Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\backup.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\backup.exe
- скрытых файлов
- расширений файлов
- Редактора реестра (RegEdit)
- %HOMEPATH%\Start Menu\Programs\Startup\backup.exe %HOMEPATH%\Start Menu\Programs\Startup\
- %CommonProgramFiles%\Microsoft Shared\DW\1031\backup.exe %CommonProgramFiles%\Microsoft Shared\DW\1031\
- C:\Far2\Plugins\Align\backup.exe C:\Far2\Plugins\Align\
- %HOMEPATH%\Start Menu\Programs\Accessories\Entertainment\backup.exe %HOMEPATH%\Start Menu\Programs\Accessories\Entertainment\
- %CommonProgramFiles%\Microsoft Shared\DW\1028\backup.exe %CommonProgramFiles%\Microsoft Shared\DW\1028\
- C:\Far2\Plugins\7-Zip\backup.exe C:\Far2\Plugins\7-Zip\
- %CommonProgramFiles%\MSSoap\backup.exe %CommonProgramFiles%\MSSoap\
- %CommonProgramFiles%\Microsoft Shared\DW\1036\System Restore.exe %CommonProgramFiles%\Microsoft Shared\DW\1036\
- C:\Far2\Plugins\AutoWrap\backup.exe C:\Far2\Plugins\AutoWrap\
- %CommonProgramFiles%\Microsoft Shared\DW\1033\backup.exe %CommonProgramFiles%\Microsoft Shared\DW\1033\
- C:\Far2\Plugins\arclite\backup.exe C:\Far2\Plugins\arclite\
- %PROGRAM_FILES%\ComPlus Applications\update.exe %PROGRAM_FILES%\ComPlus Applications\
- %HOMEPATH%\Start Menu\Programs\backup.exe %HOMEPATH%\Start Menu\Programs\
- %CommonProgramFiles%\Microsoft Shared\DAO\backup.exe %CommonProgramFiles%\Microsoft Shared\DAO\
- C:\Far2\Encyclopedia\backup.exe C:\Far2\Encyclopedia\
- C:\Far2\Documentation\eng\backup.exe C:\Far2\Documentation\eng\
- %CommonProgramFiles%\Microsoft Shared\backup.exe %CommonProgramFiles%\Microsoft Shared\
- C:\Far2\Documentation\rus\System Restore.exe C:\Far2\Documentation\rus\
- %HOMEPATH%\Start Menu\Programs\Accessories\Accessibility\backup.exe %HOMEPATH%\Start Menu\Programs\Accessories\Accessibility\
- C:\Far2\Plugins\backup.exe C:\Far2\Plugins\
- %CommonProgramFiles%\Microsoft Shared\DW\1025\backup.exe %CommonProgramFiles%\Microsoft Shared\DW\1025\
- %HOMEPATH%\Start Menu\Programs\Accessories\data.exe %HOMEPATH%\Start Menu\Programs\Accessories\
- %CommonProgramFiles%\Microsoft Shared\DW\backup.exe %CommonProgramFiles%\Microsoft Shared\DW\
- C:\Far2\FExcept\backup.exe C:\Far2\FExcept\
- %PROGRAM_FILES%\FireFox\backup.exe %PROGRAM_FILES%\FireFox\
- %PROGRAM_FILES%\Internet Explorer\backup.exe %PROGRAM_FILES%\Internet Explorer\
- %CommonProgramFiles%\Microsoft Shared\Speech\1033\update.exe %CommonProgramFiles%\Microsoft Shared\Speech\1033\
- C:\Far2\Plugins\Colorer\bin\backup.exe C:\Far2\Plugins\Colorer\bin\
- C:\Far2\PluginSDK\Headers.c\backup.exe C:\Far2\PluginSDK\Headers.c\
- %CommonProgramFiles%\Microsoft Shared\DW\1042\backup.exe %CommonProgramFiles%\Microsoft Shared\DW\1042\
- %CommonProgramFiles%\ODBC\backup.exe %CommonProgramFiles%\ODBC\
- %CommonProgramFiles%\MSSoap\Binaries\Resources\1033\backup.exe %CommonProgramFiles%\MSSoap\Binaries\Resources\1033\
