Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Win32.HLLW.Autoruner.57227

Добавлен в вирусную базу Dr.Web: 2011-08-28

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения:
Модифицирует следующие ключи реестра:
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\filedel.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\At1.job] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\blastclnnn.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\eraleuh.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\filesrv32.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Network-IPv6.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ckvo.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KGH Killer.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Top Pictures.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SxingDel.bat] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\macromedia.10.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aquarium 200.scr] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\astry.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runouce.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\new folder.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\isass.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\flash.10.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ckvo0.dll] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel templates.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\admin files.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WinRaR 3.70.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hinhem.scr] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PowerPoint temlates.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mp3 files.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Main.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AutoProtection.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Apphelp.dll] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashQuick.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashSimpl.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmScan.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Music.exe] 'Debugger' = ''
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Virus.exe] 'Debugger' = ''
  • [<HKLM>\SOFTWARE\Classes\inffile\shell\open\command] '' = 'RunDll32.exe powrprof.dll,SetSuspendState'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrnAmon.dll] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shellExt.dll] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smss.exe] 'Debugger' = ''
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashCmd.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SexGameList] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SexScreenSaver.scr] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McENUI.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskkill.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\b3b9u.com] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SexGame.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\APVXDWIN.EXE] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Inicio.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SiteAdv.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcagent.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgas.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Antivirus 2009.lnk] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegMech.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshield.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SHSTAT.EXE] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UdaterUI.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kazme__gheyz.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoply.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMon.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32krn.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32kui.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ProcessManager.exe] 'Debugger' = 'RunDll32.exe powrprof.dll,SetSuspendState'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VVSN.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\StartUpManager.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RMSubs.dll] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'MULTIMEDIA KEYBOARD88' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmc.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe] 'Debugger' = 'RunDll32.exe powrprof.dll,SetSuspendState'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DiskExplorer.exe] 'Debugger' = 'RunDll32.exe powrprof.dll,SetSuspendState'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegistryEditor.exe] 'Debugger' = 'RunDll32.exe powrprof.dll,SetSuspendState'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BIEInterface.dll] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe] 'Debugger' = 'RunDll32.exe powrprof.dll,SetSuspendState'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedt32.exe] 'Debugger' = 'RunDll32.exe powrprof.dll,SetSuspendState'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmsgs.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SSVICHOSST.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scvhosts.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svichossst.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RVHOST.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SCVHSOT.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\trojan.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avpo.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_Se.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Windows Explorer.