Technical Information
- %TEMP%\ldw1.tmp
- %TEMP%\ldterm\Ldx.ico
- %TEMP%\ldterm\Ldxc.exe
- %TEMP%\ldterm\LdxCab.ini
- %TEMP%\ldterm\LdxcManager.exe
- %TEMP%\ldterm\ldxghcore32.sys
- %TEMP%\ldterm\ldxghcore64.sys
- %TEMP%\ldterm\ldxghijt32.dll
- %TEMP%\ldterm\ldxghijt64.dll
- %TEMP%\ldterm\LdxGuard.exe
- %TEMP%\ldterm\LdTermPlug.exe
- %TEMP%\ldterm\LdxHook32.dll
- %TEMP%\ldterm\LdxManager.exe
- %TEMP%\ldterm\LdxShareData32.dll
- %TEMP%\ldterm\LdxShareData64.dll
- %TEMP%\ldterm\LdxSysCtrl.dll
- %TEMP%\ldterm\libeay32.dll
- %TEMP%\ldterm\Local.ini
- %TEMP%\ldterm\NdisSetup32.exe
- %TEMP%\ldterm\NdisSetup64.exe
- %TEMP%\ldterm\OsfDbCfg.ini
- %TEMP%\ldterm\Ldx.EN
- %TEMP%\ldterm\Ldx.exe
- %TEMP%\ldterm\Ldx.CHT
- %TEMP%\ldterm\LdWsCfg.ini
- %TEMP%\ldterm\LdWaterMarkHook64.dll
- %TEMP%\ldterm\LdSysCtrl.dll
- %TEMP%\ldterm\LdSysPlug.dll
- %TEMP%\ldterm\LdTDI_32.sys
- %TEMP%\ldterm\LdTDI_64.sys
- %TEMP%\ldterm\LdTerm.exe
- %TEMP%\ldterm\LdTerm2.22.exe
- %TEMP%\ldterm\LdtermDaemon.dll
- %TEMP%\ldterm\LdTermDaemon.exe
- %TEMP%\ldterm\LdTermDaemon.ini
- %TEMP%\ldterm\productinfo.ini
- %TEMP%\ldterm\LdxHook64.dll
- %TEMP%\ldterm\LdTermNew.exe
- %TEMP%\ldterm\ldthunk_32.dll
- %TEMP%\ldterm\ldthunk_64.dll
- %TEMP%\ldterm\LdvPrintDriver.cat
- %TEMP%\ldterm\LdVPrintDriver.gpd
- %TEMP%\ldterm\LdVPrintDriver.inf
- %TEMP%\ldterm\LdVPrintDriver.ini
- %TEMP%\ldterm\LdVPrintDriver32.dll
- %TEMP%\ldterm\LdVPrintDriver64.dll
- %TEMP%\ldterm\LdWaterMarkHook32.dll
- %TEMP%\ldterm\LdSSDTHook64.dll
- %TEMP%\ldterm\LdTermPlug64.exe
- %TEMP%\ldterm\QQFileMonitor.dll
- %TEMP%\ldterm\RCMicroDogSetup.dll
- %TEMP%\ldterm\screenhooks32.dll
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_.DEFAULT
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SECURITY
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SOFTWARE
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SYSTEM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SAM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\ComDb.Dat
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\$WinMgmt.CFG
- %TEMP%\ldterm\LdSSDTHook32.dll
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.BTR
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING.VER
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING1.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING2.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.DATA
