Technical Information
- <SYSTEM32>\dllcache\regedit.exe with <SYSTEM32>\dllcache\regedit.exe.new
- <SYSTEM32>\dllcache\taskman.exe with <SYSTEM32>\dllcache\taskman.exe.new
- <SYSTEM32>\dllcache\hh.exe with <SYSTEM32>\dllcache\hh.exe.new
- <SYSTEM32>\dllcache\notepad.exe with <SYSTEM32>\dllcache\notepad.exe.new
- <SYSTEM32>\dllcache\vmmreg32.dll with <SYSTEM32>\dllcache\vmmreg32.dll.new
- <SYSTEM32>\dllcache\winhlp32.exe with <SYSTEM32>\dllcache\winhlp32.exe.new
- <SYSTEM32>\dllcache\twain_32.dll with <SYSTEM32>\dllcache\twain_32.dll.new
- <SYSTEM32>\dllcache\twunk_32.exe with <SYSTEM32>\dllcache\twunk_32.exe.new
- %WINDIR%\regedit.exe with %WINDIR%\regedit.exe.new
- %WINDIR%\TASKMAN.EXE with %WINDIR%\taskman.exe.new
- %WINDIR%\hh.exe with %WINDIR%\hh.exe.new
- %WINDIR%\NOTEPAD.EXE with %WINDIR%\notepad.exe.new
- %WINDIR%\vmmreg32.dll with %WINDIR%\vmmreg32.dll.new
- %WINDIR%\winhlp32.exe with %WINDIR%\winhlp32.exe.new
- %WINDIR%\twain_32.dll with %WINDIR%\twain_32.dll.new
- %WINDIR%\twunk_32.exe with %WINDIR%\twunk_32.exe.new
- <SYSTEM32>\dllcache\twunk_32.exe.new
- <SYSTEM32>\dllcache\twain_32.dll.new
- <SYSTEM32>\dllcache\winhlp32.exe.new
- <SYSTEM32>\dllcache\vmmreg32.dll.new
- <SYSTEM32>\dllcache\notepad.exe.new
- <SYSTEM32>\dllcache\hh.exe.new
- <SYSTEM32>\dllcache\taskman.exe.new
- <SYSTEM32>\dllcache\regedit.exe.new
- '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\KasperskyLab\LicStorage /f
- '<SYSTEM32>\taskkill.exe' /im /f safari.exe
- '<SYSTEM32>\reg.exe' delete HKLM\SOFTWARE\Microsoft\SystemCertificates\SPC /f
- '<SYSTEM32>\rundll32.exe' mouse,disable
- '<SYSTEM32>\attrib.exe' -r -s hosts
- '<SYSTEM32>\taskkill.exe' /im /f chrome.exe
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\Build.bat""
- '<SYSTEM32>\taskkill.exe' /im /f ie.exe
- '<SYSTEM32>\taskkill.exe' /im /f opera.exe
- '<SYSTEM32>\taskkill.exe' /im /f firefox.exe
- %TEMP%\1.tmp\Build.bat
- %WINDIR%\sleep.exe
- %WINDIR%\Soap Bubbles.bmp
- %WINDIR%\setuplog.txt
- %WINDIR%\sfk.exe
- %WINDIR%\spupdsvc.log
- %WINDIR%\tabletoc.log
- %WINDIR%\TASKMAN.EXE
- %WINDIR%\Sti_Trace.log
- %WINDIR%\system.ini
- %WINDIR%\sessmgr.setup.log
- %WINDIR%\SET3.tmp
- %WINDIR%\River Sumida.bmp
- %WINDIR%\Santa Fe Stucco.bmp
- %WINDIR%\SET4.tmp
- %WINDIR%\setupapi.log
- %WINDIR%\setuperr.log
- %WINDIR%\SET8.tmp
- %WINDIR%\setupact.log
- %WINDIR%\tsoc.log
- %WINDIR%\WindowsUpdate.log
- %WINDIR%\winhelp.exe
- %WINDIR%\wiaservc.log
- %WINDIR%\win.ini
- %WINDIR%\winhlp32.exe
- %WINDIR%\Zapotec.bmp
- %WINDIR%\_default.pif
- %WINDIR%\wmsetup.log
- %WINDIR%\WMSysPr9.prx
- %WINDIR%\twunk_16.exe
- %WINDIR%\twunk_32.exe
- %WINDIR%\twain.dll
- %WINDIR%\twain_32.dll
- %WINDIR%\updspapi.log
- %WINDIR%\vmmreg32.dll
- %WINDIR%\wiadebug.log
- %WINDIR%\vb.ini
- %WINDIR%\vbaddin.ini
- %WINDIR%\Rhododendron.bmp
- %WINDIR%\explorer.scf
- %WINDIR%\FaxSetup.log
- %WINDIR%\DtcInstall.log
- %WINDIR%\explorer.exe
- %WINDIR%\FeatherTexture.bmp
- %WINDIR%\hh.exe
- %WINDIR%\iis6.log
- %WINDIR%\Gone Fishing.bmp
- %WINDIR%\Greenstone.bmp
- %WINDIR%\clock.avi
- %WINDIR%\cmsetacl.log
- %WINDIR%\0.log
- %WINDIR%\Blue Lace 16.bmp
- %WINDIR%\Coffee Bean.bmp
- %WINDIR%\control.ini
- %WINDIR%\desktop.ini
- %WINDIR%\COM+.log
- %WINDIR%\comsetup.log
- %WINDIR%\imsins.BAK
- %WINDIR%\ocmsn.log
- %WINDIR%\ODBCINST.INI
- %WINDIR%\ntdtcsetup.log
- %WINDIR%\ocgen.log
- %WINDIR%\OEWABLog.txt
- %WINDIR%\REGLOCS.OLD
- %WINDIR%\regopt.log
- %WINDIR%\Prairie Wind.bmp
- %WINDIR%\regedit.exe
- %WINDIR%\MedCtrOC.log
- %WINDIR%\msdfmap.ini
- %WINDIR%\imsins.log
- %WINDIR%\KB942288-v3.log
- %WINDIR%\msgsocm.log
- %WINDIR%\NOTEPAD.EXE
- %WINDIR%\nsreg.dat
- %WINDIR%\msmqinst.log
- %WINDIR%\netfxocm.log
- from <SYSTEM32>\dllcache\twunk_32.exe.new to <SYSTEM32>\dllcache\twunk_32.exe
- from <SYSTEM32>\dllcache\twunk_16.exe.new to <SYSTEM32>\dllcache\twunk_16.exe
- from <SYSTEM32>\dllcache\vmmreg32.dll.new to <SYSTEM32>\dllcache\vmmreg32.dll
- from <SYSTEM32>\dllcache\winhlp32.exe.new to <SYSTEM32>\dllcache\winhlp32.exe
- from <SYSTEM32>\dllcache\winhelp.exe.new to <SYSTEM32>\dllcache\winhelp.exe
- from <SYSTEM32>\dllcache\twain_32.dll.new to <SYSTEM32>\dllcache\twain_32.dll
- from <SYSTEM32>\dllcache\notepad.exe.new to <SYSTEM32>\dllcache\notepad.exe
- from <SYSTEM32>\dllcache\hh.exe.new to <SYSTEM32>\dllcache\hh.exe
- from <SYSTEM32>\dllcache\regedit.exe.new to <SYSTEM32>\dllcache\regedit.exe
- from <SYSTEM32>\dllcache\twain.dll.new to <SYSTEM32>\dllcache\twain.dll
- from <SYSTEM32>\dllcache\taskman.exe.new to <SYSTEM32>\dllcache\taskman.exe
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'