マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Trojan.MulDrop7.63965

Added to the Dr.Web virus database: 2018-02-19

Virus description added:

Technical Information

Modifies file system:
Creates the following files:
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Harbin
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Gaza
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Hong_Kong
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Ho_Chi_Minh
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Hovd
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Dhaka
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Damascus
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Dili
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Dushanbe
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Dubai
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Irkutsk
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Kashgar
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Karachi
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Kathmandu
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Krasnoyarsk
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Kolkata
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Jayapura
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Jakarta
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Jerusalem
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Kamchatka
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Kabul
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Amman
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Almaty
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Anadyr
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Aqtobe
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Aqtau
  • %ProgramFiles%\Java\jre6\lib\zi\Antarctica\Rothera
  • %ProgramFiles%\Java\jre6\lib\zi\Antarctica\Palmer
  • %ProgramFiles%\Java\jre6\lib\zi\Antarctica\Syowa
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Aden
  • %ProgramFiles%\Java\jre6\lib\zi\Antarctica\Vostok
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Ashgabat
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Brunei
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Bishkek
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Choibalsan
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Colombo
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Chongqing
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Bahrain
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Baghdad
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Baku
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Beirut
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Bangkok
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Kuala_Lumpur
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Tashkent
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Taipei
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Tbilisi
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Thimphu
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Tehran
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Samarkand
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Sakhalin
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Seoul
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Singapore
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Shanghai
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Tokyo
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Yerevan
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Yekaterinburg
  • %ProgramFiles%\Java\jre6\lib\zi\Atlantic\Azores
  • %ProgramFiles%\Java\jre6\lib\zi\Atlantic\Canary
  • %ProgramFiles%\Java\jre6\lib\zi\Atlantic\Bermuda
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Urumqi
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Ulaanbaatar
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Vientiane
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Yakutsk
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Vladivostok
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Muscat
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Manila
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Nicosia
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Omsk
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Novosibirsk
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Kuwait
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Kuching
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Macau
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Makassar
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Magadan
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Oral
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Riyadh
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Rangoon