- %PROGRAM_FILES%\FireFox\chrome\browser\content\backup.exe %PROGRAM_FILES%\FireFox\chrome\browser\content\
- %CommonProgramFiles%\Microsoft Shared\DW\2052\backup.exe %CommonProgramFiles%\Microsoft Shared\DW\2052\
- C:\Far2\PluginSDK\Headers.pas\backup.exe C:\Far2\PluginSDK\Headers.pas\
- %WINDIR%\addins\backup.exe %WINDIR%\addins\
- %PROGRAM_FILES%\FireFox\components\backup.exe %PROGRAM_FILES%\FireFox\components\
- %CommonProgramFiles%\MSSoap\Binaries\backup.exe %CommonProgramFiles%\MSSoap\Binaries\
- %PROGRAM_FILES%\FireFox\chrome\backup.exe %PROGRAM_FILES%\FireFox\chrome\
- C:\Far2\PluginSDK\backup.exe C:\Far2\PluginSDK\
- %CommonProgramFiles%\Microsoft Shared\DW\1040\data.exe %CommonProgramFiles%\Microsoft Shared\DW\1040\
- C:\Far2\Plugins\Brackets\backup.exe C:\Far2\Plugins\Brackets\
- %CommonProgramFiles%\Microsoft Shared\MSInfo\backup.exe %CommonProgramFiles%\Microsoft Shared\MSInfo\
- %WINDIR%\backup.exe %WINDIR%\
- %PROGRAM_FILES%\FireFox\chrome\browser\backup.exe %PROGRAM_FILES%\FireFox\chrome\browser\
- %CommonProgramFiles%\MSSoap\Binaries\Resources\backup.exe %CommonProgramFiles%\MSSoap\Binaries\Resources\
- %CommonProgramFiles%\Microsoft Shared\Speech\System Restore.exe %CommonProgramFiles%\Microsoft Shared\Speech\
- C:\Far2\Plugins\Colorer\backup.exe C:\Far2\Plugins\Colorer\
- %CommonProgramFiles%\Microsoft Shared\DW\1041\backup.exe %CommonProgramFiles%\Microsoft Shared\DW\1041\
- %ALLUSERSPROFILE%\Start Menu\Programs\backup.exe %ALLUSERSPROFILE%\Start Menu\Programs\
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\backup.exe %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\backup.exe %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\
- %ALLUSERSPROFILE%\Documents\My Videos\backup.exe %ALLUSERSPROFILE%\Documents\My Videos\
- %ALLUSERSPROFILE%\Favorites\backup.exe %ALLUSERSPROFILE%\Favorites\
- %ALLUSERSPROFILE%\Start Menu\backup.exe %ALLUSERSPROFILE%\Start Menu\
- %HOMEPATH%\System Restore.exe %HOMEPATH%\
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\backup.exe %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\
- C:\Far2\Addons\backup.exe C:\Far2\Addons\
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\backup.exe %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\backup.exe %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\
- C:\Far2\backup.exe C:\Far2\
- %ALLUSERSPROFILE%\Desktop\backup.exe %ALLUSERSPROFILE%\Desktop\
- %ALLUSERSPROFILE%\Documents\backup.exe %ALLUSERSPROFILE%\Documents\
- %ALLUSERSPROFILE%\Documents\My Music\backup.exe %ALLUSERSPROFILE%\Documents\My Music\
- C:\data.exe \
- C:\Documents and Settings\data.exe C:\Documents and Settings\
- %ALLUSERSPROFILE%\backup.exe %ALLUSERSPROFILE%\
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\0338E140\backup.exe %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\0338E140\
- %ALLUSERSPROFILE%\Documents\My Pictures\backup.exe %ALLUSERSPROFILE%\Documents\My Pictures\
