Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\Hidden2.vbs
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\takefullcontrol.bat
- %HOMEPATH%\Start Menu\Programs\Startup\copytostartup.bat
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\Hidden2.vbs
- %HOMEPATH%\Start Menu\Programs\Startup\takefullcontrol.bat
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\runvirusagain.bat
- %HOMEPATH%\Start Menu\Programs\Startup\runvirusagain.bat
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\youredead.bat
- %HOMEPATH%\Start Menu\Programs\Startup\youredead.bat
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\VirusOnStartup.exe
- %HOMEPATH%\Start Menu\Programs\Startup\VirusOnStartup.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\Virus.exe
- %HOMEPATH%\Start Menu\Programs\Startup\Virus.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\msgbox.exe
- %HOMEPATH%\Start Menu\Programs\Startup\Hidden.vbs
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\copytostartup.bat
- %HOMEPATH%\Start Menu\Programs\Startup\msgbox.exe
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\Hidden.vbs
- '<Текущая директория>\msgbox.exe'
- '<Текущая директория>\msgbox.exe' /c youredead.bat
- '<Текущая директория>\Virus.exe'
- '<Текущая директория>\VirusOnStartup.exe'
- '%WINDIR%\regedit.exe'
- '<SYSTEM32>\notepad.exe'
- '<SYSTEM32>\cmd.exe' /c youredead.bat
- [<HKLM>\SOFTWARE\Microsoft\MessengerService]
- <Текущая директория>\msgbox.exe
- <Текущая директория>\runvirusagain.bat
- %TEMP%\aut7.tmp
- <Текущая директория>\msgbox.exe
- %TEMP%\aut6.tmp
- <Текущая директория>\takefullcontrol.bat
- %TEMP%\aut9.tmp
- <Текущая директория>\youredead.bat
- %TEMP%\aut8.tmp
- <Текущая директория>\VirusOnStartup.exe
- %TEMP%\aut2.tmp
- <Текущая директория>\copytostartup.bat
- %TEMP%\aut1.tmp
- <Текущая директория>\Virus.exe
- %TEMP%\aut3.tmp
- <Текущая директория>\Hidden2.vbs
- %TEMP%\aut5.tmp
- <Текущая директория>\Hidden.vbs
- %TEMP%\aut4.tmp
- %WINDIR%\$NtUninstallKB942288-v3$\reg00096
- %WINDIR%\$NtUninstallKB942288-v3$\reg00095
- %WINDIR%\$NtUninstallKB942288-v3$\reg00094
- %WINDIR%\$NtUninstallKB942288-v3$\reg00097
- %WINDIR%\$NtUninstallKB942288-v3$\reg00100
- %WINDIR%\$NtUninstallKB942288-v3$\reg00099
- %WINDIR%\$NtUninstallKB942288-v3$\reg00098
- %WINDIR%\$NtUninstallKB942288-v3$\reg00093
- %WINDIR%\$NtUninstallKB942288-v3$\reg00088
- %WINDIR%\$NtUninstallKB942288-v3$\reg00087
- %WINDIR%\$NtUninstallKB942288-v3$\reg00086
- %WINDIR%\$NtUninstallKB942288-v3$\reg00089
- %WINDIR%\$NtUninstallKB942288-v3$\reg00092
- %WINDIR%\$NtUninstallKB942288-v3$\reg00091
- %WINDIR%\$NtUninstallKB942288-v3$\reg00090
- %WINDIR%\$NtUninstallKB942288-v3$\reg00101
- %WINDIR%\$NtUninstallKB942288-v3$\reg00112
- %WINDIR%\$NtUninstallKB942288-v3$\reg00111
- %WINDIR%\$NtUninstallKB942288-v3$\reg00110
- %WINDIR%\$NtUninstallKB942288-v3$\reg00113
- %WINDIR%\$NtUninstallKB942288-v3$\reg00116
- %WINDIR%\$NtUninstallKB942288-v3$\reg00115
- %WINDIR%\$NtUninstallKB942288-v3$\reg00114
