Technical Information
- '%TEMP%\nsr3.tmp\nsF.tmp' taskkill /f /im Safari.exe
- '%TEMP%\nsr3.tmp\ns10.tmp' taskkill /f /im TaoBrowser.exe
- '%TEMP%\nsr3.tmp\nsD.tmp' taskkill /f /im 360se.exe
- '%TEMP%\nsr3.tmp\nsE.tmp' taskkill /f /im baidubrowser.exe
- '%TEMP%\nsr3.tmp\ns11.tmp' taskkill /f /im twchrome.exe
- '%TEMP%\nsr3.tmp\ns14.tmp' cmd /c for /f %i in ('reg query hku^|findstr "500$"') do @echo type=%~nxi>>"%APPDATA%\Browser.ini"
- '%TEMP%\nsr3.tmp\ns15.tmp' CMD /C echo [Num2]>"%APPDATA%\Browser.ini" &pushd "%AppData%\Mozilla\Firefox\Profiles\" &for /f "delims=" %a in ('dir/b/ad^|findstr /i "default$"') do @echo type2=%~fa>>"%APPDATA%\Browser.ini"
- '%TEMP%\nsr3.tmp\ns12.tmp' taskkill /f /im Maxthon.exe
- '%TEMP%\nsr3.tmp\ns13.tmp' cmd /c echo [Num1]>"%APPDATA%\Browser.ini"
- '%TEMP%\nsr3.tmp\ns6.tmp' taskkill /f /im QQBrowser.exe
- '%TEMP%\nsr3.tmp\ns7.tmp' taskkill /f /im 2345Explorer.exe
- '%TEMP%\nsr3.tmp\ns4.tmp' taskkill /f /im killexe.exe
- '%TEMP%\nsr3.tmp\ns5.tmp' taskkill /f /im liebao.exe
- '%TEMP%\nsr3.tmp\ns8.tmp' taskkill /f /im sogouexplorer.exe
- '%TEMP%\nsr3.tmp\nsB.tmp' taskkill /f /im TTraveler.exe
- '%TEMP%\nsr3.tmp\nsC.tmp' taskkill /f /im 360chrome.exe
- '%TEMP%\nsr3.tmp\ns9.tmp' taskkill /f /im firefox.exe
- '%TEMP%\nsr3.tmp\nsA.tmp' taskkill /f /im TheWorld.exe
- '<SYSTEM32>\taskkill.exe' /f /im Safari.exe
- '<SYSTEM32>\taskkill.exe' /f /im TaoBrowser.exe
- '<SYSTEM32>\taskkill.exe' /f /im 360se.exe
- '<SYSTEM32>\taskkill.exe' /f /im baidubrowser.exe
- '<SYSTEM32>\taskkill.exe' /f /im twchrome.exe
- '<SYSTEM32>\findstr.exe' "500$"
- '<SYSTEM32>\findstr.exe' /i "default$"
- '<SYSTEM32>\taskkill.exe' /f /im Maxthon.exe
- '<SYSTEM32>\reg.exe' query hku
- '<SYSTEM32>\taskkill.exe' /f /im QQBrowser.exe
- '<SYSTEM32>\taskkill.exe' /f /im 2345Explorer.exe
- '<SYSTEM32>\taskkill.exe' /f /im killexe.exe
- '<SYSTEM32>\taskkill.exe' /f /im liebao.exe
- '<SYSTEM32>\taskkill.exe' /f /im sogouexplorer.exe
- '<SYSTEM32>\taskkill.exe' /f /im TTraveler.exe
- '<SYSTEM32>\taskkill.exe' /f /im 360chrome.exe
- '<SYSTEM32>\taskkill.exe' /f /im firefox.exe
- '<SYSTEM32>\taskkill.exe' /f /im TheWorld.exe
- safari.exe
- firefox.exe
- %APPDATA%\SogouExplorer\config.xml
- %APPDATA%\Opera\Opera\operaprefs.ini
- %APPDATA%\Tencent\TencentTraveler\100\TtConf.dat
- %APPDATA%\Apple Computer\Preferences\com.apple.Safari.plist
- %APPDATA%\360se6\User Data\Default\Preferences
- %APPDATA%\Maxthon3\Users\guest\Config\config.dat
- %TEMP%\nsr3.tmp\ns14.tmp
- %APPDATA%\Tencent\QQBrowser\OnlineSetup\QMScan\QMScan.zip.qbl