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Riyadh87
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Riyadh89
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Riyadh88
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Pontianak
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Phnom_Penh
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Pyongyang
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Qyzylorda
  • %ProgramFiles%\Java\jre6\lib\zi\Asia\Qatar
  • %ProgramFiles%\Java\jre6\lib\zi\America\Mazatlan
  • %ProgramFiles%\Java\jre6\lib\zi\America\Martinique
  • %ProgramFiles%\Java\jre6\lib\zi\America\Menominee
  • %ProgramFiles%\Java\jre6\lib\zi\America\Mexico_City
  • %ProgramFiles%\Java\jre6\lib\zi\America\Merida
  • %ProgramFiles%\Java\jre6\lib\zi\America\Los_Angeles
  • %ProgramFiles%\Java\jre6\lib\zi\America\Lima
  • %ProgramFiles%\Java\jre6\lib\zi\America\Maceio
  • %ProgramFiles%\Java\jre6\lib\zi\America\Manaus
  • %ProgramFiles%\Java\jre6\lib\zi\America\Managua
  • %ProgramFiles%\Java\jre6\lib\zi\America\Miquelon
  • %ProgramFiles%\Java\jre6\lib\zi\America\New_York
  • %ProgramFiles%\Java\jre6\lib\zi\America\Nassau
  • %ProgramFiles%\Java\jre6\lib\zi\America\Nipigon
  • %ProgramFiles%\Java\jre6\lib\zi\America\Noronha
  • %ProgramFiles%\Java\jre6\lib\zi\America\Nome
  • %ProgramFiles%\Java\jre6\lib\zi\America\Monterrey
  • %ProgramFiles%\Java\jre6\lib\zi\America\Moncton
  • %ProgramFiles%\Java\jre6\lib\zi\America\Montevideo
  • %ProgramFiles%\Java\jre6\lib\zi\America\Montserrat
  • %ProgramFiles%\Java\jre6\lib\zi\America\Montreal
  • %ProgramFiles%\Java\jre6\lib\zi\America\Indiana\Indianapolis
  • %ProgramFiles%\Java\jre6\lib\zi\America\Hermosillo
  • %ProgramFiles%\Java\jre6\lib\zi\America\Indiana\Knox
  • %ProgramFiles%\Java\jre6\lib\zi\America\Indiana\Petersburg
  • %ProgramFiles%\Java\jre6\lib\zi\America\Indiana\Marengo
  • %ProgramFiles%\Java\jre6\lib\zi\America\Guayaquil
  • %ProgramFiles%\Java\jre6\lib\zi\America\Guatemala
  • %ProgramFiles%\Java\jre6\lib\zi\America\Guyana
  • %ProgramFiles%\Java\jre6\lib\zi\America\Havana
  • %ProgramFiles%\Java\jre6\lib\zi\America\Halifax
  • %ProgramFiles%\Java\jre6\lib\zi\America\Indiana\Tell_City
  • %ProgramFiles%\Java\jre6\lib\zi\America\Juneau
  • %ProgramFiles%\Java\jre6\lib\zi\America\Jamaica
  • %ProgramFiles%\Java\jre6\lib\zi\America\Kentucky\Louisville
  • %ProgramFiles%\Java\jre6\lib\zi\America\La_Paz
  • %ProgramFiles%\Java\jre6\lib\zi\America\Kentucky\Monticello
  • %ProgramFiles%\Java\jre6\lib\zi\America\Indiana\Vincennes
  • %ProgramFiles%\Java\jre6\lib\zi\America\Indiana\Vevay
  • %ProgramFiles%\Java\jre6\lib\zi\America\Indiana\Winamac
  • %ProgramFiles%\Java\jre6\lib\zi\America\Iqaluit
  • %ProgramFiles%\Java\jre6\lib\zi\America\Inuvik
  • %ProgramFiles%\Java\jre6\lib\zi\America\North_Dakota\Center
  • %ProgramFiles%\Java\jre6\lib\zi\America\Thule
  • %ProgramFiles%\Java\jre6\lib\zi\America\Tegucigalpa
  • %ProgramFiles%\Java\jre6\lib\zi\America\Thunder_Bay
  • %ProgramFiles%\Java\jre6\lib\zi\America\Toronto
  • %ProgramFiles%\Java\jre6\lib\zi\America\Tijuana
  • %ProgramFiles%\Java\jre6\lib\zi\America\St_Lucia
  • %ProgramFiles%\Java\jre6\lib\zi\America\St_Kitts
  • %ProgramFiles%\Java\jre6\lib\zi\America\St_Thomas
  • %ProgramFiles%\Java\jre6\lib\zi\America\Swift_Current
  • %ProgramFiles%\Java\jre6\lib\zi\America\St_Vincent
  • %ProgramFiles%\Java\jre6\lib\zi\America\Tortola
  • %ProgramFiles%\Java\jre6\lib\zi\Antarctica\Davis
  • %ProgramFiles%\Java\jre6\lib\zi\Antarctica\Casey
  • %ProgramFiles%\Java\jre6\lib\zi\Antarctica\DumontDUrville
  • %ProgramFiles%\Java\jre6\lib\zi\Antarctica\McMurdo
  • %ProgramFiles%\Java\jre6\lib\zi\Antarctica\Mawson
  • %ProgramFiles%\Java\jre6\lib\zi\America\Whitehorse
  • %ProgramFiles%\Java\jre6\lib\zi\America\Vancouver
  • %ProgramFiles%\Java\jre6\lib\zi\America\Winnipeg
  • %ProgramFiles%\Java\jre6\lib\zi\America\Yellowknife
  • %ProgramFiles%\Java\jre6\lib\zi\America\Yakutat
  • %ProgramFiles%\Java\jre6\lib\zi\America\Porto_Velho
  • %ProgramFiles%\Java\jre6\lib\zi\America\Port-au-Prince
  • %ProgramFiles%\Java\jre6\lib\zi\America\Port_of_Spain
  • %ProgramFiles%\Java\jre6\lib\zi\America\Rainy_River
  • %ProgramFiles%\Java\jre6\lib\zi\America\Puerto_Rico
  • %ProgramFiles%\Java\jre6\lib\zi\America\Panama
  • %ProgramFiles%\Java\jre6\lib\zi\America\North_Dakota\New_Salem
  • %ProgramFiles%\Java\jre6\lib\zi\America\Pangnirtung
  • %ProgramFiles%\Java\jre6\lib\zi\America\Phoenix
  • %ProgramFiles%\Java\jre6\lib\zi\America\Paramaribo
  • %ProgramFiles%\Java\jre6\lib\zi\America\Rankin_Inlet
  • %ProgramFiles%\Java\jre6\lib\zi\America\Santo_Domingo
  • %ProgramFiles%\Java\jre6\lib\zi\America\Santiago
  • %ProgramFiles%\Java\jre6\lib\zi\America\Sao_Paulo
  • %ProgramFiles%\Java\jre6\lib\zi\America\St_Johns
