Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ZTEScandal.A' = '<LS_APPDATA>\svchost32.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Internet Traffic Control' = '%WINDIR%\Msinet32.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'lsass.exe' = '%HOMEPATH%\Start Menu\Programs\Startup\lsass.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Jun Lozada' = '%WINDIR%\ztescd32.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'svchost32.exe' = '<SYSTEM32>\_svchost32.exe'
- %HOMEPATH%\Start Menu\Programs\Startup\lsass.exe
- <Drive name for removable media>:\Akon - I wanna love you.exe
- <Drive name for removable media>:\Akon - Smack That.exe
- <Drive name for removable media>:\autorun.inf
- <Drive name for removable media>:\Akon - Don't Matter.exe
- <Drive name for removable media>:\ZTE Scandal.exe
- <Drive name for removable media>:\ntcdll.exe
- <Drive name for removable media>:\Akon - Sorry! Put the blame on me.exe
- hidden files
- file extensions
- Windows Task Manager (Taskmgr)
- Registry Editor (RegEdit)
- %HOMEPATH%\Start Menu\Programs\Startup\lsass.exe
- <LS_APPDATA>\svchost32.exe
- %WINDIR%\Msinet32.exe
- %WINDIR%\ztescd32.exe
- <SYSTEM32>\_svchost32.exe
- fsavgui.exe
- GUARD.EXE
- nod32.exe
- AVGCTRL.EXE
- ashAvast.exe
- avgcc.exe
- AVGCC32.EXE
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] 'NoFolderOptions' = '00000001'
- [<HKCU>\Software\Microsoft\Internet Explorer\Main] 'Window Title' = 'STOP CORRUPTION!!!'
- C:\ntcdll.exe
- C:\Akon - Sorry! Put the blame on me.exe
- %WINDIR%\details.pif
- C:\ZTE Scandal.exe
- C:\Akon - Smack That.exe
- C:\autorun.inf
- C:\Akon - Don't Matter.exe
- C:\Akon - I wanna love you.exe
- <SYSTEM32>\_svchost32.exe
- %WINDIR%\Msinet32.exe
- %WINDIR%\ztescd32.exe
- %WINDIR%\important.htm.scr
- %WINDIR%\notice.mp3.com
- %WINDIR%\news.bat
- <LS_APPDATA>\svchost32.exe
- C:\autorun.inf
- C:\ntcdll.exe
- <Drive name for removable media>:\autorun.inf
- <Drive name for removable media>:\ntcdll.exe
- <SYSTEM32>\_svchost32.exe
- %WINDIR%\ztescd32.exe
- <LS_APPDATA>\svchost32.exe
- %HOMEPATH%\Start Menu\Programs\Startup\lsass.exe
- <Drive name for removable media>:\ZTE Scandal.exe
- C:\autorun.inf
- <Drive name for removable media>:\autorun.inf
- %TEMP%\~DFD7B8.tmp
- %TEMP%\~DF4572.tmp
- %TEMP%\~DFBF43.tmp
- DNS ASK 1.#.#.#0.in-addr.arpa
- ClassName: '' WindowName: 'Error'
- ClassName: '' WindowName: 'SOCKET_WINDOW'
- ClassName: '' WindowName: 'OK'
- ClassName: '' WindowName: 'CicMarshalWndACL'
- ClassName: '' WindowName: 'Error! Cannot open file. File is corrupt.'
- ClassName: '' WindowName: '<Auxiliary name> - build Mar 22 2011'
- ClassName: '' WindowName: '<SYSTEM32>\cscript.exe'
- ClassName: '' WindowName: 'CicMarshalWndMOK'
- ClassName: '' WindowName: 'msinet32'
- ClassName: '' WindowName: 'Form1'
- ClassName: '' WindowName: 'OfficeWatson'
- ClassName: '' WindowName: 'For more information about this error,'
- ClassName: '' WindowName: 'Details'
- ClassName: '' WindowName: 'CicMarshalWndILL'
- ClassName: '' WindowName: 'CicMarshalWndABM'
- ClassName: '' WindowName: 'CicMarshalWndEPL'
- ClassName: '' WindowName: '<Auxiliary name>.exe'
- ClassName: '' WindowName: '&Close'
- ClassName: '' WindowName: 'If you were in the middle of something, the information you were working on might be lost.'
- ClassName: '' WindowName: 'De&bug'
- ClassName: '' WindowName: '<Auxiliary name>.exe has encountered a problem and needs to close. We are sorry for the inconvenience.'
- ClassName: '' WindowName: 'Start'
- ClassName: '' WindowName: 'OLEChannelWnd'
- ClassName: '' WindowName: 'Notification Area'
- ClassName: '' WindowName: 'Program Manager'
- ClassName: '' WindowName: 'Running Applications'
- ClassName: '' WindowName: 'TF_FloatingLangBar_WndTitle'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: 'CicMarshalWndADG'
- ClassName: '' WindowName: 'OleMainThreadWndName'
- ClassName: '' WindowName: 'CiceroUIWndFrame'
- ClassName: '' WindowName: 'FolderView'
- ClassName: '' WindowName: 'Show details for each &battery.'
- ClassName: '' WindowName: '&Always show icon on the taskbar.'
- ClassName: '' WindowName: 'Connections Tray'
- ClassName: '' WindowName: '<Auxiliary name>'
- ClassName: '' WindowName: 'Tiny H-Pot v1.6'
- ClassName: '' WindowName: 'CicMarshalWndEJF'
- ClassName: '' WindowName: 'CicMarshalWndIHG'
- ClassName: '' WindowName: 'MS_WebcheckMonitor'
- ClassName: '' WindowName: 'Power status'
- ClassName: '' WindowName: 'Power Meter'