Technical Information
- [<HKLM>\SOFTWARE\Classes\MSProgramGroup\Shell\Open\Command] '' = '<SYSTEM32>\grpconv.exe %1'
- %TEMP%\IXP000.TMP\jetsetup.inf
- %WINDIR%\LastGood\TMP38.tmp
- <SYSTEM32>\SET37.tmp
- <SYSTEM32>\SET36.tmp
- %WINDIR%\Temp\OLD35.tmp
- %WINDIR%\LastGood\TMP34.tmp
- <SYSTEM32>\SET33.tmp
- <SYSTEM32>\SET32.tmp
- <SYSTEM32>\SET27.tmp
- %WINDIR%\Temp\OLD31.tmp
- <SYSTEM32>\SET2F.tmp
- <SYSTEM32>\SET2E.tmp
- %WINDIR%\Temp\OLD2D.tmp
- %WINDIR%\LastGood\TMP2C.tmp
- <SYSTEM32>\SET2B.tmp
- <SYSTEM32>\SET2A.tmp
- %WINDIR%\Temp\OLD29.tmp
- %WINDIR%\LastGood\TMP30.tmp
- %WINDIR%\LastGood\TMP28.tmp
- %WINDIR%\Temp\OLD39.tmp
- %CommonProgramFiles%\Microsoft Shared\DAO\SET43.tmp
- %WINDIR%\LastGood\TMP4B.tmp
- <SYSTEM32>\SET4A.tmp
- <SYSTEM32>\SET49.tmp
- %WINDIR%\Temp\OLD48.tmp
- %WINDIR%\LastGood\TMP47.tmp
- <SYSTEM32>\SET46.tmp
- %CommonProgramFiles%\Microsoft Shared\DAO\SET45.tmp
- <SYSTEM32>\SET3B.tmp
- <SYSTEM32>\SET3A.tmp
- <SYSTEM32>\SET42.tmp
- %WINDIR%\Temp\OLD41.tmp
- %WINDIR%\LastGood\TMP40.tmp
- <SYSTEM32>\SET3F.tmp
- <SYSTEM32>\SET3E.tmp
- %WINDIR%\Temp\OLD3D.tmp
- %WINDIR%\LastGood\TMP3C.tmp
- %WINDIR%\Temp\OLD44.tmp
- <SYSTEM32>\SET26.tmp
- %WINDIR%\Temp\OLD25.tmp
- %WINDIR%\LastGood\TMP24.tmp
- %WINDIR%\Temp\OLDD.tmp
- %WINDIR%\LastGood\TMPC.tmp
- <SYSTEM32>\SETB.tmp
- <SYSTEM32>\SETA.tmp
- %WINDIR%\Temp\OLD9.tmp
- %WINDIR%\LastGood\TMP8.tmp
- <SYSTEM32>\SETF.tmp
- <SYSTEM32>\SET7.tmp
- %WINDIR%\Temp\OLD5.tmp
- %WINDIR%\LastGood\TMP4.tmp
- <SYSTEM32>\SET3.tmp
- %TEMP%\IXP000.TMP\W95INF16.DLL
- %TEMP%\IXP000.TMP\W95INF32.DLL
- %TEMP%\IXP000.TMP\ADVPACK.DLL
- %TEMP%\IXP000.TMP\jetsetup.cab
- <SYSTEM32>\SET6.tmp
- %WINDIR%\LastGood\TMP10.tmp
- <SYSTEM32>\SETE.tmp
- %WINDIR%\Temp\OLD11.tmp
- <SYSTEM32>\SET23.tmp
- <SYSTEM32>\SET1B.tmp
- <SYSTEM32>\SET22.tmp
- %WINDIR%\Temp\OLD21.tmp
- %WINDIR%\LastGood\TMP20.tmp
- <SYSTEM32>\SET1F.tmp
- <SYSTEM32>\SET1E.tmp
- %WINDIR%\Temp\OLD1D.tmp
- %WINDIR%\LastGood\TMP1C.tmp
- <SYSTEM32>\SET1A.tmp
- <SYSTEM32>\SET12.tmp
- %WINDIR%\Temp\OLD19.tmp
- %WINDIR%\LastGood\TMP18.tmp
- <SYSTEM32>\SET17.tmp
- <SYSTEM32>\SET16.tmp
- %WINDIR%\Temp\OLD15.tmp
- %WINDIR%\LastGood\TMP14.tmp
- <SYSTEM32>\SET13.tmp
- %WINDIR%\Temp\OLD4C.tmp
- <SYSTEM32>\SET4D.tmp
- <SYSTEM32>\SET6.tmp
- <SYSTEM32>\SET49.tmp
- <SYSTEM32>\SET46.tmp
- <SYSTEM32>\SET4D.tmp
- <SYSTEM32>\SET4A.tmp
- %WINDIR%\Temp\OLD4C.tmp
- %WINDIR%\Temp\OLD48.tmp
- %WINDIR%\Temp\OLD44.tmp
- %WINDIR%\Temp\OLD41.tmp
- %WINDIR%\Temp\OLD3D.tmp
- %WINDIR%\Temp\OLD39.tmp
- %WINDIR%\Temp\OLD35.tmp
- %WINDIR%\Temp\OLD31.tmp
- <SYSTEM32>\SET1F.tmp
- %WINDIR%\Temp\OLD2D.tmp
- %WINDIR%\Temp\OLD25.tmp