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\backup.exe %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\
- %ALLUSERSPROFILE%\Documents\My Music\My Playlists\backup.exe %ALLUSERSPROFILE%\Documents\My Music\My Playlists\
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\backup.exe %ALLUSERSPROFILE%\Documents\My Music\Sample Music\
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\backup.exe %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\
- %HOMEPATH%\Cookies\backup.exe %HOMEPATH%\Cookies\
- <Служебный элемент> <Служебный элемент>
- %HOMEPATH%\My Documents\My Pictures\backup.exe %HOMEPATH%\My Documents\My Pictures\
- C:\Far2\Addons\XLat\backup.exe C:\Far2\Addons\XLat\
- C:\Far2\Addons\SetUp\backup.exe C:\Far2\Addons\SetUp\
- %HOMEPATH%\My Documents\My Music\backup.exe %HOMEPATH%\My Documents\My Music\
- C:\Far2\Addons\Shell\backup.exe C:\Far2\Addons\Shell\
- C:\Far2\Addons\XLat\Russian\System Restore.exe C:\Far2\Addons\XLat\Russian\
- %CommonProgramFiles%\update.exe %CommonProgramFiles%\
- %HOMEPATH%\Start Menu\backup.exe %HOMEPATH%\Start Menu\
- %PROGRAM_FILES%\backup.exe %PROGRAM_FILES%\
- C:\Far2\Documentation\backup.exe C:\Far2\Documentation\
- %HOMEPATH%\My Documents\My Received Files\backup.exe %HOMEPATH%\My Documents\My Received Files\
- %ALLUSERSPROFILE%\Start Menu\Programs\Games\backup.exe %ALLUSERSPROFILE%\Start Menu\Programs\Games\
- %HOMEPATH%\Favorites\backup.exe %HOMEPATH%\Favorites\
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\backup.exe %ALLUSERSPROFILE%\Start Menu\Programs\Startup\
- %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\update.exe %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\
- %HOMEPATH%\Desktop\backup.exe %HOMEPATH%\Desktop\
- C:\Far2\Addons\Colors\backup.exe C:\Far2\Addons\Colors\
- %HOMEPATH%\My Documents\data.exe %HOMEPATH%\My Documents\
- C:\Far2\Addons\Macros\backup.exe C:\Far2\Addons\Macros\
- %HOMEPATH%\My Documents\Downloads\backup.exe %HOMEPATH%\My Documents\Downloads\
- C:\Far2\Addons\Colors\Custom Highlighting\backup.exe C:\Far2\Addons\Colors\Custom Highlighting\
- %HOMEPATH%\Favorites\Links\backup.exe %HOMEPATH%\Favorites\Links\
- C:\Far2\Addons\Colors\Default Highlighting\backup.exe C:\Far2\Addons\Colors\Default Highlighting\
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] 'NoFolderOptions' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '00000001'
- C:\Far2\Plugins\Align\backup.exe
- %CommonProgramFiles%\Microsoft Shared\DW\1033\backup.exe
- C:\Far2\Plugins\arclite\backup.exe
- C:\Far2\Plugins\7-Zip\backup.exe
- %CommonProgramFiles%\Microsoft Shared\DW\1028\backup.exe
- %CommonProgramFiles%\Microsoft Shared\DW\1031\backup.exe
- %PROGRAM_FILES%\ComPlus Applications\update.exe
- %PROGRAM_FILES%\FireFox\backup.exe
- %CommonProgramFiles%\Microsoft Shared\DW\1040\data.exe
- %CommonProgramFiles%\MSSoap\Binaries\backup.exe
- %CommonProgramFiles%\MSSoap\backup.exe
