Technical Information
- [<HKLM>\SYSTEM\CurrentControlSet\services\SCardSvr] 'Start' = '00000002'
- [<HKLM>\SYSTEM\CurrentControlSet\services\MpsSvc] 'Start' = '00000002'
- '%WINDIR%\syswow64\taskkill.exe' /f /im Nca_v4_certd.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im eSigner.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im HTKK.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im iTaxViewer.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im FixCert.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im javacpl.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im jqs.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im jaureg.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im jucheck.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im jusched.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im jp2launcher.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im javaws.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im javaw.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im java.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im PFS.QTT2012.TOOLNHAPDKT2009.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im PFS.QTT2012.TOOLNHAP.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im CertEnrollCtrl.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im Xseo.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im UpdateWinsys.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im CheckWinSys.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im WinSys.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im WinDone.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im iexplore.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im Nca_v4.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im msiexec.exe
- '%WINDIR%\syswow64\taskkill.exe' /f /im ietabhelper.exe
- <SYSTEM32>\msiexec.exe
- iexplore.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1208' = '00000000'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1201' = '00000003'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '1201' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] '1201' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '2201' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1004' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1201' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1405' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1200' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '120B' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1402' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '120A' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1208' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '2201' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1004' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1201' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1405' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1200' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '120B' = '00000000'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '120A' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] '1209' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1209' = '00000003'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] '1A10' = '00000000'
- %TEMP%\$inst\2.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\47\is-np31v.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\47\is-h8rfa.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\48\is-4qqg7.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\48\is-iamc3.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\48\is-s7dbk.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\is-hm2eg.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\is-c7un7.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\is-eei61.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\is-9sq0d.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\is-vu9ld.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\is-s2akn.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\58\is-r3l0i.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\58\is-r3c82.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\61\is-6jpao.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\63\is-65s4e.tmp
- %ProgramFiles(x86)%\cks24h\is-b1v38.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\8\is-77eec.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\security\is-cnt9a.tmp
- %LOCALAPPDATA%low\sun\java\deployment\security\is-q6fu9.tmp
- %LOCALAPPDATA%low\sun\java\deployment\security\is-hivec.tmp
- %LOCALAPPDATA%low\sun\java\deployment\security\is-oig33.tmp
- %LOCALAPPDATA%low\sun\java\deployment\security\is-11qvr.tmp
- %LOCALAPPDATA%low\sun\java\deployment\security\is-84fpr.tmp
- %LOCALAPPDATA%low\sun\java\deployment\security\is-7hnf5.tmp
- %LOCALAPPDATA%low\sun\java\deployment\security\is-nf3pt.tmp
- %LOCALAPPDATA%low\sun\java\deployment\security\is-fi7h1.tmp
- %ProgramFiles(x86)%\cks24h\is-ds0at.tmp
- %ProgramFiles(x86)%\cks24h\is-iu3bg.tmp
- %ProgramFiles(x86)%\cks24h\is-a5tal.tmp
- %ProgramFiles(x86)%\cks24h\is-v3tjn.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\45\is-3botv.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\63\is-43vag.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\44\is-mg120.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\10\is-nlg1k.tmp
- %TEMP%\$inst\temp_0.tmp
- %ProgramFiles(x86)%\java_full\java2.exe
- %WINDIR%\temp\esignerchrometct_goc.crx
- %ProgramFiles(x86)%\java_full\del.cmd
- %ProgramFiles(x86)%\java_full\uninstall.exe
- %ProgramFiles(x86)%\java_full\uninstall.ini
- %TEMP%\is-b13qg.tmp\java2.tmp
- %TEMP%\is-434tj.tmp\_isetup\_setup64.tmp
- %ProgramFiles(x86)%\cks24h\is-bfman.tmp
- %ProgramFiles(x86)%\newca\is-dt0fj.tmp
