Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.Siggen3.63843

Добавлен в вирусную базу Dr.Web: 2012-05-15

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения:
Подменяет следующие исполняемые системные файлы:
  • <SYSTEM32>\setup.exe файлом <SYSTEM32>\setup.bmp
  • <SYSTEM32>\msvbvm60.dll файлом <SYSTEM32>\Msvbvm60.dll
Создает следующие файлы на съемном носителе:
  • <Имя диска съемного носителя>:\Msvbvm60.dll
  • <Имя диска съемного носителя>:\FOUND.007.exe
  • <Имя диска съемного носителя>:\Autorun.inf
Вредоносные функции:
Создает и запускает на исполнение:
  • %WINDIR%\AE 0124 BE.exe
  • <DRIVERS>\winlogon.exe
Запускает на исполнение:
  • <SYSTEM32>\rundll32.exe <SYSTEM32>\shimgvw.dll,ImageView_Fullscreen %WINDIR%\AE 0124 BE.jpg
Изменения в файловой системе:
Создает следующие файлы:
  • %WINDIR%\pchealth\helpctr\System\images\Centers\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\images\48x48\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\images\Expando\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Common\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\images\32x32\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\blurbs\Msvbvm60.dll
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\images\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\images\24x24\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\images\16x16\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\Msvbvm60.dll
  • <SYSTEM32>\dllcache\Msvbvm60.dll
  • <SYSTEM32>\config\systemprofile\Templates\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Server\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\Msvbvm60.dll
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Msvbvm60.dll
  • C:\Autorun.inf
  • <DRIVERS>\Msvbvm60.dll
  • C:\FOUND.007.exe
  • %HOMEPATH%\Recent\AE 0124 BE.lnk
  • C:\Msvbvm60.dll
  • %WINDIR%\AE 0124 BE.exe
  • %WINDIR%\Msvbvm60.dll
  • %WINDIR%\AE 0124 BE.jpg
  • <DRIVERS>\winlogon.exe
  • <Текущая директория>\Msvbvm60.dll
  • C:\B1uv3nth3x1.diz
  • %HOMEPATH%\Recent\WINDOWS.lnk
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\Msvbvm60.dll
  • %WINDIR%\Media\Msvbvm60.dll
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\Msvbvm60.dll
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\Msvbvm60.dll
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\chrome\Msvbvm60.dll
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\Msvbvm60.dll
  • %WINDIR%\Help\Tours\htmlTour\Msvbvm60.dll
  • %WINDIR%\Cursors\Msvbvm60.dll
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\Msvbvm60.dll
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\Msvbvm60.dll
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Msvbvm60.dll
Присваивает атрибут 'скрытый' для следующих файлов:
  • %WINDIR%\pchealth\helpctr\System\images\Expando\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\images\Centers\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Common\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\images\48x48\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\images\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\blurbs\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\images\16x16\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\images\32x32\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\images\24x24\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\Msvbvm60.dll
  • <SYSTEM32>\dllcache\Msvbvm60.dll
  • <SYSTEM32>\config\systemprofile\Templates\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Server\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\Msvbvm60.dll
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\Msvbvm60.dll
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\Msvbvm60.dll
  • <Имя диска съемного носителя>:\Autorun.inf
  • C:\Msvbvm60.dll
  • <Имя диска съемного носителя>:\FOUND.007.exe
  • %WINDIR%\Cursors\Msvbvm60.dll
  • <Имя диска съемного носителя>:\Msvbvm60.dll
  • C:\FOUND.007.exe
  • <DRIVERS>\winlogon.exe
  • %WINDIR%\Msvbvm60.dll
  • <Текущая директория>\Msvbvm60.dll
  • C:\Autorun.inf
  • <DRIVERS>\Msvbvm60.dll
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\Msvbvm60.dll
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\Msvbvm60.dll
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\chrome\Msvbvm60.dll
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Msvbvm60.dll
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\Msvbvm60.dll
  • %WINDIR%\Media\Msvbvm60.dll
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\Msvbvm60.dll
  • %WINDIR%\Help\Tours\htmlTour\Msvbvm60.dll
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Msvbvm60.dll
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\Msvbvm60.dll
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\Msvbvm60.dll
Перемещает следующие системные файлы:
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Quit.bmp в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Quit.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendChat.gif в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendChat.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Options.bmp в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\Options.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\hide-chat.gif в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\hide-chat.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\info.gif в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\info.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendFile.bmp в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendFile.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Server\ESC_key.gif в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Server\ESC_key.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Server\Helpee_line.gif в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Server\Helpee_line.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\show-chat.gif в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\show-chat.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendVoice.bmp в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendVoice.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendVoiceOn.gif в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\SendVoiceOn.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Common\icon_warning_32x.gif в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Common\icon_warning_32x.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\Animation.gif в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\Animation.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Common\icon_information_32x.gif в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Common\icon_information_32x.exe
  • %WINDIR%\pchealth\helpctr\System\images\Expando\helpdoc.gif в %WINDIR%\pchealth\helpctr\System\images\Expando\helpdoc.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\ding.wav в %WINDIR%\pchealth\helpctr\System\Remote Assistance\ding.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\combobox_line.gif в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\combobox_line.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\UpArrow.gif в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\UpArrow.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\HelpCenter.bmp в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\HelpCenter.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\TakeControl.bmp в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\TakeControl.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\connected.gif в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\connected.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\DownArrow.gif в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\DownArrow.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\monitor.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\monitor.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\personalizing.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\personalizing.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\info.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\info.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\GArrow.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\GArrow.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\gears.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\gears.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\PieChart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\PieChart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\r1_c1.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\r1_c1.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\r1_c2.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\r1_c2.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\printer.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\printer.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\PieGrey.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\PieGrey.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\PieWhite.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\PieWhite.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\card.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\card.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\cd.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\cd.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\BArrow.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\BArrow.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Server\StopControl.bmp в %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Server\StopControl.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\alert.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\alert.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\check.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\check.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\error.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\error.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\floppy.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\floppy.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\drive.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\drive.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\chip.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\chip.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\down.bmp в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\down.exe
  • %WINDIR%\pchealth\helpctr\System\images\Expando\expanded.gif в %WINDIR%\pchealth\helpctr\System\images\Expando\expanded.exe
  • %WINDIR%\pchealth\helpctr\System\images\icon_onlineinline_12x.bmp в %WINDIR%\pchealth\helpctr\System\images\icon_onlineinline_12x.exe
  • %WINDIR%\pchealth\helpctr\System\images\icon_tours_12x.bmp в %WINDIR%\pchealth\helpctr\System\images\icon_tours_12x.exe
  • %WINDIR%\pchealth\helpctr\System\images\icon_newwindow_12x.bmp в %WINDIR%\pchealth\helpctr\System\images\icon_newwindow_12x.exe
  • %WINDIR%\pchealth\helpctr\System\images\icon_articles_12x.bmp в %WINDIR%\pchealth\helpctr\System\images\icon_articles_12x.exe