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.MAP
- %WINDIR%\inf\oem3.inf
- %WINDIR%\inf\oem3.PNF
- <SYSTEM32>\spool\drivers\w32x86\30363040\SET5.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19
- %TEMP%\ldterm\TrLog.dll
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19
- %TEMP%\ldterm\TrDb.ini
- %TEMP%\ldterm\Setup.exe
- %TEMP%\ldterm\Sounds.RES
- %TEMP%\ldterm\SQLiteDB.dll
- %TEMP%\ldterm\ssleay32.dll
- %TEMP%\ldterm\TaskManageModule.dll
- %TEMP%\ldterm\TaskMgr.dll
- %TEMP%\ldterm\TestConnectionDLL.dll
- %TEMP%\ldterm\ThreadGet.dll
- %TEMP%\ldterm\TpNGBusiness.dll
- %TEMP%\ldterm\trace.ini
- <SYSTEM32>\spool\drivers\w32x86\30363040\SET6.tmp
- <SYSTEM32>\spool\drivers\w32x86\3\LdVPrintDriver.ini
- %TEMP%\ldterm\TrNetShare.dll
- %TEMP%\ldterm\WdmAdo.dll
- %TEMP%\ldterm\FileCheckSum.ini
- %TEMP%\ldterm\log\LdSetup.log
- C:\InetPub\ftproot\Tipray\LdTerm\ArComm.ini
- C:\InetPub\ftproot\Tipray\LdTerm\ArWorkstation.ini
- %TEMP%\ldterm\LdVPrintDriver.dll
- <SYSTEM32>\spool\drivers\w32x86\3\LdVPrintDriver.dll
- <SYSTEM32>\spool\drivers\w32x86\3\LdVPrintDriver.gpd
- <SYSTEM32>\spool\drivers\w32x86\3\LdVPrintDriver.inf
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\domain.txt
- %TEMP%\ldterm\LdShareData32.dll
- %TEMP%\ldterm\ldndis64.sys
- %TEMP%\ldterm\detoured.dll
- %TEMP%\ldterm\DeviceControl.dll
- %TEMP%\ldterm\DriverPlugin.dll
- %TEMP%\ldterm\FileVersion.ini
- %TEMP%\ldterm\Forbit.ini
- %TEMP%\ldterm\FtpUtil.dll
- %TEMP%\ldterm\ghhlp32.dll
- %TEMP%\ldterm\ghhlp64.dll
- %TEMP%\ldterm\ghijt32.dll
- %TEMP%\ldterm\ArsDbClient.dll
- %TEMP%\ldterm\ghijt64.dll
- %TEMP%\ldterm\InstallArVPrinter.exe
- %TEMP%\ldterm\key.db
- %TEMP%\ldterm\LdApproval.exe
- %TEMP%\ldterm\LdBurnCD.dll
- %TEMP%\ldterm\LdCab.exe
- %TEMP%\ldterm\LdCab.ini
- %TEMP%\ldterm\LdCab1.exe
- %TEMP%\ldterm\LdCdBurn.exe
- %TEMP%\ldterm\LdCdRomFilters_32.sys
- %TEMP%\ldterm\ChatPlugIn.dll
- %TEMP%\ldterm\config.ini
- %TEMP%\ldterm\ChangeDevState.exe
- %TEMP%\ldterm\CapScreen.dll
- %TEMP%\ldterm\CapNsg.dll
- %TEMP%\ldterm\7z.dll
- %TEMP%\ldterm\7z.exe
- %TEMP%\ldterm\ArComm.dll
- %TEMP%\ldterm\ArComm.ini
- %TEMP%\ldterm\ArFileDaemon.dll
- %TEMP%\ldterm\ArLib.dll
- %TEMP%\ldterm\ArLog.dll
- %TEMP%\ldterm\ArNet.dll
- %TEMP%\ldterm\ArRemoteControl.dll
- %TEMP%\ldterm\LdCdRomFilters_64.sys
- %TEMP%\ldterm\HttpMonitor.dll
- %TEMP%\ldterm\ArsDb.dll