  • %ProgramFiles%\Java\jre6\lib\zi\America\Scoresbysund
  • %ProgramFiles%\Java\jre6\lib\zi\America\Regina
  • %ProgramFiles%\Java\jre6\lib\zi\America\Recife
  • %ProgramFiles%\Java\jre6\lib\zi\America\Resolute
  • %ProgramFiles%\Java\jre6\lib\zi\America\Santarem
  • %ProgramFiles%\Java\jre6\lib\zi\America\Rio_Branco
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Apia
  • %ProgramFiles%\Java\jre6\lib\zi\MST7MDT
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Auckland
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Easter
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Chatham
  • %ProgramFiles%\Java\jre6\lib\zi\Indian\Mayotte
  • %ProgramFiles%\Java\jre6\lib\zi\Indian\Mauritius
  • %ProgramFiles%\Java\jre6\lib\zi\Indian\Reunion
  • %ProgramFiles%\Java\jre6\lib\zi\MST
  • %ProgramFiles%\Java\jre6\lib\zi\MET
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Efate
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Guadalcanal
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Gambier
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Guam
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Johnston
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Honolulu
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Fakaofo
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Enderbury
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Fiji
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Galapagos
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Funafuti
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Vilnius
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Vienna
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Volgograd
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Zaporozhye
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Warsaw
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Tallinn
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Stockholm
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Tirane
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Vaduz
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Uzhgorod
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Zurich
  • %ProgramFiles%\Java\jre6\lib\zi\Indian\Comoro
  • %ProgramFiles%\Java\jre6\lib\zi\Indian\Cocos
  • %ProgramFiles%\Java\jre6\lib\zi\Indian\Kerguelen
  • %ProgramFiles%\Java\jre6\lib\zi\Indian\Maldives
  • %ProgramFiles%\Java\jre6\lib\zi\Indian\Mahe
  • %ProgramFiles%\Java\jre6\lib\zi\HST
  • %ProgramFiles%\Java\jre6\lib\zi\GMT
  • %ProgramFiles%\Java\jre6\lib\zi\Indian\Antananarivo
  • %ProgramFiles%\Java\jre6\lib\zi\Indian\Christmas
  • %ProgramFiles%\Java\jre6\lib\zi\Indian\Chagos
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Kiritimati
  • %ProgramFiles%\Java\jre6\lib\zi\SystemV\EST5
  • %ProgramFiles%\Java\jre6\lib\zi\SystemV\CST6CDT
  • %ProgramFiles%\Java\jre6\lib\zi\SystemV\EST5EDT
  • %ProgramFiles%\Java\jre6\lib\zi\SystemV\MST7
  • %ProgramFiles%\Java\jre6\lib\zi\SystemV\HST10
  • %ProgramFiles%\Java\jre6\lib\zi\PST8PDT
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Wallis
  • %ProgramFiles%\Java\jre6\lib\zi\SystemV\AST4
  • %ProgramFiles%\Java\jre6\lib\zi\SystemV\CST6
  • %ProgramFiles%\Java\jre6\lib\zi\SystemV\AST4ADT
  • %ProgramFiles%\Java\jre6\lib\zi\SystemV\MST7MDT
  • %ProgramFiles%\Java\jre6\bin\new_plugin\msvcr71.dll
  • %ProgramFiles%\Java\jre6\lib\zi\ZoneInfoMappings
  • %ProgramFiles%\Java\jre6\bin\new_plugin\npdeploytk.dll
  • %ProgramFiles%\Java\jre6\lib\rt.jar
  • %WINDIR%\Installer\MSIC.tmp
  • %ProgramFiles%\Java\jre6\lib\zi\SystemV\PST8PDT
  • %ProgramFiles%\Java\jre6\lib\zi\SystemV\PST8
  • %ProgramFiles%\Java\jre6\lib\zi\SystemV\YST9
  • %ProgramFiles%\Java\jre6\lib\zi\WET
  • %ProgramFiles%\Java\jre6\lib\zi\SystemV\YST9YDT
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Niue
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Nauru
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Norfolk
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Pago_Pago
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Noumea
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Kwajalein
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Kosrae
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Majuro
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Midway
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Marquesas
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Palau
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Tarawa
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Tahiti
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Tongatapu
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Wake
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Truk
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Ponape
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Pitcairn