  • %WINDIR%\pchealth\helpctr\System\images\icon_blank_12x.bmp в %WINDIR%\pchealth\helpctr\System\images\icon_blank_12x.exe
  • %WINDIR%\pchealth\helpctr\System\images\icon_tutorials_12x.bmp в %WINDIR%\pchealth\helpctr\System\images\icon_tutorials_12x.exe
  • %WINDIR%\pchealth\helpctr\System\images\wrapperhelp.gif в %WINDIR%\pchealth\helpctr\System\images\wrapperhelp.exe
  • %WINDIR%\pchealth\helpctr\System\images\16x16\arrow_blue_normal_shadow.bmp в %WINDIR%\pchealth\helpctr\System\images\16x16\arrow_blue_normal_shadow.exe
  • %WINDIR%\pchealth\helpctr\System\images\warning.gif в %WINDIR%\pchealth\helpctr\System\images\warning.exe
  • %WINDIR%\pchealth\helpctr\System\images\info.gif в %WINDIR%\pchealth\helpctr\System\images\info.exe
  • %WINDIR%\pchealth\helpctr\System\images\progbar.gif в %WINDIR%\pchealth\helpctr\System\images\progbar.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\header.bmp в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\header.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\SplashScreen.bmp в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\SplashScreen.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\watermark.bmp в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\watermark.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\header.bmp в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\header.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\SplashScreen.bmp в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\SplashScreen.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\watermark.bmp в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\watermark.exe
  • %WINDIR%\pchealth\helpctr\System\images\flyout_arrow.gif в %WINDIR%\pchealth\helpctr\System\images\flyout_arrow.exe
  • %WINDIR%\pchealth\helpctr\System\images\get_conn.gif в %WINDIR%\pchealth\helpctr\System\images\get_conn.exe
  • %WINDIR%\pchealth\helpctr\System\images\feedback.gif в %WINDIR%\pchealth\helpctr\System\images\feedback.exe
  • %WINDIR%\pchealth\helpctr\System\blurbs\watermark_300x.bmp в %WINDIR%\pchealth\helpctr\System\blurbs\watermark_300x.exe
  • %WINDIR%\pchealth\helpctr\System\images\error.gif в %WINDIR%\pchealth\helpctr\System\images\error.exe
  • %WINDIR%\pchealth\helpctr\System\images\48x48\desktop_icon_04.bmp в %WINDIR%\pchealth\helpctr\System\images\48x48\desktop_icon_04.exe
  • %WINDIR%\pchealth\helpctr\System\images\48x48\desktop_icon_generic.bmp в %WINDIR%\pchealth\helpctr\System\images\48x48\desktop_icon_generic.exe
  • %WINDIR%\pchealth\helpctr\System\images\48x48\desktop_icon_03.bmp в %WINDIR%\pchealth\helpctr\System\images\48x48\desktop_icon_03.exe
  • %WINDIR%\pchealth\helpctr\System\images\48x48\desktop_icon_01.bmp в %WINDIR%\pchealth\helpctr\System\images\48x48\desktop_icon_01.exe
  • %WINDIR%\pchealth\helpctr\System\images\48x48\desktop_icon_02.bmp в %WINDIR%\pchealth\helpctr\System\images\48x48\desktop_icon_02.exe
  • %WINDIR%\pchealth\helpctr\System\images\Centers\blue_arrow.gif в %WINDIR%\pchealth\helpctr\System\images\Centers\blue_arrow.exe
  • %WINDIR%\pchealth\helpctr\System\images\Expando\collapsed.gif в %WINDIR%\pchealth\helpctr\System\images\Expando\collapsed.exe
  • %WINDIR%\pchealth\helpctr\System\images\Expando\endnode.gif в %WINDIR%\pchealth\helpctr\System\images\Expando\endnode.exe
  • %WINDIR%\pchealth\helpctr\System\images\Centers\Uabrand.gif в %WINDIR%\pchealth\helpctr\System\images\Centers\Uabrand.exe
  • %WINDIR%\pchealth\helpctr\System\images\Centers\Connect.gif в %WINDIR%\pchealth\helpctr\System\images\Centers\Connect.exe
  • %WINDIR%\pchealth\helpctr\System\images\Centers\IULogo.gif в %WINDIR%\pchealth\helpctr\System\images\Centers\IULogo.exe
  • %WINDIR%\pchealth\helpctr\System\images\16x16\support.bmp в %WINDIR%\pchealth\helpctr\System\images\16x16\support.exe
  • %WINDIR%\pchealth\helpctr\System\images\16x16\tools.bmp в %WINDIR%\pchealth\helpctr\System\images\16x16\tools.exe
  • %WINDIR%\pchealth\helpctr\System\images\16x16\errmsg.bmp в %WINDIR%\pchealth\helpctr\System\images\16x16\errmsg.exe
  • %WINDIR%\pchealth\helpctr\System\images\16x16\arrow_green_normal_shadow.bmp в %WINDIR%\pchealth\helpctr\System\images\16x16\arrow_green_normal_shadow.exe
  • %WINDIR%\pchealth\helpctr\System\images\16x16\compat.bmp в %WINDIR%\pchealth\helpctr\System\images\16x16\compat.exe
  • %WINDIR%\pchealth\helpctr\System\images\16x16\update.bmp в %WINDIR%\pchealth\helpctr\System\images\16x16\update.exe
  • %WINDIR%\pchealth\helpctr\System\images\24x24\arrow_green_normal.bmp в %WINDIR%\pchealth\helpctr\System\images\24x24\arrow_green_normal.exe
  • %WINDIR%\pchealth\helpctr\System\images\32x32\logo.bmp в %WINDIR%\pchealth\helpctr\System\images\32x32\logo.exe
  • %WINDIR%\pchealth\helpctr\System\images\24x24\arrow_green_mouseover.bmp в %WINDIR%\pchealth\helpctr\System\images\24x24\arrow_green_mouseover.exe
  • %WINDIR%\pchealth\helpctr\System\images\16x16\warning.gif в %WINDIR%\pchealth\helpctr\System\images\16x16\warning.exe