- %WINDIR%\Temp\OLD21.tmp
- %WINDIR%\Temp\OLD1D.tmp
- %WINDIR%\Temp\OLD19.tmp
- %WINDIR%\Temp\OLD15.tmp
- %WINDIR%\Temp\OLD11.tmp
- %WINDIR%\Temp\OLDD.tmp
- %WINDIR%\Temp\OLD9.tmp
- %WINDIR%\Temp\OLD5.tmp
- %TEMP%\IXP000.TMP\W95INF16.DLL
- %TEMP%\IXP000.TMP\W95INF32.DLL
- %TEMP%\IXP000.TMP\ADVPACK.DLL
- %CommonProgramFiles%\Microsoft Shared\DAO\SET45.tmp
- %CommonProgramFiles%\Microsoft Shared\DAO\SET43.tmp
- <SYSTEM32>\SET3F.tmp
- <SYSTEM32>\SET42.tmp
- <SYSTEM32>\SET3B.tmp
- <SYSTEM32>\SETA.tmp
- <SYSTEM32>\SET7.tmp
- <SYSTEM32>\SETE.tmp
- <SYSTEM32>\SETB.tmp
- <SYSTEM32>\SET12.tmp
- <SYSTEM32>\SETF.tmp
- <SYSTEM32>\SET16.tmp
- <SYSTEM32>\SET13.tmp
- <SYSTEM32>\SET1A.tmp
- <SYSTEM32>\SET17.tmp
- <SYSTEM32>\SET1E.tmp
- <SYSTEM32>\SET1B.tmp
- %TEMP%\IXP000.TMP\jetsetup.cab
- %WINDIR%\Temp\OLD29.tmp
- <SYSTEM32>\SET22.tmp
- <SYSTEM32>\SET23.tmp
- <SYSTEM32>\SET2A.tmp
- <SYSTEM32>\SET27.tmp
- <SYSTEM32>\SET2E.tmp
- <SYSTEM32>\SET2B.tmp
- <SYSTEM32>\SET32.tmp
- <SYSTEM32>\SET2F.tmp
- <SYSTEM32>\SET36.tmp
- <SYSTEM32>\SET33.tmp
- <SYSTEM32>\SET3A.tmp
- <SYSTEM32>\SET37.tmp
- <SYSTEM32>\SET3E.tmp
- <SYSTEM32>\SET3.tmp
- <SYSTEM32>\SET26.tmp
- %TEMP%\IXP000.TMP\jetsetup.inf
- from %WINDIR%\LastGood\TMP4.tmp to %WINDIR%\LastGood\system32\msjet40.dll
- from %WINDIR%\LastGood\TMP40.tmp to %WINDIR%\LastGood\system32\msjtes40.dll
- from %WINDIR%\LastGood\TMP3C.tmp to %WINDIR%\LastGood\system32\msxbde40.dll
- from %WINDIR%\LastGood\TMP38.tmp to %WINDIR%\LastGood\system32\mstext40.dll
- from %WINDIR%\LastGood\TMP34.tmp to %WINDIR%\LastGood\system32\mspbde40.dll
- from %WINDIR%\LastGood\TMP30.tmp to %WINDIR%\LastGood\system32\msltus40.dll
- from %WINDIR%\LastGood\TMP2C.tmp to %WINDIR%\LastGood\system32\msexch40.dll
- from %WINDIR%\LastGood\TMP28.tmp to %WINDIR%\LastGood\system32\msexcl40.dll
- from %WINDIR%\LastGood\TMP24.tmp to %WINDIR%\LastGood\system32\msjint40.dll
- from %WINDIR%\LastGood\TMP20.tmp to %WINDIR%\LastGood\system32\mswdat10.dll
- from %WINDIR%\LastGood\TMP1C.tmp to %WINDIR%\LastGood\system32\mswstr10.dll
- from %WINDIR%\LastGood\TMP18.tmp to %WINDIR%\LastGood\system32\msrepl40.dll
- from %WINDIR%\LastGood\TMP14.tmp to %WINDIR%\LastGood\system32\msrd3x40.dll
- from %WINDIR%\LastGood\TMP10.tmp to %WINDIR%\LastGood\system32\msrd2x40.dll
- from %WINDIR%\LastGood\TMPC.tmp to %WINDIR%\LastGood\system32\msjetoledb40.dll
- from %WINDIR%\LastGood\TMP8.tmp to %WINDIR%\LastGood\system32\msjter40.dll
- from %WINDIR%\LastGood\TMP47.tmp to %WINDIR%\LastGood\system32\expsrv.dll
- from %WINDIR%\LastGood\TMP4B.tmp to %WINDIR%\LastGood\system32\vbajet32.dll
- '<SYSTEM32>\grpconv.exe' -o