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Port_Moresby
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Saipan
  • %ProgramFiles%\Java\jre6\lib\zi\Pacific\Rarotonga
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT+11
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT+10
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT+12
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT+3
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT+2
  • %ProgramFiles%\Java\jre6\lib\zi\EST
  • %ProgramFiles%\Java\jre6\lib\zi\EET
  • %ProgramFiles%\Java\jre6\lib\zi\EST5EDT
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT+1
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT+4
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT-10
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT-1
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT-11
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT-13
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT-12
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT+6
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT+5
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT+7
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT+9
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT+8
  • %ProgramFiles%\Java\jre6\lib\zi\Atlantic\St_Helena
  • %ProgramFiles%\Java\jre6\lib\zi\Atlantic\Stanley
  • %ProgramFiles%\Java\jre6\lib\zi\Australia\Adelaide
  • %ProgramFiles%\Java\jre6\lib\zi\Australia\Broken_Hill
  • %ProgramFiles%\Java\jre6\lib\zi\Australia\Brisbane
  • %ProgramFiles%\Java\jre6\lib\zi\Atlantic\Faroe
  • %ProgramFiles%\Java\jre6\lib\zi\Atlantic\Cape_Verde
  • %ProgramFiles%\Java\jre6\lib\zi\Atlantic\Madeira
  • %ProgramFiles%\Java\jre6\lib\zi\Atlantic\South_Georgia
  • %ProgramFiles%\Java\jre6\lib\zi\Atlantic\Reykjavik
  • %ProgramFiles%\Java\jre6\lib\zi\Australia\Currie
  • %ProgramFiles%\Java\jre6\lib\zi\Australia\Perth
  • %ProgramFiles%\Java\jre6\lib\zi\Australia\Melbourne
  • %ProgramFiles%\Java\jre6\lib\zi\Australia\Sydney
  • %ProgramFiles%\Java\jre6\lib\zi\CST6CDT
  • %ProgramFiles%\Java\jre6\lib\zi\CET
  • %ProgramFiles%\Java\jre6\lib\zi\Australia\Eucla
  • %ProgramFiles%\Java\jre6\lib\zi\Australia\Darwin
  • %ProgramFiles%\Java\jre6\lib\zi\Australia\Hobart
  • %ProgramFiles%\Java\jre6\lib\zi\Australia\Lord_Howe
  • %ProgramFiles%\Java\jre6\lib\zi\Australia\Lindeman
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT-14
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\London
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Lisbon
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Luxembourg
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Malta
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Madrid
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Helsinki
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Gibraltar
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Istanbul
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Kiev
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Kaliningrad
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Minsk
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Rome
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Riga
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Samara
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Sofia
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Simferopol
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Moscow
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Monaco
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Oslo
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Prague
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Paris
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT-8
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT-7
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT-9
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\UTC
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\UCT
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT-3
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT-2
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT-4
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT-6
  • %ProgramFiles%\Java\jre6\lib\zi\Etc\GMT-5
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Amsterdam
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Budapest
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Bucharest
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Chisinau
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Dublin
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Copenhagen
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Athens
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Andorra
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Belgrade