  • %WINDIR%\pchealth\helpctr\System\images\24x24\arrow_green_mousedown.bmp в %WINDIR%\pchealth\helpctr\System\images\24x24\arrow_green_mousedown.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\icon_information_32x.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\icon_information_32x.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\icon_warning_32x.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\icon_warning_32x.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\status_ok.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\status_ok.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r3_c2.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r3_c2.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\spacer.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\spacer.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\address_book.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\address_book.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy_attention.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy_attention.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy_away.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy_away.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\arrow.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\arrow.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\attention.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\attention.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\90_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\90_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\95_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\95_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\85_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\85_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\75_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\75_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\80_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\80_chart.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\GArrow.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\GArrow.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r1_c2.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r1_c2.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r1_c3.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r1_c3.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r1_c1.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\r1_c1.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\GRect.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\GRect.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Info_Icon.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Info_Icon.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\outlook_express.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\outlook_express.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\square_bullet.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\square_bullet.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\outlook.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\outlook.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\monitor_left.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\monitor_left.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\monitor_right.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\monitor_right.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\check.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\check.exe
  • <SYSTEM32>\config\systemprofile\Templates\sndrec.wav в <SYSTEM32>\config\systemprofile\Templates\sndrec.exe
  • <SYSTEM32>\dllcache\gm.dls в <SYSTEM32>\dllcache\gm.exe
  • <SYSTEM32>\ntimage.gif в <SYSTEM32>\ntimage.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\help.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\help.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreenshot3.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreenshot3.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\Envelope.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\Envelope.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\floppy.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\floppy.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy_offline.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy_offline.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy_busy.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy_busy.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy_none.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\buddy_none.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\generic_mail.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\generic_mail.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\logon_anim.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\logon_anim.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\messenger_big.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\messenger_big.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\info.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\info.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\icon_extweb.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\icon_extweb.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\IM_icon.gif в %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\IM_icon.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\70_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\70_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\30_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\30_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\35_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\35_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\25_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\25_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\15_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\15_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\20_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\20_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\40_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\40_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\5_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\5_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\60_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\60_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\55_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\55_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\45_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\45_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\50_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\50_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\system.