- %WINDIR%\$NtUninstallKB942288-v3$\reg00109
- %WINDIR%\$NtUninstallKB942288-v3$\reg00104
- %WINDIR%\$NtUninstallKB942288-v3$\reg00103
- %WINDIR%\$NtUninstallKB942288-v3$\reg00102
- %WINDIR%\$NtUninstallKB942288-v3$\reg00105
- %WINDIR%\$NtUninstallKB942288-v3$\reg00108
- %WINDIR%\$NtUninstallKB942288-v3$\reg00107
- %WINDIR%\$NtUninstallKB942288-v3$\reg00106
- %WINDIR%\$NtUninstallKB942288-v3$\reg00085
- %WINDIR%\$NtUninstallKB942288-v3$\reg00064
- %WINDIR%\$NtUninstallKB942288-v3$\reg00063
- %WINDIR%\$NtUninstallKB942288-v3$\reg00062
- %WINDIR%\$NtUninstallKB942288-v3$\reg00065
- %WINDIR%\$NtUninstallKB942288-v3$\reg00068
- %WINDIR%\$NtUninstallKB942288-v3$\reg00067
- %WINDIR%\$NtUninstallKB942288-v3$\reg00066
- %WINDIR%\$NtUninstallKB942288-v3$\reg00061
- %WINDIR%\$NtUninstallKB942288-v3$\reg00056
- %WINDIR%\$NtUninstallKB942288-v3$\reg00055
- %WINDIR%\$NtUninstallKB942288-v3$\reg00054
- %WINDIR%\$NtUninstallKB942288-v3$\reg00057
- %WINDIR%\$NtUninstallKB942288-v3$\reg00060
- %WINDIR%\$NtUninstallKB942288-v3$\reg00059
- %WINDIR%\$NtUninstallKB942288-v3$\reg00058
- %WINDIR%\$NtUninstallKB942288-v3$\reg00069
- %WINDIR%\$NtUninstallKB942288-v3$\reg00080
- %WINDIR%\$NtUninstallKB942288-v3$\reg00079
- %WINDIR%\$NtUninstallKB942288-v3$\reg00078
- %WINDIR%\$NtUninstallKB942288-v3$\reg00081
- %WINDIR%\$NtUninstallKB942288-v3$\reg00084
- %WINDIR%\$NtUninstallKB942288-v3$\reg00083
- %WINDIR%\$NtUninstallKB942288-v3$\reg00082
- %WINDIR%\$NtUninstallKB942288-v3$\reg00077
- %WINDIR%\$NtUninstallKB942288-v3$\reg00072
- %WINDIR%\$NtUninstallKB942288-v3$\reg00071
- %WINDIR%\$NtUninstallKB942288-v3$\reg00070
- %WINDIR%\$NtUninstallKB942288-v3$\reg00073
- %WINDIR%\$NtUninstallKB942288-v3$\reg00076
- %WINDIR%\$NtUninstallKB942288-v3$\reg00075
- %WINDIR%\$NtUninstallKB942288-v3$\reg00074
- %WINDIR%\assembly\GAC\Microsoft.Vsa\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\Microsoft.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- %WINDIR%\assembly\GAC\Microsoft.VisualC\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- %WINDIR%\assembly\GAC\Microsoft_VsaVb\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\Microsoft_VsaVb\7.0.5000.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- %WINDIR%\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\Microsoft.VisualC\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualC.dll
- %WINDIR%\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- %WINDIR%\assembly\GAC\ISymWrapper\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- %WINDIR%\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
- %WINDIR%\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\mscorcfg\1.0.5000.0__b03f5f7f11d50a3a\mscorcfg.dll
- %WINDIR%\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\System.Data.OracleClient.dll
- %WINDIR%\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Design.dll
- %WINDIR%\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- %WINDIR%\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\System.Data.dll