- C:\Far2\Plugins\AutoWrap\backup.exe
- %CommonProgramFiles%\Microsoft Shared\DW\1036\System Restore.exe
- C:\Far2\Documentation\rus\System Restore.exe
- %CommonProgramFiles%\Microsoft Shared\DAO\backup.exe
- C:\Far2\Encyclopedia\backup.exe
- %HOMEPATH%\Start Menu\backup.exe
- %CommonProgramFiles%\Microsoft Shared\backup.exe
- %HOMEPATH%\Start Menu\Programs\backup.exe
- %HOMEPATH%\Start Menu\Programs\Accessories\data.exe
- %CommonProgramFiles%\Microsoft Shared\DW\1025\backup.exe
- C:\Far2\Plugins\backup.exe
- %HOMEPATH%\Start Menu\Programs\Accessories\Entertainment\backup.exe
- %CommonProgramFiles%\Microsoft Shared\DW\backup.exe
- C:\Far2\FExcept\backup.exe
- %HOMEPATH%\Start Menu\Programs\Accessories\Accessibility\backup.exe
- C:\Far2\Plugins\Brackets\backup.exe
- %CommonProgramFiles%\MSSoap\Binaries\Resources\1033\backup.exe
- %PROGRAM_FILES%\FireFox\chrome\browser\content\backup.exe
- C:\Far2\PluginSDK\Headers.pas\backup.exe
- %CommonProgramFiles%\ODBC\backup.exe
- %PROGRAM_FILES%\Internet Explorer\backup.exe
- %WINDIR%\addins\backup.exe
- %PROGRAM_FILES%\FireFox\components\backup.exe
- %CommonProgramFiles%\Microsoft Shared\Stationery\backup.exe
- C:\Far2\Plugins\Compare\backup.exe
- C:\Far2\Plugins\Colorer\hrc\backup.exe
- %CommonProgramFiles%\Microsoft Shared\DW\2052\backup.exe
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\backup.exe
- %CommonProgramFiles%\ODBC\Data Sources\backup.exe
- C:\Far2\Plugins\Colorer\backup.exe
- %CommonProgramFiles%\Microsoft Shared\DW\1041\backup.exe
- %CommonProgramFiles%\Microsoft Shared\Speech\System Restore.exe
- %PROGRAM_FILES%\FireFox\chrome\backup.exe
- %CommonProgramFiles%\Microsoft Shared\MSInfo\backup.exe
- C:\Far2\PluginSDK\backup.exe
- %PROGRAM_FILES%\FireFox\chrome\browser\backup.exe
- %CommonProgramFiles%\Microsoft Shared\DW\1042\backup.exe
- %CommonProgramFiles%\Microsoft Shared\Speech\1033\update.exe
- C:\Far2\Plugins\Colorer\bin\backup.exe
- %CommonProgramFiles%\MSSoap\Binaries\Resources\backup.exe
- C:\Far2\PluginSDK\Headers.c\backup.exe
- %WINDIR%\backup.exe
- C:\Far2\Documentation\eng\backup.exe
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\backup.exe
- %ALLUSERSPROFILE%\Documents\My Videos\backup.exe
- %ALLUSERSPROFILE%\Favorites\backup.exe
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\backup.exe
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\0338E140\backup.exe
- %ALLUSERSPROFILE%\Documents\My Pictures\backup.exe
- %ALLUSERSPROFILE%\Start Menu\backup.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\backup.exe
- <Текущая директория>\<Имя вируса>.zip
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\backup.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\backup.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\backup.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\backup.exe
- <Текущая директория>\82a02820
- <Текущая директория>\<Имя вируса>.dat
- C:\data.exe
- <Текущая директория>\backup.exe