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\system.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\Untitled.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\Untitled.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\spacer.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\spacer.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\r1_c3.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\r1_c3.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\r3_c2.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\r3_c2.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\up.bmp в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\up.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\100_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\100_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\10_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\10_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\0_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\0_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\usb.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\usb.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\windows.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\windows.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\35_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\35_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\40_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\40_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\30_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\30_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\20_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\20_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\25_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\25_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\45_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\45_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\60_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\60_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\65_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\65_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\5_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\5_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\50_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\50_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\55_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\55_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\80_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\80_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\85_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\85_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\75_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\75_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\65_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\65_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\70_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\70_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\90_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\90_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\10_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\10_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\15_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\15_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\100_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\100_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\95_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\95_chart.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\0_chart.gif в %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\0_chart.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\yellowCORNER.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\yellowCORNER.exe
  • %WINDIR%\Help\Tours\htmlTour\nav_start_here.gif в %WINDIR%\Help\Tours\htmlTour\nav_start_here.exe
  • %WINDIR%\Help\Tours\htmlTour\nav_start_here_down.gif в %WINDIR%\Help\Tours\htmlTour\nav_start_here_down.exe
  • %WINDIR%\Help\Tours\htmlTour\nav_safe_easy_down.gif в %WINDIR%\Help\Tours\htmlTour\nav_safe_easy_down.exe
  • %WINDIR%\Help\Tours\htmlTour\nav_gray.gif в %WINDIR%\Help\Tours\htmlTour\nav_gray.exe
  • %WINDIR%\Help\Tours\htmlTour\nav_safe_easy.gif в %WINDIR%\Help\Tours\htmlTour\nav_safe_easy.exe
  • %WINDIR%\Help\Tours\htmlTour\nav_unlock.gif в %WINDIR%\Help\Tours\htmlTour\nav_unlock.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud2.wav в %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud2.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud3.wav в %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud3.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud1.wav в %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud1.exe
