding\config\smartcodingconfig.json
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\smartcoding\third\~glh0030.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\smartcoding\third\aliyun.oss.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\languages\~glh0044.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\languages\print_zh_cn.qm
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\platforms\~glh0045.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\platforms\qwindows.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0059.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\skao.exe
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0058.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\remotelogout.exe
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0057.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\qt_zh_cn.qm
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0056.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\cssssssign.cer
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0055.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\01.png
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0054.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\01.ico
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0053.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\.lic
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0052.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\wtdz_kp.chm
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0051.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kp.chm
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh004f.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\nisecinstaller_v1.0.8.7.3.exe
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0021.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\sqlite3.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh004e.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\nisecinstaller.exe
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\printsupport\~glh004d.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\printsupport\windowsprintersupportd.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\printsupport\~glh004c.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\printsupport\windowsprintersupport.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\~glh004b.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\receipttool.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\~glh004a.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\ofdsign.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\~glh0049.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\ofddom.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\~glh0048.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\oesplugin.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\~glh0047.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\imageconvertor.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\imageformats\~glh0046.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\plugins\imageformats\qsvg.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\networkchannel\config\~glh002e.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\networkchannel\config\httpconfig.json
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\networkchannel\~glh002d.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\networkchannel\bc.networkchannel.plugin.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\~glh002c.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\bc.madeinvoice.plugin.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\buriedpoint\~glh0012.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\buriedpoint\bc.buriedpoint.plugin.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\buriedpoint\config\~glh0011.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\buriedpoint\config\appidconfig.json
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh0010.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\7z.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh000f.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\7z.exe
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh000e.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\bc.basic.util.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh000d.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\bc.plugin.core.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh000c.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\bc.plugin.entity.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh000b.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\bcupgrade.exe
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh000a.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\bwkp.exe
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh0009.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\bwkp.exe.config
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh0008.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\config.ini
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\~glh0007.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\log4net.config
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\~glh0006.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\appconfigpath.bwconf
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\~glh0005.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\bwkp.exe
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\~glh0004.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\dotnetfx40.zip
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\~glh0003.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\inisys.ini
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\~glh0002.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\launcher.ini
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0001.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\unwise.exe
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\config\~glh0014.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\config\clientlogconfig.json
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\config\~glh0015.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\config\initconfig.json
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\configmanager\~glh0013.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\configmanager\bc.configmanager.plugin.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\config\~glh0016.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\config\sysconfig.json
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh002b.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\adb.exe
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\third\~glh0017.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\third\aliyun.oss.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh002a.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\adbwinapi.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0029.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\adbwinusbapi.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0028.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\bwtemp.dat
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0027.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\ewm_gzh.jpg
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0026.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\ininotice.ini
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0025.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\kjkp.chm
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0024.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\notice.exe
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0023.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\poseidon.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh0050.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\jyp_kp.chm
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh005a.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\newskkp.exe
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0020.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\wxencrypt.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh001f.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\wxgenerator.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh001e.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\wxtransfer.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\config\~glh001d.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\config\madeinvoiceconfig.json
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\config\~glh001c.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\config\dataextraction.json
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\logger\~glh001b.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\logger\log4net.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\logger\~glh001a.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\logger\bc.logger.plugin.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\~glh0019.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\bc.init.plugin.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\third\~glh0018.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\init\third\icsharpcode.sharpziplib.dll
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\~glh0022.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\kjkp\1.2.0.0\addins\madeinvoice\third\sqkp_ewm.bmp
  • from %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\~glh005b.tmp to %ProgramFiles(x86)%\ôööµë°·¢æ±ë°¿ø¿ªæ±èí¼þ(ë°¿øåì°æ)\skrj.exe
Miscellaneous
Creates and executes the following
  • '%ProgramFiles(x86)%\nisec\nisec_srv.exe' -i
  • '%ProgramFiles(x86)%\nisec\nisec_reg.exe' -install
  • '%ProgramFiles(x86)%\nisec\nisec_reg.exe' -startSrv
  • '%ProgramFiles%\nisec\nisec_reg.exe' -pminstall
  • '%ProgramFiles(x86)%\nisec\nisec_srv.exe'
Executes the following
  • '%WINDIR%\syswow64\regsvr32.exe' /s /i NISEC_CSPShell32.dll
  • '<SYSTEM32>\regsvr32.exe' /s /i NISEC_CSPShell64.dll
  • '%WINDIR%\syswow64\net.exe' start WTKeySrv_Name
  • '%WINDIR%\syswow64\net1.exe' start WTKeySrv_Name
  • '%WINDIR%\syswow64\net.exe' start WTKeySrv_Name' (with hidden window)

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android