- %APPDATA%\Tencent\QQBrowser\ClientUpdate\cli1D9.tmp.qbl
- %APPDATA%\Baidu\browser\UserData\0A73B7929C9546628F097CEEACA6E079410064006d0069006e006900730074007200610074006f007200\userpref_v2
- %HOMEPATH%\AppData\Roaming\TheWorld\TheWorld.ini
- <LS_APPDATA>\360Chrome\Chrome\User Data\Default\Preferences
- %APPDATA%\2345Explorer\Users\Default\Default.cfg
- %TEMP%\nsr3.tmp\ns15.tmp
- <LS_APPDATA>\TheWorld6\User Data\Default\Preferences
- <LS_APPDATA>\Google\Chrome\User Data\Default\Preferences
- <LS_APPDATA>\baidu\BaiduPlayer2\UserData\Default\Preferences
- <LS_APPDATA>\TheWorld\Chrome\User Data\Default\Preferences
- <LS_APPDATA>\TaoBrowser\User Data\Default\Preferences
- %TEMP%\nsr3.tmp\ns8.tmp
- %TEMP%\nsr3.tmp\ns7.tmp
- %TEMP%\nsr3.tmp\nsA.tmp
- %TEMP%\nsr3.tmp\ns9.tmp
- %TEMP%\nsr3.tmp\ns6.tmp
- %TEMP%\nsr3.tmp\NsExec.dll
- %TEMP%\nsm2.tmp
- %TEMP%\nsr3.tmp\ns5.tmp
- %TEMP%\nsr3.tmp\ns4.tmp
- %TEMP%\nsr3.tmp\nsB.tmp
- %TEMP%\nsr3.tmp\ns12.tmp
- %TEMP%\nsr3.tmp\ns11.tmp
- %APPDATA%\Browser.ini
- %TEMP%\nsr3.tmp\ns13.tmp
- %TEMP%\nsr3.tmp\ns10.tmp
- %TEMP%\nsr3.tmp\nsD.tmp
- %TEMP%\nsr3.tmp\nsC.tmp
- %TEMP%\nsr3.tmp\nsF.tmp
- %TEMP%\nsr3.tmp\nsE.tmp
- <LS_APPDATA>\Google\Chrome\User Data\Default\Preferences
- <LS_APPDATA>\baidu\BaiduPlayer2\UserData\Default\Preferences
- %APPDATA%\Baidu\browser\UserData\0A73B7929C9546628F097CEEACA6E079410064006d0069006e006900730074007200610074006f007200\userpref_v2
- <LS_APPDATA>\TheWorld\Chrome\User Data\Default\Preferences
- %APPDATA%\2345Explorer\Users\Default\Default.cfg
- <LS_APPDATA>\360Chrome\Chrome\User Data\Default\Preferences
- <LS_APPDATA>\TheWorld6\User Data\Default\Preferences
- %APPDATA%\Tencent\TencentTraveler\100\TtConf.dat
- %APPDATA%\Tencent\QQBrowser\OnlineSetup\QMScan\QMScan.zip.qbl
- %APPDATA%\Tencent\QQBrowser\ClientUpdate\cli1D9.tmp.qbl
- %APPDATA%\Maxthon3\Users\guest\Config\config.dat
- %APPDATA%\360se6\User Data\Default\Preferences
- %APPDATA%\Apple Computer\Preferences\com.apple.Safari.plist
- %APPDATA%\SogouExplorer\config.xml
- %APPDATA%\Opera\Opera\operaprefs.ini
- %TEMP%\nsr3.tmp\ns10.tmp
- %TEMP%\nsr3.tmp\ns11.tmp
- %TEMP%\nsr3.tmp\nsE.tmp
- %TEMP%\nsr3.tmp\nsF.tmp
- %TEMP%\nsr3.tmp\ns12.tmp
- %TEMP%\nsr3.tmp\ns15.tmp
- %TEMP%\nsr3.tmp\NsExec.dll
- %TEMP%\nsr3.tmp\ns13.tmp
- %TEMP%\nsr3.tmp\ns14.tmp
- %TEMP%\nsr3.tmp\nsD.tmp
- %TEMP%\nsr3.tmp\ns6.tmp
- %TEMP%\nsr3.tmp\ns7.tmp
- %TEMP%\nsr3.tmp\ns4.tmp
- %TEMP%\nsr3.tmp\ns5.tmp
- %TEMP%\nsr3.tmp\ns8.tmp
- %TEMP%\nsr3.tmp\nsB.tmp
- %TEMP%\nsr3.tmp\nsC.tmp
- %TEMP%\nsr3.tmp\ns9.tmp
- %TEMP%\nsr3.tmp\nsA.tmp
- ClassName: '(null)' WindowName: '(null)'