  • %WINDIR%\Help\Tours\htmlTour\nav_unlock_down.gif в %WINDIR%\Help\Tours\htmlTour\nav_unlock_down.exe
  • %WINDIR%\Help\Tours\htmlTour\spacer.gif в %WINDIR%\Help\Tours\htmlTour\spacer.exe
  • %WINDIR%\Cursors\wagtail.ani в %WINDIR%\Cursors\wagtail.exe
  • %WINDIR%\Help\Tours\htmlTour\bluearrow.gif в %WINDIR%\Help\Tours\htmlTour\bluearrow.exe
  • %WINDIR%\Cursors\vanisher.ani в %WINDIR%\Cursors\vanisher.exe
  • %WINDIR%\Cursors\sizewe.ani в %WINDIR%\Cursors\sizewe.exe
  • %WINDIR%\Cursors\stopwtch.ani в %WINDIR%\Cursors\stopwtch.exe
  • %WINDIR%\Help\Tours\htmlTour\bot_bar.gif в %WINDIR%\Help\Tours\htmlTour\bot_bar.exe
  • %WINDIR%\Help\Tours\htmlTour\nav_connected.gif в %WINDIR%\Help\Tours\htmlTour\nav_connected.exe
  • %WINDIR%\Help\Tours\htmlTour\nav_connected_down.gif в %WINDIR%\Help\Tours\htmlTour\nav_connected_down.exe
  • %WINDIR%\Help\Tours\htmlTour\nav_blank.gif в %WINDIR%\Help\Tours\htmlTour\nav_blank.exe
  • %WINDIR%\Help\Tours\htmlTour\nav_best.gif в %WINDIR%\Help\Tours\htmlTour\nav_best.exe
  • %WINDIR%\Help\Tours\htmlTour\nav_best_down.gif в %WINDIR%\Help\Tours\htmlTour\nav_best_down.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\cloapph.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\cloapph.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\cnt.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\cnt.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\cloapp.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\cloapp.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\bktr.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\bktr.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\bktrh.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\bktrh.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\cntd.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\cntd.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\taon.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\taon.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\taonh.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\taonh.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\taoffh.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\taoffh.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\cnth.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\cnth.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\taoff.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\taoff.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud7.wav в %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud7.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud8.wav в %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud8.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud6.wav в %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud6.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud4.wav в %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud4.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud5.wav в %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud5.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud9.wav в %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\wmpaud9.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\videobg.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\videobg.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\vidsamp.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\vidsamp.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\tourbg.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\tourbg.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\mplogo.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\mplogo.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\mplogoh.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\mplogoh.exe
  • %WINDIR%\Cursors\sizenwse.ani в %WINDIR%\Cursors\sizenwse.exe
  • %WINDIR%\Zapotec.bmp в %WINDIR%\Zapotec.exe
  • %WINDIR%\Cursors\appstar2.ani в %WINDIR%\Cursors\appstar2.exe
  • %WINDIR%\winnt256.bmp в %WINDIR%\winnt256.exe
  • %WINDIR%\Soap Bubbles.bmp в %WINDIR%\Soap Bubbles.exe
  • %WINDIR%\winnt.bmp в %WINDIR%\winnt.exe
  • %WINDIR%\Cursors\appstar3.ani в %WINDIR%\Cursors\appstar3.exe
  • %WINDIR%\Cursors\coin.ani в %WINDIR%\Cursors\coin.exe
  • %WINDIR%\Cursors\counter.ani в %WINDIR%\Cursors\counter.exe
  • %WINDIR%\Cursors\barber.ani в %WINDIR%\Cursors\barber.exe
  • %WINDIR%\Cursors\appstart.ani в %WINDIR%\Cursors\appstart.exe
  • %WINDIR%\Cursors\banana.ani в %WINDIR%\Cursors\banana.exe
  • %WINDIR%\Coffee Bean.bmp в %WINDIR%\Coffee Bean.exe
  • %WINDIR%\FeatherTexture.bmp в %WINDIR%\FeatherTexture.exe
  • %WINDIR%\clock.avi в %WINDIR%\clock.exe
  • <SYSTEM32>\msvbvm60.dll в <SYSTEM32>\Msvbvm60.dlll
  • %WINDIR%\Blue Lace 16.bmp в %WINDIR%\Blue Lace 16.exe
  • %WINDIR%\Gone Fishing.bmp в %WINDIR%\Gone Fishing.exe
  • %WINDIR%\River Sumida.bmp в %WINDIR%\River Sumida.exe
  • %WINDIR%\Santa Fe Stucco.bmp в %WINDIR%\Santa Fe Stucco.exe
  • %WINDIR%\Rhododendron.bmp в %WINDIR%\Rhododendron.exe
  • %WINDIR%\Greenstone.bmp в %WINDIR%\Greenstone.exe
  • %WINDIR%\Prairie Wind.bmp в %WINDIR%\Prairie Wind.exe
  • %WINDIR%\Cursors\hourgla3.ani в %WINDIR%\Cursors\hourgla3.exe
  • %WINDIR%\Cursors\hourglas.ani в %WINDIR%\Cursors\hourglas.exe
  • %WINDIR%\Cursors\hourgla2.ani в %WINDIR%\Cursors\hourgla2.exe
  • %WINDIR%\Cursors\handwe.ani в %WINDIR%\Cursors\handwe.exe
  • %WINDIR%\Cursors\horse.ani в %WINDIR%\Cursors\horse.exe
  • %WINDIR%\Cursors\metronom.ani в %WINDIR%\Cursors\metronom.exe
  • %WINDIR%\Cursors\sizenesw.ani в %WINDIR%\Cursors\sizenesw.exe