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Brussels
  • %ProgramFiles%\Java\jre6\lib\zi\Europe\Berlin
  • %ProgramFiles%\Java\jre6\lib\zi\America\Guadeloupe
  • %ProgramFiles%\Java\jre6\bin\klist.exe
  • %ProgramFiles%\Java\jre6\bin\kinit.exe
  • %ProgramFiles%\Java\jre6\bin\ktab.exe
  • %ProgramFiles%\Java\jre6\bin\mlib_image.dll
  • %ProgramFiles%\Java\jre6\bin\management.dll
  • %ProgramFiles%\Java\jre6\bin\jucheck.exe
  • %ProgramFiles%\Java\jre6\bin\jsoundds.dll
  • %ProgramFiles%\Java\jre6\bin\jureg.exe
  • %ProgramFiles%\Java\jre6\bin\keytool.exe
  • %ProgramFiles%\Java\jre6\bin\jusched.exe
  • %ProgramFiles%\Java\jre6\bin\msvcr71.dll
  • %ProgramFiles%\Java\jre6\bin\npoji610.dll
  • %ProgramFiles%\Java\jre6\bin\npjpi160_16.dll
  • %ProgramFiles%\Java\jre6\bin\npt.dll
  • %ProgramFiles%\Java\jre6\bin\pack200.exe
  • %ProgramFiles%\Java\jre6\bin\orbd.exe
  • %ProgramFiles%\Java\jre6\bin\net.dll
  • %ProgramFiles%\Java\jre6\bin\msvcrt.dll
  • %ProgramFiles%\Java\jre6\bin\new_plugin\npjp2.dll
  • %ProgramFiles%\Java\jre6\bin\npdeploytk.dll
  • %ProgramFiles%\Java\jre6\bin\nio.dll
  • %ProgramFiles%\Java\jre6\bin\jkernel.dll
  • %ProgramFiles%\Java\jre6\bin\jdwp.dll
  • %ProgramFiles%\Java\jre6\bin\jli.dll
  • %ProgramFiles%\Java\jre6\bin\jp2launcher.exe
  • %ProgramFiles%\Java\jre6\bin\jp2iexp.dll
  • %ProgramFiles%\Java\jre6\bin\java_crw_demo.dll
  • %ProgramFiles%\Java\jre6\bin\javaws.exe
  • %ProgramFiles%\Java\jre6\bin\jawt.dll
  • %ProgramFiles%\Java\jre6\bin\JdbcOdbc.dll
  • %ProgramFiles%\Java\jre6\bin\jbroker.exe
  • %ProgramFiles%\Java\jre6\bin\jp2native.dll
  • %ProgramFiles%\Java\jre6\bin\jpishare.dll
  • %ProgramFiles%\Java\jre6\bin\jpioji.dll
  • %ProgramFiles%\Java\jre6\bin\jqs.exe
  • %ProgramFiles%\Java\jre6\bin\jsound.dll
  • %ProgramFiles%\Java\jre6\bin\jqsnotify.exe
  • %ProgramFiles%\Java\jre6\bin\jpeg.dll
  • %ProgramFiles%\Java\jre6\bin\jp2ssv.dll
  • %ProgramFiles%\Java\jre6\bin\jpicom.dll
  • %ProgramFiles%\Java\jre6\bin\jpinscp.dll
  • %ProgramFiles%\Java\jre6\bin\jpiexp.dll
  • %ProgramFiles%\Java\jre6\bin\policytool.exe
  • %ProgramFiles%\Java\jre6\lib\deploy\jqs\ff\chrome\content\overlay.js
  • %ProgramFiles%\Java\jre6\lib\deploy\ffjcext.zip
  • %ProgramFiles%\Java\jre6\lib\deploy\jqs\ff\chrome\content\overlay.xul
  • %ProgramFiles%\Java\jre6\lib\deploy\jqs\ff\install.rdf
  • %ProgramFiles%\Java\jre6\lib\deploy\jqs\ff\chrome.manifest
  • %ProgramFiles%\Java\jre6\lib\cmm\LINEAR_RGB.pf
  • %ProgramFiles%\Java\jre6\lib\cmm\GRAY.pf
  • %ProgramFiles%\Java\jre6\lib\cmm\PYCC.pf
  • %ProgramFiles%\Java\jre6\lib\content-types.properties
  • %ProgramFiles%\Java\jre6\lib\cmm\sRGB.pf
  • %ProgramFiles%\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
  • %ProgramFiles%\Java\jre6\lib\deploy\messages_fr.properties
  • %ProgramFiles%\Java\jre6\lib\deploy\messages_es.properties
  • %ProgramFiles%\Java\jre6\lib\deploy\messages_it.properties
  • %ProgramFiles%\Java\jre6\lib\deploy\messages_ko.properties
  • %ProgramFiles%\Java\jre6\lib\deploy\messages_ja.properties
  • %ProgramFiles%\Java\jre6\lib\deploy\jqs\jqsmessages.properties
  • %ProgramFiles%\Java\jre6\lib\deploy\jqs\jqs.conf
  • %ProgramFiles%\Java\jre6\lib\deploy\lzma.dll
  • %ProgramFiles%\Java\jre6\lib\deploy\messages_de.properties
  • %ProgramFiles%\Java\jre6\lib\deploy\messages.properties
  • %ProgramFiles%\Java\jre6\bin\ssvagent.exe
  • %ProgramFiles%\Java\jre6\bin\ssv.dll
  • %ProgramFiles%\Java\jre6\bin\sunmscapi.dll
  • %ProgramFiles%\Java\jre6\bin\unicows.dll
  • %ProgramFiles%\Java\jre6\bin\tnameserv.exe
  • %ProgramFiles%\Java\jre6\bin\rmid.exe
  • %ProgramFiles%\Java\jre6\bin\rmi.dll
  • %ProgramFiles%\Java\jre6\bin\rmiregistry.exe
  • %ProgramFiles%\Java\jre6\bin\splashscreen.dll
  • %ProgramFiles%\Java\jre6\bin\servertool.exe
  • %ProgramFiles%\Java\jre6\bin\unpack.dll
  • %ProgramFiles%\Java\jre6\lib\calendars.properties
  • %ProgramFiles%\Java\jre6\lib\audio\soundbank.gm
  • %ProgramFiles%\Java\jre6\lib\charsets.pack
  • %ProgramFiles%\Java\jre6\lib\cmm\CIEXYZ.pf
  • %ProgramFiles%\Java\jre6\lib\classlist
  • %ProgramFiles%\Java\jre6\bin\verify.dll
  • %ProgramFiles%\Java\jre6\bin\unpack200.exe
  • %ProgramFiles%\Java\jre6\bin\w2k_lsa_auth.dll
  • %ProgramFiles%\Java\jre6\bin\zip.dll
  • %ProgramFiles%\Java\jre6\bin\wsdetect.dll
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.DATA
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING2.MAP
  • %WINDIR%\Installer\MSI2.tmp
  • %WINDIR%\Installer\MSI3.tmp
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.MAP
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.BTR
  • %TEMP%\~DF4235.tmp
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.MAP
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING1.MAP
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING.VER
  • %WINDIR%\Installer\MSI4.tmp