- <Текущая директория>\temp.zip
- C:\Documents and Settings\data.exe
- %ALLUSERSPROFILE%\Documents\My Music\backup.exe
- %ALLUSERSPROFILE%\Documents\My Music\My Playlists\backup.exe
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\backup.exe
- %ALLUSERSPROFILE%\backup.exe
- %ALLUSERSPROFILE%\Desktop\backup.exe
- %ALLUSERSPROFILE%\Documents\backup.exe
- C:\Far2\backup.exe
- %HOMEPATH%\My Documents\My Music\backup.exe
- C:\Far2\Addons\Shell\backup.exe
- <Служебный элемент>
- C:\Far2\Addons\Macros\backup.exe
- %HOMEPATH%\My Documents\Downloads\backup.exe
- C:\Far2\Addons\SetUp\backup.exe
- %HOMEPATH%\My Documents\My Pictures\backup.exe
- %HOMEPATH%\My Documents\My Received Files\backup.exe
- C:\Far2\Addons\XLat\Russian\System Restore.exe
- %CommonProgramFiles%\update.exe
- C:\Far2\Addons\XLat\backup.exe
- %PROGRAM_FILES%\backup.exe
- C:\Far2\Documentation\backup.exe
- %HOMEPATH%\Cookies\backup.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\update.exe
- C:\Far2\Addons\Colors\backup.exe
- %HOMEPATH%\System Restore.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\backup.exe
- C:\Far2\Addons\backup.exe
- %HOMEPATH%\Desktop\backup.exe
- %HOMEPATH%\Favorites\Links\backup.exe
- C:\Far2\Addons\Colors\Default Highlighting\backup.exe
- %HOMEPATH%\My Documents\data.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\Games\backup.exe
- %HOMEPATH%\Favorites\backup.exe
- C:\Far2\Addons\Colors\Custom Highlighting\backup.exe
- <Текущая директория>\<Имя вируса>.zip
- <Текущая директория>\temp.zip
- %TEMP%\~DFE873.tmp
- %TEMP%\~DF9E6B.tmp
- %TEMP%\~DF7AEB.tmp
- %TEMP%\~DF21BC.tmp
- %TEMP%\~DF99B5.tmp
- %TEMP%\~DFCA8C.tmp
- %TEMP%\~DFA046.tmp
- %TEMP%\~DF83D2.tmp
- %TEMP%\~DF5EA4.tmp
- %TEMP%\~DFE448.tmp
- %TEMP%\~DF3FC4.tmp
- %TEMP%\~DF5A02.tmp
- %TEMP%\~DF42AC.tmp
- %TEMP%\~DF6FD5.tmp
- %TEMP%\~DF7F07.tmp
- %TEMP%\~DF2BFA.tmp
- %TEMP%\~DF7B32.tmp
- %TEMP%\~DF5831.tmp
- %TEMP%\~DF3635.tmp
- %TEMP%\~DF508A.tmp
- %TEMP%\~DF738C.tmp
- %TEMP%\~DF8F8.tmp
- %TEMP%\~DFC53A.tmp
- %TEMP%\~DF7DD6.tmp
- %TEMP%\~DFB288.tmp
- %TEMP%\~DF7643.tmp
- %TEMP%\~DFE923.tmp
- %TEMP%\~DFF75.tmp
- %TEMP%\~DFABE.tmp
- %TEMP%\~DFC23A.tmp
- %TEMP%\~DF9918.tmp
- %TEMP%\~DF4F8.tmp
- %TEMP%\~DFDEFA.tmp
- %TEMP%\~DF1862.tmp
- %TEMP%\~DF592D.tmp
- <Текущая директория>\<Имя вируса>.dat
- %TEMP%\~DF4C11.tmp
- %TEMP%\~DFB82F.tmp
- %TEMP%\~DFAC05.tmp
- <Текущая директория>\temp.zip
- %TEMP%\~DFD15B.tmp
- %TEMP%\~DFF65A.tmp
- %TEMP%\~DFC793.tmp
- %TEMP%\~DFA393.tmp
- %TEMP%\~DF6C9A.tmp
- %TEMP%\~DF3B49.tmp
- %TEMP%\~DF8B1E.tmp
- %TEMP%\~DF292B.tmp
- %TEMP%\~DFEEE7.tmp
- %TEMP%\~DF8DF.tmp
- %TEMP%\~DF2772.tmp
- %TEMP%\~DFCD3.tmp
- %TEMP%\~DFAB8C.tmp
- %TEMP%\~DF8B79.tmp
- %TEMP%\~DF43D2.tmp
- %TEMP%\~DFA218.tmp
- %TEMP%\~DFED6C.tmp
- %TEMP%\~DFCAAC.tmp
- %TEMP%\~DFC221.tmp
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ExploreWClass' WindowName: ''
- ClassName: 'CabinetWClass' WindowName: ''