- %WINDIR%\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\RegCode.dll
- %WINDIR%\assembly\GAC\mscorcfg\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- %WINDIR%\assembly\GAC\System.Configuration.Install\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\System.Configuration.Install\1.0.5000.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
- %WINDIR%\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\ISymWrapper\1.0.5000.0__b03f5f7f11d50a3a\ISymWrapper.dll
- %WINDIR%\AppPatch\AcLayers.dll
- %WINDIR%\AppPatch\AcGenral.dll
- %WINDIR%\$NtUninstallWIC$\spuninst\updspapi.dll
- %WINDIR%\AppPatch\AcLua.dll
- %WINDIR%\AppPatch\apphelp.sdb
- %WINDIR%\AppPatch\AcXtrnal.dll
- %WINDIR%\AppPatch\AcSpecfc.dll
- %WINDIR%\$NtUninstallWIC$\spuninst\spuninst.txt
- %WINDIR%\$NtUninstallKB942288-v3$\spuninst\spuninst.inf
- %WINDIR%\$NtUninstallKB942288-v3$\spuninst\spuninst.exe
- %WINDIR%\$NtUninstallKB942288-v3$\reg00117
- %WINDIR%\$NtUninstallKB942288-v3$\spuninst\spuninst.txt
- %WINDIR%\$NtUninstallWIC$\spuninst\spuninst.inf
- %WINDIR%\$NtUninstallWIC$\spuninst\spuninst.exe
- %WINDIR%\$NtUninstallKB942288-v3$\spuninst\updspapi.dll
- %WINDIR%\AppPatch\apph_sp.sdb
- %WINDIR%\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\IEExecRemote.dll
- %WINDIR%\assembly\GAC\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\IEHost.dll
- %WINDIR%\assembly\GAC\IIEHost\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\IIEHost\1.0.5000.0__b03f5f7f11d50a3a\IIEHost.dll
- %WINDIR%\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a\CustomMarshalers.dll
- %WINDIR%\assembly\GAC\Accessibility\1.0.5000.0__b03f5f7f11d50a3a\Accessibility.dll
- %WINDIR%\AppPatch\msimain.sdb
- %WINDIR%\AppPatch\drvmain.sdb
- %WINDIR%\assembly\GAC\Accessibility\1.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\__AssemblyInfo__.ini
- %WINDIR%\assembly\GAC\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\cscompmgd.dll
- %WINDIR%\AppPatch\sysmain.sdb
- %WINDIR%\$NtUninstallKB942288-v3$\reg00053
- %WINDIR%\Prairie Wind.bmp
- %WINDIR%\OEWABLog.txt
- %WINDIR%\ODBCINST.INI
- %WINDIR%\regedit.exe
- %WINDIR%\Rhododendron.bmp
- %WINDIR%\regopt.log
- %WINDIR%\REGLOCS.OLD
- %WINDIR%\ocmsn.log
- %WINDIR%\netfxocm.log
- %WINDIR%\msmqinst.log
- %WINDIR%\msgsocm.log
- %WINDIR%\NOTEPAD.EXE
- %WINDIR%\ocgen.log
- %WINDIR%\ntdtcsetup.log
- %WINDIR%\nsreg.dat
- %WINDIR%\River Sumida.bmp
- %WINDIR%\sleep.exe
- %WINDIR%\sfk.exe
- %WINDIR%\setuplog.txt
- %WINDIR%\Soap Bubbles.bmp
- %WINDIR%\system.ini
- %WINDIR%\Sti_Trace.log
- %WINDIR%\spupdsvc.log
- %WINDIR%\setuperr.log
- %WINDIR%\SET3.tmp
- %WINDIR%\sessmgr.setup.log
- %WINDIR%\Santa Fe Stucco.bmp
- %WINDIR%\SET4.tmp
- %WINDIR%\setupapi.log
- %WINDIR%\setupact.log
- %WINDIR%\SET8.tmp
- %WINDIR%\msdfmap.ini
- %WINDIR%\Blue Lace 16.bmp
- %WINDIR%\0.log
- %TEMP%\aut9.tmp
- %WINDIR%\clock.avi
- %WINDIR%\COM+.log
- %WINDIR%\Coffee Bean.bmp
- %WINDIR%\cmsetacl.log