- %LOCALAPPDATA%low\sun\java\deployment\is-njqo3.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\is-o3bjs.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\1\is-stbl4.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\10\is-6reag.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\15\is-bu6ik.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\42\is-780vn.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\18\is-hf4po.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\2\is-hp7on.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\22\is-5pprq.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\22\is-ljckh.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\22\is-kmbud.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\26\is-kann1.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\26\is-hr6md.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\30\is-ueu8e.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\30\is-glrcr.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\31\is-0vpm6.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\37\is-gho54.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\38\is-vkrh1.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\38\is-hsbip.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\42\is-o7vqt.tmp
- %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\44\is-q9q52.tmp
- %ProgramFiles(x86)%\cks24h\unins000.dat
- %TEMP%\$inst\temp_0.tmp
- %ProgramFiles(x86)%\cks24h\rootca-ssl.reg
- from %ProgramFiles(x86)%\cks24h\is-bfman.tmp to %ProgramFiles(x86)%\cks24h\unins000.exe
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\48\is-s7dbk.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\48\1f149870-685a7a12d30ff86a7f11e0b99c48f936ee8196807dbaeccc15825f89e5a7c331-6.0.lap
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\is-hm2eg.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\43f0f277-7ca26d59
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\is-c7un7.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\43f0f277-7ca26d59.idx
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\is-eei61.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\764be5b7-14a96ba7
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\is-9sq0d.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\764be5b7-14a96ba7.idx
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\is-vu9ld.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\764be5b7-32346e3f
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\is-s2akn.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\55\764be5b7-32346e3f.idx
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\58\is-r3l0i.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\58\d7b147a-479bcc78
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\58\is-r3c82.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\58\d7b147a-479bcc78.idx
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\61\is-6jpao.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\61\4ecd93fd-d8968cc8334583542f529cb42caa064e92fcf7114fc7d139a34047dbb2a4d586-6.0.lap
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\63\is-43vag.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\63\258934ff-417968d4
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\8\is-77eec.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\8\3a708f48-00487a3f02f131df680007e4308d554f16b3897ce0748491e292592b5989739f-6.0.lap
- from %ProgramFiles(x86)%\cks24h\is-v3tjn.tmp to %ProgramFiles(x86)%\cks24h\scard.reg
- from %LOCALAPPDATA%low\sun\java\deployment\cache\security\is-cnt9a.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\security\blacklist.cache
- from %LOCALAPPDATA%low\sun\java\deployment\security\is-q6fu9.tmp to %LOCALAPPDATA%low\sun\java\deployment\security\baseline.versions
- from %LOCALAPPDATA%low\sun\java\deployment\security\is-hivec.tmp to %LOCALAPPDATA%low\sun\java\deployment\security\blacklist.dynamic
- from %LOCALAPPDATA%low\sun\java\deployment\security\is-oig33.tmp to %LOCALAPPDATA%low\sun\java\deployment\security\blacklisted.certs
- from %LOCALAPPDATA%low\sun\java\deployment\security\is-11qvr.tmp to %LOCALAPPDATA%low\sun\java\deployment\security\exception.sites
- from %LOCALAPPDATA%low\sun\java\deployment\security\is-84fpr.tmp to %LOCALAPPDATA%low\sun\java\deployment\security\securitypack.jar
- from %LOCALAPPDATA%low\sun\java\deployment\security\is-7hnf5.tmp to %LOCALAPPDATA%low\sun\java\deployment\security\trusted.certs
- from %LOCALAPPDATA%low\sun\java\deployment\security\is-nf3pt.tmp to %LOCALAPPDATA%low\sun\java\deployment\security\trusted.jssecerts
- from %LOCALAPPDATA%low\sun\java\deployment\security\is-fi7h1.tmp to %LOCALAPPDATA%low\sun\java\deployment\security\update.securitypack.timestamp
- from %ProgramFiles(x86)%\cks24h\is-ds0at.tmp to %ProgramFiles(x86)%\cks24h\rootca-ssl.reg
- from %ProgramFiles(x86)%\cks24h\is-a5tal.tmp to %ProgramFiles(x86)%\cks24h\rootca-vn.reg
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\48\is-iamc3.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\48\14580f0-6504efa7.idx
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\63\is-65s4e.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\63\258934ff-417968d4.idx
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\48\is-4qqg7.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\48\14580f0-6504efa7
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\26\is-kann1.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\26\4dde2e1a-5bea50e5
- from %ProgramFiles(x86)%\newca\is-dt0fj.tmp to %ProgramFiles(x86)%\newca\fix_cks.exe
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\is-o3bjs.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\lastaccessed
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\1\is-stbl4.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\1\1ca7f41-7966d07c0d6762e55e946cf5da9d1d8a47f275a0bff67621803cbd29af6f735a-6.0.lap
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\10\is-6reag.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\10\252bdbca-417dd7b9
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\10\is-nlg1k.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\10\252bdbca-417dd7b9.idx
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\15\is-bu6ik.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\15\4939ef4f-fe9db7b5f7d4bcec136b8181504840c0da12eef98b3bb02b60e7ef0378f5bced-6.0.lap
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\18\is-hf4po.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\18\139f1052-b6ac6f9003a620e629d24a391dbe3b3a292072c409435046f56e9a74c7889910-6.0.lap
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\2\is-hp7on.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\2\4f24df82-7431105993348efa21eec4bc7022e4d08c52cdce61365b475d85db2e1222683c-6.0.lap
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\22\is-5pprq.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\22\4d69116-64f4ebd7
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\22\is-ljckh.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\22\4d69116-64f4ebd7.idx
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\22\is-kmbud.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\22\607b91d6-3f055f24d7b650fad3aa4b38687a916b11b52ebaf79c020e0ad199012d348a1b-6.0.lap
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\26\is-hr6md.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\26\4dde2e1a-5bea50e5.idx
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\47\is-np31v.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\47\322135af-47b3802dff91fc76d5272dadc467fc0fc295dd487d7e96d6591ab43a3268431c-6.0.lap
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\30\is-ueu8e.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\30\4c24d09e-559f3010
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\30\is-glrcr.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\30\4c24d09e-559f3010.idx
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\31\is-0vpm6.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\31\25d03f5f-795fa91a7bc2a3a2e9e3b5d29fd1c75a9a79f3e235827802a1219a40074e06a7-6.0.lap
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\37\is-gho54.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\37\40e4fb65-d5a6bb7bceae2217b89b6d822ed448366f21dabc58068329375e8d55c8ac8224-6.0.lap
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\38\is-vkrh1.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\38\228dec66-79cff367
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\38\is-hsbip.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\38\228dec66-79cff367.idx
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\42\is-o7vqt.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\42\348fe6a-ea2be78bc4464b66d49b53e19716e18955e78164214584fdb08052e5d3ef6328-6.0.lap
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\42\is-780vn.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\42\5b5f9bea-121d26d012ade6e85de3f9c947f71c47772ebbd4f60beca45de4db23863e0117-6.0.lap
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\44\is-q9q52.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\44\6c47e56c-3a311881
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\44\is-mg120.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\44\6c47e56c-3a311881.idx
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\45\is-3botv.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\45\6bdf78ad-98968513c94ea1d9bf7ce9bd56a3a2d061bd64093d3b7f2bba3c9505d36b41f9-6.0.lap
- from %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\47\is-h8rfa.tmp to %LOCALAPPDATA%low\sun\java\deployment\cache\6.0\47\d9566af-d22989dd8719598c4940b2c6ec2d76db9509b1518a5c22d4412b16b02fc016b1-6.0.lap
- from %ProgramFiles(x86)%\cks24h\is-b1v38.tmp to %ProgramFiles(x86)%\cks24h\wuauserv.reg
- %LOCALAPPDATA%Low\Sun\Java\Deployment\deployment.properties
- %ProgramFiles(x86)%\cks24h\rootca-ssl.reg
- 'ch###so24h.com':80
- DNS ASK ch###so24h.com
- ClassName: '' WindowName: ''
- '%ProgramFiles(x86)%\java_full\java2.exe' /silent /norestart /closeapplications
- '%TEMP%\is-b13qg.tmp\java2.tmp' /SL5="$10270,3256340,125952,%ProgramFiles(x86)%\Java_Full\Java2.exe" /silent /norestart /closeapplications
- '%WINDIR%\syswow64\taskkill.exe' /f /im msiexec.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im eSigner.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im HTKK.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im iTaxViewer.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im FixCert.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im javacpl.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im jqs.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im jaureg.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im jucheck.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im jusched.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im jp2launcher.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im javaws.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im javaw.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im java.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im PFS.QTT2012.TOOLNHAPDKT2009.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im PFS.QTT2012.TOOLNHAP.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im CertEnrollCtrl.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im Xseo.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im UpdateWinsys.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im CheckWinSys.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im WinSys.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im WinDone.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im iexplore.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im Nca_v4.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im Nca_v4_certd.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /f /im ietabhelper.exe' (with hidden window)
- '%WINDIR%\syswow64\regsvr32.exe' "<SYSTEM32>\scrrun.dll" /S' (with hidden window)
- '%WINDIR%\syswow64\regsvr32.exe' "<SYSTEM32>\scrrun.dll" /S