  • %WINDIR%\Cursors\sizens.ani в %WINDIR%\Cursors\sizens.exe
  • %WINDIR%\Cursors\raindrop.ani в %WINDIR%\Cursors\raindrop.exe
  • %WINDIR%\Cursors\piano.ani в %WINDIR%\Cursors\piano.exe
  • %WINDIR%\Cursors\rainbow.ani в %WINDIR%\Cursors\rainbow.exe
  • %WINDIR%\Cursors\fillitup.ani в %WINDIR%\Cursors\fillitup.exe
  • %WINDIR%\Cursors\hand.ani в %WINDIR%\Cursors\hand.exe
  • %WINDIR%\Cursors\drum.ani в %WINDIR%\Cursors\drum.exe
  • %WINDIR%\Cursors\dinosau2.ani в %WINDIR%\Cursors\dinosau2.exe
  • %WINDIR%\Cursors\dinosaur.ani в %WINDIR%\Cursors\dinosaur.exe
  • %WINDIR%\Cursors\handapst.ani в %WINDIR%\Cursors\handapst.exe
  • %WINDIR%\Cursors\handnwse.ani в %WINDIR%\Cursors\handnwse.exe
  • %WINDIR%\Cursors\handwait.ani в %WINDIR%\Cursors\handwait.exe
  • %WINDIR%\Cursors\handns.ani в %WINDIR%\Cursors\handns.exe
  • %WINDIR%\Cursors\handnesw.ani в %WINDIR%\Cursors\handnesw.exe
  • %WINDIR%\Cursors\handno.ani в %WINDIR%\Cursors\handno.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\image2.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\image2.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\requiredBang.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\requiredBang.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\image1.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\image1.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\help.jpg в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\help.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\HelpIcon_solid.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\HelpIcon_solid.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\security_watermark.jpg в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\security_watermark.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\unSelectedTab_leftCorner.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\unSelectedTab_leftCorner.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\unSelectedTab_rightCorner.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\unSelectedTab_rightCorner.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\selectedTab_rightCorner.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\selectedTab_rightCorner.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\selectedTab_1x1.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\selectedTab_1x1.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\selectedTab_leftCorner.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\selectedTab_leftCorner.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\alert_lrg.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\alert_lrg.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\aspx_file.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\aspx_file.exe
  • %WINDIR%\Media\Windows XP Startup.wav в %WINDIR%\Media\Windows XP Startup.exe
  • %WINDIR%\Media\Windows XP Shutdown.wav в %WINDIR%\Media\Windows XP Shutdown.exe
  • %WINDIR%\Media\Windows XP Start.wav в %WINDIR%\Media\Windows XP Start.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\branding_Full2.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\branding_Full2.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\gradient_onWhite.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\gradient_onWhite.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\headerGRADIENT_Tall.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\headerGRADIENT_Tall.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\gradient_onBlue.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\gradient_onBlue.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\deselectedTab_1x1.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\deselectedTab_1x1.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\folder.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\folder.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\image2.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\image2.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\requiredBang.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\requiredBang.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\image1.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\image1.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\help.jpg в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\help.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\HelpIcon_solid.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\HelpIcon_solid.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\security_watermark.jpg в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\security_watermark.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\unSelectedTab_leftCorner.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\unSelectedTab_leftCorner.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\unSelectedTab_rightCorner.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\unSelectedTab_rightCorner.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\selectedTab_rightCorner.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\selectedTab_rightCorner.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\selectedTab_1x1.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\selectedTab_1x1.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\selectedTab_leftCorner.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\selectedTab_leftCorner.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\alert_lrg.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\alert_lrg.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\aspx_file.