  • C:\Config.Msi\20038.rbs
  • %WINDIR%\Installer\MSIA.tmp
  • %ProgramFiles%\Java\jre6\zipper.exe
  • %ProgramFiles%\Java\jre6\bin\regutils.dll
  • %ProgramFiles%\Java\jre6\core.zip
  • %WINDIR%\Installer\MSI6.tmp
  • %WINDIR%\Installer\MSI5.tmp
  • %WINDIR%\Installer\MSI7.tmp
  • %WINDIR%\Installer\MSI9.tmp
  • %WINDIR%\Installer\MSI8.tmp
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20
  • %APPDATA%\Sun\Java\jre1.6.0_16\Data1.cab
  • %TEMP%\RarSFX0\java.exe
  • %APPDATA%\Sun\Java\jre1.6.0_16\jre1.6.0_16.msi
  • %WINDIR%\Installer\MSI1.tmp
  • %WINDIR%\Installer\20035.msi
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2052111302-484763869-725345543-1003
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\ComDb.Dat
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SAM
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\domain.txt
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\$WinMgmt.CFG
  • %WINDIR%\Installer\20037.ipi
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_.DEFAULT
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2052111302-484763869-725345543-1003
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SECURITY
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SYSTEM
  • C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SOFTWARE
  • %WINDIR%\Installer\20039.msi
  • %ProgramFiles%\Java\jre6\bin\eula.dll
  • %ProgramFiles%\Java\jre6\bin\dt_socket.dll
  • %ProgramFiles%\Java\jre6\bin\fontmanager.dll
  • %ProgramFiles%\Java\jre6\bin\hprof.dll
  • %ProgramFiles%\Java\jre6\bin\hpi.dll
  • %ProgramFiles%\Java\jre6\bin\dcpr.dll
  • %ProgramFiles%\Java\jre6\bin\cmm.dll
  • %ProgramFiles%\Java\jre6\bin\deploy.dll
  • %ProgramFiles%\Java\jre6\bin\dt_shmem.dll
  • %ProgramFiles%\Java\jre6\bin\deploytk.dll
  • %ProgramFiles%\Java\jre6\bin\instrument.dll
  • %ProgramFiles%\Java\jre6\bin\java.exe
  • %ProgramFiles%\Java\jre6\bin\java.dll
  • %ProgramFiles%\Java\jre6\bin\javacpl.cpl
  • %ProgramFiles%\Java\jre6\bin\javaw.exe
  • %ProgramFiles%\Java\jre6\bin\javacpl.exe
  • %ProgramFiles%\Java\jre6\bin\j2pcsc.dll
  • %ProgramFiles%\Java\jre6\bin\ioser12.dll
  • %ProgramFiles%\Java\jre6\bin\j2pkcs11.dll
  • %ProgramFiles%\Java\jre6\bin\java-rmi.exe
  • %ProgramFiles%\Java\jre6\bin\jaas_nt.dll
  • %ProgramFiles%\Java\jre6\LICENSE_es.rtf
  • %ProgramFiles%\Java\jre6\LICENSE_de.rtf
  • %ProgramFiles%\Java\jre6\LICENSE_fr.rtf
  • %ProgramFiles%\Java\jre6\LICENSE_ja.rtf
  • %ProgramFiles%\Java\jre6\LICENSE_it.rtf
  • %TEMP%\java_install.log
  • %TEMP%\java_install_reg.log
  • %ProgramFiles%\Java\jre6\COPYRIGHT
  • %ProgramFiles%\Java\jre6\LICENSE.rtf
  • %ProgramFiles%\Java\jre6\LICENSE
  • %ProgramFiles%\Java\jre6\LICENSE_ko.rtf
  • %ProgramFiles%\Java\jre6\bin\awt.dll
  • %ProgramFiles%\Java\jre6\Welcome.html
  • %ProgramFiles%\Java\jre6\bin\axbridge.dll
  • %ProgramFiles%\Java\jre6\bin\client\Xusage.txt
  • %ProgramFiles%\Java\jre6\bin\client\jvm.dll
  • %ProgramFiles%\Java\jre6\LICENSE_zh_CN.rtf
  • %ProgramFiles%\Java\jre6\LICENSE_sv.rtf
  • %ProgramFiles%\Java\jre6\LICENSE_zh_TW.rtf
  • %ProgramFiles%\Java\jre6\THIRDPARTYLICENSEREADME.txt
  • %ProgramFiles%\Java\jre6\README.txt
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Sao_Tome
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Porto-Novo
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Tripoli
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Windhoek
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Tunis
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Ndjamena
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Nairobi
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Niamey
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Ouagadougou
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Nouakchott
  • %ProgramFiles%\Java\jre6\lib\zi\America\Adak
  • %ProgramFiles%\Java\jre6\lib\zi\America\Argentina\Cordoba
  • %ProgramFiles%\Java\jre6\lib\zi\America\Argentina\Catamarca
  • %ProgramFiles%\Java\jre6\lib\zi\America\Argentina\Jujuy
  • %ProgramFiles%\Java\jre6\lib\zi\America\Argentina\Mendoza
  • %ProgramFiles%\Java\jre6\lib\zi\America\Argentina\La_Rioja
  • %ProgramFiles%\Java\jre6\lib\zi\America\Anguilla
  • %ProgramFiles%\Java\jre6\lib\zi\America\Anchorage
  • %ProgramFiles%\Java\jre6\lib\zi\America\Antigua
  • %ProgramFiles%\Java\jre6\lib\zi\America\Argentina\Buenos_Aires
  • %ProgramFiles%\Java\jre6\lib\zi\America\Araguaina
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Khartoum
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Kampala
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Kigali
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Lagos
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Kinshasa
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Freetown
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\El_Aaiun