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a.dll.vbs] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\amvo.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WINNT32.EXE] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgw.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdlite.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdoesrv.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MDM.EXE] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fooool.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashAvast.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegCool.EXE] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoruns.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Procmon.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdswitch.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CAVRID.exe] 'Debugger' = 'dllcache\smss.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccApp.exe] 'Debugger' = 'dllcache\smss.exe'
Создает следующие файлы на съемном носителе:
  • <Имя диска съемного носителя>:\autorun.inf
  • <Имя диска съемного носителя>:\New Folder .exe
  • <Имя диска съемного носителя>:\RECYCLER \.exe
Вредоносные функции:
Для затруднения выявления своего присутствия в системе
блокирует отображение:
  • скрытых файлов
  • расширений файлов
Создает и запускает на исполнение:
  • <SYSTEM32>\dllcache\smss.exe 
Ищет следующие окна с целью
обнаружения утилит для анализа:
  • ClassName: '' WindowName: 'process monitor - sysinternals: www.sysinternals.com'
  • ClassName: '' WindowName: 'registry monitor - sysinternals: www.sysinternals.com'
  • ClassName: '' WindowName: 'file monitor - sysinternals: www.sysinternals.com'
Изменения в файловой системе:
Создает следующие файлы:
  • C:\New Folder .exe
  • C:\autorun.inf
  • <SYSTEM32>\New Folder .exe
  • C:\RECYCLER \.exe
  • <SYSTEM32>\dllcache\btpan.dll.lnk
  • <SYSTEM32>\dllcache\smss.exe
  • %PROGRAM_FILES%\Pic Sexi .exe
Присваивает атрибут 'скрытый' для следующих файлов:
  • C:\RECYCLER \.exe
  • <Имя диска съемного носителя>:\RECYCLER \.exe
  • <SYSTEM32>\dllcache\btpan.dll.lnk
  • <SYSTEM32>\dllcache\smss.exe
Удаляет следующие файлы:
  • <SYSTEM32>\dllcache\smss.exe
Другое:
Ищет следующие окна:
  • ClassName: '' WindowName: 'OleMainThreadWndName'
  • ClassName: '' WindowName: 'OLEChannelWnd'
  • ClassName: '' WindowName: 'CicMarshalWndIDG'
  • ClassName: '' WindowName: 'Notification Area'
  • ClassName: '' WindowName: 'Program Manager'
  • ClassName: '' WindowName: 'FolderView'
  • ClassName: '' WindowName: 'Running Applications'
  • ClassName: '' WindowName: 'CiceroUIWndFrame'
  • ClassName: '' WindowName: 'System32'
  • ClassName: '' WindowName: '%WINDIR%'
  • ClassName: '' WindowName: 'Setup - Anti KaleKhar Auto Protection'
  • ClassName: '' WindowName: 'Anti KaleKhar'
  • ClassName: '' WindowName: 'TF_FloatingLangBar_WndTitle'
  • ClassName: '' WindowName: ' www.Kalekhar.bdl.ir -'
  • ClassName: '' WindowName: ''
  • ClassName: '' WindowName: 'Start'
  • ClassName: '' WindowName: 'CicMarshalWndMGG'
  • ClassName: '' WindowName: '<Служебное имя> - build Mar 22 2011'
  • ClassName: '' WindowName: 'CicMarshalWndMMK'
  • ClassName: '' WindowName: '<Служебное имя>'
  • ClassName: '' WindowName: '<SYSTEM32>\cscript.exe'
  • ClassName: '' WindowName: 'Program Manager www.Kalekhar.bdl.ir -'
  • ClassName: '' WindowName: 'Program Manager www.Kalekhar.bdl.ir - www.Kalekhar.bdl.ir -'
  • ClassName: '' WindowName: '?'
  • ClassName: '' WindowName: '0'
  • ClassName: '' WindowName: 'Power Meter'
  • ClassName: '' WindowName: 'Power status'
  • ClassName: '' WindowName: 'CicMarshalWndECG'
  • ClassName: '' WindowName: 'MS_WebcheckMonitor'
  • ClassName: '' WindowName: 'Connections Tray'
  • ClassName: '' WindowName: 'Tiny H-Pot v1.6'
  • ClassName: '' WindowName: '&Always show icon on the taskbar.'
  • ClassName: '' WindowName: 'Show details for each &battery.'
  • ClassName: '' WindowName: 'avast! splash screen'
  • ClassName: '' WindowName: 'avast! simple user interface'
  • ClassName: '' WindowName: 'Shell Extension Test'
  • ClassName: '' WindowName: 'Registry toolkit'
  • ClassName: '' WindowName: 'avast! quick scanner'
  • ClassName: '' WindowName: 'eTrust EZ AntiVirus'
  • ClassName: '' WindowName: 'Kaspersky Anti-Virus Personal Pro Setup'
  • ClassName: '' WindowName: 'AVG 7.1 Professional - Control Center'
  • ClassName: '' WindowName: 'BitDefender 9 Professional Plus'
  • ClassName: '' WindowName: 'Registry Editor'
  • ClassName: '' WindowName: 'System Configuration'
  • ClassName: 'CabinetWClass' WindowName: ''
  • ClassName: '' WindowName: 'Modem1'
  • ClassName: '' WindowName: 'TuneUp Registry Editor'
  • ClassName: '' WindowName: 'TuneUp StartUp Manager'
  • ClassName: '' WindowName: 'Tuneup Disk Space Explorer'
  • ClassName: '' WindowName: 'TuneUp Process Manager'
  • ClassName: '' WindowName: 'Symantec AntiVirus'
  • ClassName: '' WindowName: 'Panda Global Protection 2009 Setup'
  • ClassName: '' WindowName: 'Panda Global Protection 2009'
  • ClassName: '' WindowName: 'AVG Anti-Spyware 7.5 Setup'
  • ClassName: '' WindowName: 'AVG Anti-Spyware 7.5'
  • ClassName: '' WindowName: 'Scanning hard disk drives'
  • ClassName: '' WindowName: 'avast! Antivirus Setup'
  • ClassName: '' WindowName: 'Panda Global Protection 2009 (2.00.00)'
  • ClassName: '' WindowName: 'Scan'
  • ClassName: '' WindowName: 'Windows Setup'
  • ClassName: '' WindowName: 'New?Folder? properties'
  • ClassName: '' WindowName: 'regmon'
  • ClassName: '' WindowName: 'RegCool 3.1.0.5'
  • ClassName: '' WindowName: 'McAfee Installer'
  • ClassName: '' WindowName: 'McAfee SecurityCenter'
  • ClassName: '' WindowName: 'New?Folder?.exe properties'
  • ClassName: '' WindowName: 'Kaspersky Anti-Virus 2009'