Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'HKSERV.EXE' = '%PROGRAM_FILES%\Sony\HotKey Utility\HKserv.exe'
- '%CommonProgramFiles%\InstallShield\Engine\6\Intel 32\IKernel.exe' 32\IKernel.exe -Embedding
- '%CommonProgramFiles%\InstallShield\Engine\6\Intel 32\IKernel.exe' /REGSERVER
- '%TEMP%\<Имя вируса>\Setup.exe' -S -SMS
- '%CommonProgramFiles%\InstallShield\Engine\6\Intel 32\IKernel.exe' -RegServer
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\$WinMgmt.CFG
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.BTR
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\drivetable.txt
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP15\drivetable.txt
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\layo5228.rra
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING1.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING.VER
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SECURITY
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SOFTWARE
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_.DEFAULT
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\ComDb.Dat
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\domain.txt
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SYSTEM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SAM
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\data5247.rra
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\RestorePointSize
- %PROGRAM_FILES%\Sony\HotKey Utility\SuEv55b2.rra
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.MAP
- %PROGRAM_FILES%\Sony\HotKey Utility\HKWn5526.rra
- %PROGRAM_FILES%\Sony\HotKey Utility\LocV56cc.rra
- %PROGRAM_FILES%\Sony\HotKey Utility\Version.txt
- %PROGRAM_FILES%\Sony\HotKey Utility\HKRe55e1.rra
- %PROGRAM_FILES%\Sony\HotKey Utility\pi566e.rra
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.DATA
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\Setu52e4.rra
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING2.MAP
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\data5276.rra
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\Setup.ini
- %PROGRAM_FILES%\Sony\HotKey Utility\HKSe54e7.rra
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\Setu5332.rra
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\setu5361.rra
- %TEMP%\<Имя вируса>\~GLH0009.TMP
- %TEMP%\<Имя вируса>\~GLH000a.TMP
- %TEMP%\<Имя вируса>\~GLH0007.TMP
- %TEMP%\<Имя вируса>\~GLH0008.TMP
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\corebb9.rra
- %TEMP%\IEC3.tmp
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\temp.000
- %TEMP%\<Имя вируса>\~GLH0001.TMP
- %TEMP%\<Имя вируса>\~GLH0002.TMP
- %TEMP%\GLC1.tmp
- %TEMP%\<Имя вируса>\~GLH0000.TMP
- %TEMP%\<Имя вируса>\~GLH0005.TMP
- %TEMP%\<Имя вируса>\~GLH0006.TMP
- %TEMP%\<Имя вируса>\~GLH0003.TMP
- %TEMP%\<Имя вируса>\~GLH0004.TMP
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\ctorc55.rra
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19
- %TEMP%\<Имя вируса>\setup.log
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\rp.log
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20
- %CommonProgramFiles%\InstallShield\IScript\iscr13e7.rra
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\setu2106.rra
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\objeef5.rra
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\iusef72.rra
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\defa2329.rra
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\_IsR23f4.rra
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\valu2210.rra
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\isrt229c.rra
- %TEMP%\<Имя вируса>\LocVersion.txt
- %TEMP%\<Имя вируса>\Setup.exe
- %TEMP%\<Имя вируса>\ikernel.ex_
- %TEMP%\<Имя вируса>\layout.bin
- %TEMP%\<Имя вируса>\Setup.ini
- %TEMP%\<Имя вируса>\setup.log
- %TEMP%\GLC1.tmp
- %TEMP%\<Имя вируса>\setup.inx
- %TEMP%\<Имя вируса>\Setup.iss
- %TEMP%\<Имя вируса>\ESD.ini
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\default.pal
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\isrt.dll
- %TEMP%\IEC3.tmp
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\_IsRes.dll
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\value.shl
- %TEMP%\<Имя вируса>\data1.hdr
- %TEMP%\<Имя вируса>\data2.cab
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\setup.inx
- %TEMP%\<Имя вируса>\data1.cab
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\data5247.rra в %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\data1.hdr
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\layo5228.rra в %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\layout.bin
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\Setu52e4.rra в %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\Setup.exe
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\data5276.rra в %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\data1.cab
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\isrt229c.rra в %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\isrt.dll
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\valu2210.rra в %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\value.shl
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\_IsR23f4.rra в %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\_IsRes.dll
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\defa2329.rra в %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\default.pal
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\Setu5332.rra в %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\Setup.ini
- %PROGRAM_FILES%\Sony\HotKey Utility\pi566e.rra в %PROGRAM_FILES%\Sony\HotKey Utility\pi.wav
- %PROGRAM_FILES%\Sony\HotKey Utility\HKRe55e1.rra в %PROGRAM_FILES%\Sony\HotKey Utility\HKRes.dll
- %TEMP%\31e.rra в %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\setup.ilg
- %PROGRAM_FILES%\Sony\HotKey Utility\LocV56cc.rra в %PROGRAM_FILES%\Sony\HotKey Utility\LocVersion.txt
- %PROGRAM_FILES%\Sony\HotKey Utility\HKSe54e7.rra в %PROGRAM_FILES%\Sony\HotKey Utility\HKServ.exe
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\setu5361.rra в %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\setup.inx
- %PROGRAM_FILES%\Sony\HotKey Utility\SuEv55b2.rra в %PROGRAM_FILES%\Sony\HotKey Utility\SuEvent.dll
- %PROGRAM_FILES%\Sony\HotKey Utility\HKWn5526.rra в %PROGRAM_FILES%\Sony\HotKey Utility\HKWnd.exe
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\setu2106.rra в %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\setup.inx
- %TEMP%\<Имя вируса>\~GLH0005.TMP в %TEMP%\<Имя вируса>\layout.bin
- %TEMP%\<Имя вируса>\~GLH0004.TMP в %TEMP%\<Имя вируса>\ikernel.ex_
- %TEMP%\<Имя вируса>\~GLH0007.TMP в %TEMP%\<Имя вируса>\Setup.exe
- %TEMP%\<Имя вируса>\~GLH0006.TMP в %TEMP%\<Имя вируса>\LocVersion.txt
- %TEMP%\<Имя вируса>\~GLH0001.TMP в %TEMP%\<Имя вируса>\data1.hdr
- %TEMP%\<Имя вируса>\~GLH0000.TMP в %TEMP%\<Имя вируса>\data1.cab
- %TEMP%\<Имя вируса>\~GLH0003.TMP в %TEMP%\<Имя вируса>\ESD.ini
- %TEMP%\<Имя вируса>\~GLH0002.TMP в %TEMP%\<Имя вируса>\data2.cab
- %TEMP%\<Имя вируса>\~GLH0008.TMP в %TEMP%\<Имя вируса>\Setup.ini
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\objeef5.rra в %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\objectps.dll
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\ctorc55.rra в %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\ctor.dll
- %CommonProgramFiles%\InstallShield\IScript\iscr13e7.rra в %CommonProgramFiles%\InstallShield\IScript\iscript.dll
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\iusef72.rra в %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\iuser.dll
- %TEMP%\<Имя вируса>\~GLH000a.TMP в %TEMP%\<Имя вируса>\Setup.iss
- %TEMP%\<Имя вируса>\~GLH0009.TMP в %TEMP%\<Имя вируса>\setup.inx
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\corebb9.rra в %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\corecomp.ini
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\temp.000 в %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\IKernel.exe
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'