- %TEMP%\aut8.tmp
- %TEMP%\aut3.tmp
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- %TEMP%\aut4.tmp
- %TEMP%\aut7.tmp
- %TEMP%\aut6.tmp
- %TEMP%\aut5.tmp
- %WINDIR%\comsetup.log
- %WINDIR%\iis6.log
- %WINDIR%\hh.exe
- %WINDIR%\Greenstone.bmp
- %WINDIR%\imsins.BAK
- %WINDIR%\MedCtrOC.log
- %WINDIR%\KB942288-v3.log
- %WINDIR%\imsins.log
- %WINDIR%\Gone Fishing.bmp
- %WINDIR%\DtcInstall.log
- %WINDIR%\desktop.ini
- %WINDIR%\control.ini
- %WINDIR%\explorer.exe
- %WINDIR%\FeatherTexture.bmp
- %WINDIR%\FaxSetup.log
- %WINDIR%\explorer.scf
- %WINDIR%\$NtUninstallKB942288-v3$\reg00029
- %WINDIR%\$NtUninstallKB942288-v3$\reg00028
- %WINDIR%\$NtUninstallKB942288-v3$\reg00027
- %WINDIR%\$NtUninstallKB942288-v3$\reg00030
- %WINDIR%\$NtUninstallKB942288-v3$\reg00033
- %WINDIR%\$NtUninstallKB942288-v3$\reg00032
- %WINDIR%\$NtUninstallKB942288-v3$\reg00031
- %WINDIR%\$NtUninstallKB942288-v3$\reg00026
- %WINDIR%\$NtUninstallKB942288-v3$\reg00021
- %WINDIR%\$NtUninstallKB942288-v3$\reg00020
- %WINDIR%\$NtUninstallKB942288-v3$\reg00019
- %WINDIR%\$NtUninstallKB942288-v3$\reg00022
- %WINDIR%\$NtUninstallKB942288-v3$\reg00025
- %WINDIR%\$NtUninstallKB942288-v3$\reg00024
- %WINDIR%\$NtUninstallKB942288-v3$\reg00023
- %WINDIR%\$NtUninstallKB942288-v3$\reg00034
- %WINDIR%\$NtUninstallKB942288-v3$\reg00046
- %WINDIR%\$NtUninstallKB942288-v3$\reg00045
- %WINDIR%\$NtUninstallKB942288-v3$\reg00044
- %WINDIR%\$NtUninstallKB942288-v3$\reg00047
- %WINDIR%\$NtUninstallKB942288-v3$\reg00052
- %WINDIR%\$NtUninstallKB942288-v3$\reg00049
- %WINDIR%\$NtUninstallKB942288-v3$\reg00048
- %WINDIR%\$NtUninstallKB942288-v3$\reg00043
- %WINDIR%\$NtUninstallKB942288-v3$\reg00037
- %WINDIR%\$NtUninstallKB942288-v3$\reg00036
- %WINDIR%\$NtUninstallKB942288-v3$\reg00035
- %WINDIR%\$NtUninstallKB942288-v3$\reg00039
- %WINDIR%\$NtUninstallKB942288-v3$\reg00042
- %WINDIR%\$NtUninstallKB942288-v3$\reg00041
- %WINDIR%\$NtUninstallKB942288-v3$\reg00040
- %WINDIR%\$NtUninstallKB942288-v3$\reg00018
- %WINDIR%\vmmreg32.dll
- %WINDIR%\vbaddin.ini
- %WINDIR%\vb.ini
- %WINDIR%\wiadebug.log
- %WINDIR%\WindowsUpdate.log
- %WINDIR%\win.ini
- %WINDIR%\wiaservc.log
- %WINDIR%\updspapi.log
- %WINDIR%\tsoc.log
- %WINDIR%\TASKMAN.EXE
- %WINDIR%\tabletoc.log
- %WINDIR%\twain.dll
- %WINDIR%\twunk_32.exe
- %WINDIR%\twunk_16.exe
- %WINDIR%\twain_32.dll
- %WINDIR%\winhelp.exe
- %WINDIR%\$NtUninstallKB942288-v3$\reg00013
- %WINDIR%\$NtUninstallKB942288-v3$\msisip.dll
- %WINDIR%\$NtUninstallKB942288-v3$\msimsg.dll
- %WINDIR%\$NtUninstallKB942288-v3$\reg00014
- %WINDIR%\$NtUninstallKB942288-v3$\reg00017
- %WINDIR%\$NtUninstallKB942288-v3$\reg00016
- %WINDIR%\$NtUninstallKB942288-v3$\reg00015
- %WINDIR%\$NtUninstallKB942288-v3$\msihnd.dll
- %WINDIR%\WMSysPr9.prx
- %WINDIR%\wmsetup.log
- %WINDIR%\winhlp32.exe
- %WINDIR%\Zapotec.bmp
- %WINDIR%\$NtUninstallKB942288-v3$\msiexec.exe
- %WINDIR%\$NtUninstallKB942288-v3$\msi.dll
- %WINDIR%\_default.pif
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''