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Gaborone
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Johannesburg
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Harare
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Libreville
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Maseru
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Maputo
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Mbabane
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Monrovia
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Mogadishu
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Luanda
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Lome
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Lubumbashi
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Malabo
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Lusaka
  • %ProgramFiles%\Java\jre6\lib\zi\America\Argentina\Rio_Gallegos
  • %ProgramFiles%\Java\jre6\lib\zi\America\Danmarkshavn
  • %ProgramFiles%\Java\jre6\lib\zi\America\Curacao
  • %ProgramFiles%\Java\jre6\lib\zi\America\Dawson
  • %ProgramFiles%\Java\jre6\lib\zi\America\Denver
  • %ProgramFiles%\Java\jre6\lib\zi\America\Dawson_Creek
  • %ProgramFiles%\Java\jre6\lib\zi\America\Chicago
  • %ProgramFiles%\Java\jre6\lib\zi\America\Cayman
  • %ProgramFiles%\Java\jre6\lib\zi\America\Chihuahua
  • %ProgramFiles%\Java\jre6\lib\zi\America\Cuiaba
  • %ProgramFiles%\Java\jre6\lib\zi\America\Costa_Rica
  • %ProgramFiles%\Java\jre6\lib\zi\America\Detroit
  • %ProgramFiles%\Java\jre6\lib\zi\America\Godthab
  • %ProgramFiles%\Java\jre6\lib\zi\America\Glace_Bay
  • %ProgramFiles%\Java\jre6\lib\zi\America\Goose_Bay
  • %ProgramFiles%\Java\jre6\lib\zi\America\Grenada
  • %ProgramFiles%\Java\jre6\lib\zi\America\Grand_Turk
  • %ProgramFiles%\Java\jre6\lib\zi\America\Edmonton
  • %ProgramFiles%\Java\jre6\lib\zi\America\Dominica
  • %ProgramFiles%\Java\jre6\lib\zi\America\Eirunepe
  • %ProgramFiles%\Java\jre6\lib\zi\America\Fortaleza
  • %ProgramFiles%\Java\jre6\lib\zi\America\El_Salvador
  • %ProgramFiles%\Java\jre6\lib\zi\America\Asuncion
  • %ProgramFiles%\Java\jre6\lib\zi\America\Aruba
  • %ProgramFiles%\Java\jre6\lib\zi\America\Atikokan
  • %ProgramFiles%\Java\jre6\lib\zi\America\Barbados
  • %ProgramFiles%\Java\jre6\lib\zi\America\Bahia
  • %ProgramFiles%\Java\jre6\lib\zi\America\Argentina\San_Juan
  • %ProgramFiles%\Java\jre6\lib\zi\America\Argentina\Salta
  • %ProgramFiles%\Java\jre6\lib\zi\America\Argentina\San_Luis
  • %ProgramFiles%\Java\jre6\lib\zi\America\Argentina\Ushuaia
  • %ProgramFiles%\Java\jre6\lib\zi\America\Argentina\Tucuman
  • %ProgramFiles%\Java\jre6\lib\zi\America\Belem
  • %ProgramFiles%\Java\jre6\lib\zi\America\Campo_Grande
  • %ProgramFiles%\Java\jre6\lib\zi\America\Cambridge_Bay
  • %ProgramFiles%\Java\jre6\lib\zi\America\Cancun
  • %ProgramFiles%\Java\jre6\lib\zi\America\Cayenne
  • %ProgramFiles%\Java\jre6\lib\zi\America\Caracas
  • %ProgramFiles%\Java\jre6\lib\zi\America\Blanc-Sablon
  • %ProgramFiles%\Java\jre6\lib\zi\America\Belize
  • %ProgramFiles%\Java\jre6\lib\zi\America\Boa_Vista
  • %ProgramFiles%\Java\jre6\lib\zi\America\Boise
  • %ProgramFiles%\Java\jre6\lib\zi\America\Bogota
  • %ProgramFiles%\Java\jre6\lib\im\thaiim.jar
  • %ProgramFiles%\Java\jre6\lib\im\indicim.jar
  • %ProgramFiles%\Java\jre6\lib\images\cursors\cursors.properties
  • %ProgramFiles%\Java\jre6\lib\images\cursors\win32_CopyDrop32x32.gif
  • %ProgramFiles%\Java\jre6\lib\images\cursors\invalid32x32.gif
  • %ProgramFiles%\Java\jre6\lib\fonts\LucidaSansRegular.ttf
  • %ProgramFiles%\Java\jre6\lib\fonts\LucidaSansDemiBold.ttf
  • %ProgramFiles%\Java\jre6\lib\fonts\LucidaTypewriterBold.ttf
  • %ProgramFiles%\Java\jre6\lib\i386\jvm.cfg
  • %ProgramFiles%\Java\jre6\lib\fonts\LucidaTypewriterRegular.ttf
  • %ProgramFiles%\Java\jre6\lib\images\cursors\win32_CopyNoDrop32x32.gif
  • %ProgramFiles%\Java\jre6\lib\jsse.pack
  • %ProgramFiles%\Java\jre6\lib\jce.jar
  • %ProgramFiles%\Java\jre6\lib\jvm.hprof.txt
  • %ProgramFiles%\Java\jre6\lib\management\jmxremote.access
  • %ProgramFiles%\Java\jre6\lib\logging.properties
  • %ProgramFiles%\Java\jre6\lib\images\cursors\win32_LinkNoDrop32x32.gif
  • %ProgramFiles%\Java\jre6\lib\images\cursors\win32_LinkDrop32x32.gif
  • %ProgramFiles%\Java\jre6\lib\images\cursors\win32_MoveDrop32x32.gif
  • %ProgramFiles%\Java\jre6\lib\javaws.pack
  • %ProgramFiles%\Java\jre6\lib\images\cursors\win32_MoveNoDrop32x32.gif
  • %ProgramFiles%\Java\jre6\lib\ext\dnsns.jar
  • %ProgramFiles%\Java\jre6\lib\deploy.pack
  • %ProgramFiles%\Java\jre6\lib\ext\localedata.pack
  • %ProgramFiles%\Java\jre6\lib\ext\sunjce_provider.jar
  • %ProgramFiles%\Java\jre6\lib\ext\meta-index
  • %ProgramFiles%\Java\jre6\lib\deploy\messages_zh_CN.properties
  • %ProgramFiles%\Java\jre6\lib\deploy\messages_sv.properties