- %TEMP%\ldterm\ArTime.dat
- %TEMP%\ldterm\ArUpdate.ini
- %TEMP%\ldterm\ArVersion.ini
- %TEMP%\ldterm\ArwCapture.dll
- %TEMP%\ldterm\ArWorkstation.ini
- %TEMP%\ldterm\ArWs.dat
- %TEMP%\ldterm\ArWs.dll
- %TEMP%\ldterm\ArWsPlug.dll
- %TEMP%\ldterm\borlndmm.dll
- %TEMP%\ldw2.tmp
- %TEMP%\ldterm\ArsFile.dll
- %TEMP%\ldterm\LdCmperDec.exe
- %TEMP%\ldterm\LdCmperProxy.exe
- %TEMP%\ldterm\LdCmperScan.exe
- %TEMP%\ldterm\LdMail.exe
- %TEMP%\ldterm\LdMenuExt_32.dll
- %TEMP%\ldterm\LdMenuExt_64.dll
- %TEMP%\ldterm\LdMenuPlug_32.dll
- %TEMP%\ldterm\LdMenuPlug_64.dll
- %TEMP%\ldterm\LdMoveFile.exe
- %TEMP%\ldterm\ldndis.cat
- %TEMP%\ldterm\ldndis.inf
- %TEMP%\ldterm\ldndis_m.inf
- %TEMP%\ldterm\ldndis32.sys
- %TEMP%\ldterm\ldnetmon32.sys
- %TEMP%\ldterm\LdSetup.exe
- %TEMP%\ldterm\ldnetmon64.sys
- %TEMP%\ldterm\LdNetMonitor.dll
- %TEMP%\ldterm\LdOutSend.exe
- %TEMP%\ldterm\LdOutSend1.exe
- %TEMP%\ldterm\LdPrintMonitor.dll
- %TEMP%\ldterm\LdPrintMonitor64.dll
- %TEMP%\ldterm\LdReader.exe
- %TEMP%\ldterm\LdReject64.exe
- %TEMP%\ldterm\LdRemote.exe
- %TEMP%\ldterm\LdRemoteService.exe
- %TEMP%\ldterm\LdKeyBoardFilter64.sys
- %TEMP%\ldterm\LdExplorerIcon_32.dll
- %TEMP%\ldterm\LdKeyBoardFilter32.sys
- %TEMP%\ldterm\LdEIS_XP.sys
- %TEMP%\ldterm\LdComm_32.dll
- %TEMP%\ldterm\LdComm_64.dll
- %TEMP%\ldterm\ldcore32.sys
- %TEMP%\ldterm\Ldcore64.sys
- %TEMP%\ldterm\LdDisk32.sys
- %TEMP%\ldterm\LdDisk64.sys
- %TEMP%\ldterm\LdDlgMon.exe
- %TEMP%\ldterm\LdDriverPlugin.dll
- %TEMP%\ldterm\LdEIS_2K.sys
- %TEMP%\ldterm\LdEIS_64.sys
- %TEMP%\ldterm\LdScreen.exe
- %TEMP%\ldterm\LdKbCtrl.dll
- %TEMP%\ldterm\LdExplorerIcon_64.dll
- %TEMP%\ldterm\LdFileClient.exe
- %TEMP%\ldterm\LdFileEngineClient.dll
- %TEMP%\ldterm\LdFileGate.exe
- %TEMP%\ldterm\LdFileGate.ini
- %TEMP%\ldterm\LdHook32.dll
- %TEMP%\ldterm\LdHook64.dll
- %TEMP%\ldterm\LdIcon.dll
- %TEMP%\ldterm\ldinject_32.dll
- %TEMP%\ldterm\ldinject_64.dll
- %TEMP%\ldterm\LdKeRestore.sys
- <SYSTEM32>\spool\drivers\w32x86\30363040\SET7.tmp
- from <SYSTEM32>\spool\drivers\w32x86\30363040\SET5.tmp to <SYSTEM32>\spool\drivers\w32x86\30363040\UNIDRV.DLL
- from <SYSTEM32>\spool\drivers\w32x86\30363040\SET6.tmp to <SYSTEM32>\spool\drivers\w32x86\30363040\UNIRES.DLL
- ClassName: 'DirectUIHWND' WindowName: ''
- '%TEMP%\ldterm\Setup.exe' -ip 121.28.169.2 -port 20086
- '%TEMP%\ldterm\InstallArVPrinter.exe' -Install