Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'HKSERV.EXE' = '%PROGRAM_FILES%\Sony\HotKey Utility\HKserv.exe'
- '%CommonProgramFiles%\InstallShield\Engine\6\Intel 32\IKernel.exe' 32\IKernel.exe -Embedding
- '%CommonProgramFiles%\InstallShield\Engine\6\Intel 32\IKernel.exe' /REGSERVER
- '%TEMP%\<Virus name>\Setup.exe' -S -SMS
- '%CommonProgramFiles%\InstallShield\Engine\6\Intel 32\IKernel.exe' -RegServer
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\$WinMgmt.CFG
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.BTR
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\drivetable.txt
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP15\drivetable.txt
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\layo5228.rra
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING1.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING.VER
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SECURITY
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SOFTWARE
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_.DEFAULT
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\ComDb.Dat
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\domain.txt
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SYSTEM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SAM
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\data5247.rra
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\RestorePointSize
- %PROGRAM_FILES%\Sony\HotKey Utility\SuEv55b2.rra
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.MAP
- %PROGRAM_FILES%\Sony\HotKey Utility\HKWn5526.rra
- %PROGRAM_FILES%\Sony\HotKey Utility\LocV56cc.rra
- %PROGRAM_FILES%\Sony\HotKey Utility\Version.txt
- %PROGRAM_FILES%\Sony\HotKey Utility\HKRe55e1.rra
- %PROGRAM_FILES%\Sony\HotKey Utility\pi566e.rra
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.DATA
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\Setu52e4.rra
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING2.MAP
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\data5276.rra
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\Setup.ini
- %PROGRAM_FILES%\Sony\HotKey Utility\HKSe54e7.rra
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\Setu5332.rra
- %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\setu5361.rra
- %TEMP%\<Virus name>\~GLH0009.TMP
- %TEMP%\<Virus name>\~GLH000a.TMP
- %TEMP%\<Virus name>\~GLH0007.TMP
- %TEMP%\<Virus name>\~GLH0008.TMP
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\corebb9.rra
- %TEMP%\IEC3.tmp
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\temp.000
- %TEMP%\<Virus name>\~GLH0001.TMP
- %TEMP%\<Virus name>\~GLH0002.TMP
- %TEMP%\GLC1.tmp
- %TEMP%\<Virus name>\~GLH0000.TMP
- %TEMP%\<Virus name>\~GLH0005.TMP
- %TEMP%\<Virus name>\~GLH0006.TMP
- %TEMP%\<Virus name>\~GLH0003.TMP
- %TEMP%\<Virus name>\~GLH0004.TMP
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\ctorc55.rra
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19
- %TEMP%\<Virus name>\setup.log
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\rp.log
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20
- %CommonProgramFiles%\InstallShield\IScript\iscr13e7.rra
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\setu2106.rra
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\objeef5.rra
- %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\iusef72.rra
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\defa2329.rra
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\_IsR23f4.rra
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\valu2210.rra
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\isrt229c.rra
- %TEMP%\<Virus name>\LocVersion.txt
- %TEMP%\<Virus name>\Setup.exe
- %TEMP%\<Virus name>\ikernel.ex_
- %TEMP%\<Virus name>\layout.bin
- %TEMP%\<Virus name>\Setup.ini
- %TEMP%\<Virus name>\setup.log
- %TEMP%\GLC1.tmp
- %TEMP%\<Virus name>\setup.inx
- %TEMP%\<Virus name>\Setup.iss
- %TEMP%\<Virus name>\ESD.ini
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\default.pal
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\isrt.dll
- %TEMP%\IEC3.tmp
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\_IsRes.dll
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\value.shl
- %TEMP%\<Virus name>\data1.hdr
- %TEMP%\<Virus name>\data2.cab
- %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\setup.inx
- %TEMP%\<Virus name>\data1.cab
- from %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\data5247.rra to %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\data1.hdr
- from %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\layo5228.rra to %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\layout.bin
- from %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\Setu52e4.rra to %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\Setup.exe
- from %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\data5276.rra to %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\data1.cab
- from %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\isrt229c.rra to %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\isrt.dll
- from %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\valu2210.rra to %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\value.shl
- from %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\_IsR23f4.rra to %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\_IsRes.dll
- from %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\defa2329.rra to %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\default.pal
- from %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\Setu5332.rra to %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\Setup.ini
- from %PROGRAM_FILES%\Sony\HotKey Utility\pi566e.rra to %PROGRAM_FILES%\Sony\HotKey Utility\pi.wav
- from %PROGRAM_FILES%\Sony\HotKey Utility\HKRe55e1.rra to %PROGRAM_FILES%\Sony\HotKey Utility\HKRes.dll
- from %TEMP%\31e.rra to %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\setup.ilg
- from %PROGRAM_FILES%\Sony\HotKey Utility\LocV56cc.rra to %PROGRAM_FILES%\Sony\HotKey Utility\LocVersion.txt
- from %PROGRAM_FILES%\Sony\HotKey Utility\HKSe54e7.rra to %PROGRAM_FILES%\Sony\HotKey Utility\HKServ.exe
- from %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\setu5361.rra to %PROGRAM_FILES%\InstallShield Installation Information\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\setup.inx
- from %PROGRAM_FILES%\Sony\HotKey Utility\SuEv55b2.rra to %PROGRAM_FILES%\Sony\HotKey Utility\SuEvent.dll
- from %PROGRAM_FILES%\Sony\HotKey Utility\HKWn5526.rra to %PROGRAM_FILES%\Sony\HotKey Utility\HKWnd.exe
- from %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\setu2106.rra to %TEMP%\{BB311F54-39D6-4A03-8E18-053D1B2833D7}\setup.inx
- from %TEMP%\<Virus name>\~GLH0005.TMP to %TEMP%\<Virus name>\layout.bin
- from %TEMP%\<Virus name>\~GLH0004.TMP to %TEMP%\<Virus name>\ikernel.ex_
- from %TEMP%\<Virus name>\~GLH0007.TMP to %TEMP%\<Virus name>\Setup.exe
- from %TEMP%\<Virus name>\~GLH0006.TMP to %TEMP%\<Virus name>\LocVersion.txt
- from %TEMP%\<Virus name>\~GLH0001.TMP to %TEMP%\<Virus name>\data1.hdr
- from %TEMP%\<Virus name>\~GLH0000.TMP to %TEMP%\<Virus name>\data1.cab
- from %TEMP%\<Virus name>\~GLH0003.TMP to %TEMP%\<Virus name>\ESD.ini
- from %TEMP%\<Virus name>\~GLH0002.TMP to %TEMP%\<Virus name>\data2.cab
- from %TEMP%\<Virus name>\~GLH0008.TMP to %TEMP%\<Virus name>\Setup.ini
- from %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\objeef5.rra to %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\objectps.dll
- from %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\ctorc55.rra to %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\ctor.dll
- from %CommonProgramFiles%\InstallShield\IScript\iscr13e7.rra to %CommonProgramFiles%\InstallShield\IScript\iscript.dll
- from %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\iusef72.rra to %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\iuser.dll
- from %TEMP%\<Virus name>\~GLH000a.TMP to %TEMP%\<Virus name>\Setup.iss
- from %TEMP%\<Virus name>\~GLH0009.TMP to %TEMP%\<Virus name>\setup.inx
- from %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\corebb9.rra to %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\corecomp.ini
- from %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\temp.000 to %CommonProgramFiles%\InstallShield\Engine\6\Intel 32\IKernel.exe
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'