  • %ProgramFiles%\Java\jre6\lib\deploy\messages_zh_HK.properties
  • %ProgramFiles%\Java\jre6\lib\deploy\splash.gif
  • %ProgramFiles%\Java\jre6\lib\deploy\messages_zh_TW.properties
  • %ProgramFiles%\Java\jre6\lib\ext\sunmscapi.jar
  • %ProgramFiles%\Java\jre6\lib\fonts\LucidaBrightDemiBold.ttf
  • %ProgramFiles%\Java\jre6\lib\fontconfig.properties.src
  • %ProgramFiles%\Java\jre6\lib\fonts\LucidaBrightDemiItalic.ttf
  • %ProgramFiles%\Java\jre6\lib\fonts\LucidaBrightRegular.ttf
  • %ProgramFiles%\Java\jre6\lib\fonts\LucidaBrightItalic.ttf
  • %ProgramFiles%\Java\jre6\lib\flavormap.properties
  • %ProgramFiles%\Java\jre6\lib\ext\sunpkcs11.jar
  • %ProgramFiles%\Java\jre6\lib\fontconfig.98.bfc
  • %ProgramFiles%\Java\jre6\lib\fontconfig.bfc
  • %ProgramFiles%\Java\jre6\lib\fontconfig.98.properties.src
  • %ProgramFiles%\Java\jre6\lib\management\jmxremote.password.template
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Bamako
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Asmara
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Bangui
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Bissau
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Banjul
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Abidjan
  • %ProgramFiles%\Java\jre6\lib\tzmappings
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Accra
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Algiers
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Addis_Ababa
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Blantyre
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Dakar
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Conakry
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Dar_es_Salaam
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Douala
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Djibouti
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Bujumbura
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Brazzaville
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Cairo
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Ceuta
  • %ProgramFiles%\Java\jre6\lib\zi\Africa\Casablanca
  • %ProgramFiles%\Java\jre6\lib\psfont.properties.ja
  • %ProgramFiles%\Java\jre6\lib\plugin.pack
  • %ProgramFiles%\Java\jre6\lib\psfontj2d.properties
  • %ProgramFiles%\Java\jre6\lib\rt.pack
  • %ProgramFiles%\Java\jre6\lib\resources.jar
  • %ProgramFiles%\Java\jre6\lib\management\snmp.acl.template
  • %ProgramFiles%\Java\jre6\lib\management\management.properties
  • %ProgramFiles%\Java\jre6\lib\management-agent.jar
  • %ProgramFiles%\Java\jre6\lib\net.properties
  • %ProgramFiles%\Java\jre6\lib\meta-index
  • %ProgramFiles%\Java\jre6\lib\security\blacklist
  • %ProgramFiles%\Java\jre6\lib\servicetag\jdk_header.png
  • %ProgramFiles%\Java\jre6\lib\security\US_export_policy.jar
  • %ProgramFiles%\Java\jre6\lib\sound.properties
  • %ProgramFiles%\Java\jre6\lib\task64.xml
  • %ProgramFiles%\Java\jre6\lib\task.xml
  • %ProgramFiles%\Java\jre6\lib\security\java.policy
  • %ProgramFiles%\Java\jre6\lib\security\cacerts
  • %ProgramFiles%\Java\jre6\lib\security\java.security
  • %ProgramFiles%\Java\jre6\lib\security\local_policy.jar
  • %ProgramFiles%\Java\jre6\lib\security\javaws.policy
Deletes the following files:
  • %WINDIR%\Installer\MSI8.tmp
  • %WINDIR%\Installer\MSI7.tmp
  • %WINDIR%\Installer\MSI9.tmp
  • %WINDIR%\Installer\MSIC.tmp
  • %WINDIR%\Installer\MSIA.tmp
  • %WINDIR%\Installer\MSI3.tmp
  • %WINDIR%\Installer\MSI1.tmp
  • %WINDIR%\Installer\MSI4.tmp
  • %WINDIR%\Installer\MSI6.tmp
  • %WINDIR%\Installer\MSI5.tmp
Network activity:
Connects to:
  • 'crl.verisign.com':80
  • 'csc3-2009-crl.verisign.com':80
  • 'ja##.sun.com':80
  • 'wp#d':80
TCP:
HTTP GET requests:
  • http://crl.verisign.com/pca3-g2.crl
  • http://csc3-2009-crl.verisign.com/CSC3-2009.crl
  • http://ja##.sun.com/update/1.6.0/1.6.0_16-b01.xml
  • http://11#.#11.111.2/wpad.dat via wp#d
UDP:
  • DNS ASK crl.verisign.com
  • DNS ASK csc3-2009-crl.verisign.com
  • DNS ASK ja##.sun.com
  • DNS ASK wp#d
Miscellaneous:
Searches for the following windows:
  • ClassName: 'EDIT' WindowName: ''
Creates and executes the following:
  • '%ProgramFiles%\Java\jre6\bin\unpack200.exe' -r -v -l "%TEMP%\java_install.log" "%ProgramFiles%\Java\jre6\lib\rt.pack" "%ProgramFiles%\Java\jre6\lib\rt.jar"
  • '%ProgramFiles%\Java\jre6\zipper.exe' "%ProgramFiles%\Java\jre6\core.zip" "%ProgramFiles%\Java\jre6\" "%TEMP%\java_install.log"
  • '%TEMP%\RarSFX0\java.exe' /passive
Executes the following:
  • '<SYSTEM32>\msiexec.exe' -Embedding 33960F1BD0995CFC27B7E9A48117C242
  • '<SYSTEM32>\msiexec.exe' -Embedding 1CC35946D9DB29717D54C0C1DD81C7C2 M Global\MSI0000
  • '<SYSTEM32>\msiexec.exe' /i "%APPDATA%\Sun\Java\jre1.6.0_16\jre1.6.0_16.msi" /passive
  • '<SYSTEM32>\msiexec.exe' /V

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android