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\aspx_file.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\chrome\chrome.jar в %WINDIR%\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\chrome\chrome.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\yellowCORNER.gif в %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\yellowCORNER.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\logo.bmp в %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\logo.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\branding_Full2.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\branding_Full2.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\gradient_onWhite.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\gradient_onWhite.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\headerGRADIENT_Tall.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\headerGRADIENT_Tall.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\gradient_onBlue.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\gradient_onBlue.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\deselectedTab_1x1.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\deselectedTab_1x1.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\folder.gif в %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\folder.exe
  • %WINDIR%\Media\Windows XP Ringout.wav в %WINDIR%\Media\Windows XP Ringout.exe
  • %WINDIR%\Media\chord.wav в %WINDIR%\Media\chord.exe
  • %WINDIR%\Media\ding.wav в %WINDIR%\Media\ding.exe
  • %WINDIR%\Media\chimes.wav в %WINDIR%\Media\chimes.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm8.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm8.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm9.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm9.exe
  • %WINDIR%\Media\notify.wav в %WINDIR%\Media\notify.exe
  • %WINDIR%\Media\start.wav в %WINDIR%\Media\start.exe
  • %WINDIR%\Media\tada.wav в %WINDIR%\Media\tada.exe
  • %WINDIR%\Media\ringout.wav в %WINDIR%\Media\ringout.exe
  • %WINDIR%\Media\recycle.wav в %WINDIR%\Media\recycle.exe
  • %WINDIR%\Media\ringin.wav в %WINDIR%\Media\ringin.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\tplayh.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\tplayh.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm1.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm1.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\tplay.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\tplay.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\tpause.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\tpause.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\tpauseh.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\tpauseh.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm2.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm2.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm6.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm6.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm7.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm7.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm5.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm5.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm3.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm3.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm4.gif в %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\wm4.exe
  • %WINDIR%\Media\Windows XP Menu Command.wav в %WINDIR%\Media\Windows XP Menu Command.exe
  • %WINDIR%\Media\Windows XP Minimize.wav в %WINDIR%\Media\Windows XP Minimize.exe
  • %WINDIR%\Media\Windows XP Logon Sound.wav в %WINDIR%\Media\Windows XP Logon Sound.exe
  • %WINDIR%\Media\Windows XP Information Bar.wav в %WINDIR%\Media\Windows XP Information Bar.exe
  • %WINDIR%\Media\Windows XP Logoff Sound.wav в %WINDIR%\Media\Windows XP Logoff Sound.exe
  • %WINDIR%\Media\Windows XP Notify.wav в %WINDIR%\Media\Windows XP Notify.exe
  • %WINDIR%\Media\Windows XP Restore.wav в %WINDIR%\Media\Windows XP Restore.exe
  • %WINDIR%\Media\Windows XP Ringin.wav в %WINDIR%\Media\Windows XP Ringin.exe
  • %WINDIR%\Media\Windows XP Recycle.wav в %WINDIR%\Media\Windows XP Recycle.exe
  • %WINDIR%\Media\Windows XP Pop-up Blocked.wav в %WINDIR%\Media\Windows XP Pop-up Blocked.exe
  • %WINDIR%\Media\Windows XP Print complete.wav в %WINDIR%\Media\Windows XP Print complete.exe
  • %WINDIR%\Media\Windows XP Critical Stop.wav в %WINDIR%\Media\Windows XP Critical Stop.exe
  • %WINDIR%\Media\Windows XP Default.wav в %WINDIR%\Media\Windows XP Default.exe
  • %WINDIR%\Media\Windows XP Battery Low.wav в %WINDIR%\Media\Windows XP Battery Low.exe
  • %WINDIR%\Media\Windows XP Balloon.wav в %WINDIR%\Media\Windows XP Balloon.exe
  • %WINDIR%\Media\Windows XP Battery Critical.wav в %WINDIR%\Media\Windows XP Battery Critical.exe
  • %WINDIR%\Media\Windows XP Ding.wav в %WINDIR%\Media\Windows XP Ding.exe
  • %WINDIR%\Media\Windows XP Hardware Insert.wav в %WINDIR%\Media\Windows XP Hardware Insert.exe
  • %WINDIR%\Media\Windows XP Hardware Remove.wav в %WINDIR%\Media\Windows XP Hardware Remove.exe
  • %WINDIR%\Media\Windows XP Hardware Fail.wav в %WINDIR%\Media\Windows XP Hardware Fail.exe
  • %WINDIR%\Media\Windows XP Error.wav в %WINDIR%\Media\Windows XP Error.exe
  • %WINDIR%\Media\Windows XP Exclamation.wav в %WINDIR%\Media\Windows XP Exclamation.exe
Другое:
Ищет следующие окна:
  • ClassName: 'Shell_TrayWnd' WindowName: ''
  • ClassName: 'ShImgVw:CPreviewWnd' WindowName: ''

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке