Technical Information
- %WINDIR%\Tasks\ Tasks.exe
- <SYSTEM32>\userinit.exe
- <SYSTEM32>\dllcache\userinit.exe
- <SYSTEM32>\7321\smss.exe
- <SYSTEM32>\7321\Virus.exe
- <SYSTEM32>\7321\services.exe
- <SYSTEM32>\shutdown.exe -r -t 10
- %WINDIR%\explorer.exe
- <SYSTEM32>\dllcache\userinit.exe
- %HOMEPATH%\Desktop\ Desktop.exe
- %HOMEPATH%\Cookies\ Cookies.exe
- %HOMEPATH%\Favorites\ Favorites.exe
- %HOMEPATH%\My Documents\ My Documents.exe
- %HOMEPATH%\Local Settings\ Local Settings.exe
- C:\Documents and Settings\NetworkService\Application Data\ Application Data.exe
- C:\Documents and Settings\LocalService\Local Settings\ Local Settings.exe
- C:\Documents and Settings\NetworkService\Cookies\ Cookies.exe
- %APPDATA%\ Application Data.exe
- C:\Documents and Settings\NetworkService\Local Settings\ Local Settings.exe
- C:\Far2\Addons\Colors\ Colors.exe
- %HOMEPATH%\Templates\ Templates.exe
- C:\Far2\Addons\Macros\ Macros.exe
- C:\Far2\Addons\Shell\ Shell.exe
- C:\Far2\Addons\SetUp\ SetUp.exe
- %HOMEPATH%\PrintHood\ PrintHood.exe
- %HOMEPATH%\NetHood\ NetHood.exe
- %HOMEPATH%\Recent\ Recent.exe
- %HOMEPATH%\Start Menu\ Start Menu.exe
- %HOMEPATH%\SendTo\ SendTo.exe
- C:\Documents and Settings\Default User\Application Data\ Application Data.exe
- %ALLUSERSPROFILE%\Templates\ Templates.exe
- C:\Documents and Settings\Default User\Cookies\ Cookies.exe
- C:\Documents and Settings\Default User\Favorites\ Favorites.exe
- C:\Documents and Settings\Default User\Desktop\ Desktop.exe
- %ALLUSERSPROFILE%\Documents\ Documents.exe
- %ALLUSERSPROFILE%\Desktop\ Desktop.exe
- %ALLUSERSPROFILE%\DRM\ DRM.exe
- %ALLUSERSPROFILE%\Start Menu\ Start Menu.exe
- %ALLUSERSPROFILE%\Favorites\ Favorites.exe
- C:\Documents and Settings\Default User\Start Menu\ Start Menu.exe
- C:\Documents and Settings\Default User\SendTo\ SendTo.exe
- C:\Documents and Settings\Default User\Templates\ Templates.exe
- C:\Documents and Settings\LocalService\Cookies\ Cookies.exe
- C:\Documents and Settings\LocalService\Application Data\ Application Data.exe
- C:\Documents and Settings\Default User\My Documents\ My Documents.exe
- C:\Documents and Settings\Default User\Local Settings\ Local Settings.exe
- C:\Documents and Settings\Default User\NetHood\ NetHood.exe
- C:\Documents and Settings\Default User\Recent\ Recent.exe
- C:\Documents and Settings\Default User\PrintHood\ PrintHood.exe
- C:\Far2\Addons\XLat\ XLat.exe
- %CommonProgramFiles%\ODBC\ ODBC.exe
- %CommonProgramFiles%\MSSoap\ MSSoap.exe
- %CommonProgramFiles%\Services\ Services.exe
- %CommonProgramFiles%\System\ System.exe
- %CommonProgramFiles%\SpeechEngines\ SpeechEngines.exe
- C:\Far2\Plugins\WinSCP\ WinSCP.exe
- C:\Far2\Plugins\TmpPanel\ TmpPanel.exe
- C:\Far2\PluginSDK\Headers.c\ Headers.c.exe
- %CommonProgramFiles%\Microsoft Shared\ Microsoft Shared.exe
- C:\Far2\PluginSDK\Headers.pas\ Headers.pas.exe
- %PROGRAM_FILES%\FireFox\plugins\ plugins.exe
- %PROGRAM_FILES%\FireFox\modules\ modules.exe
- %PROGRAM_FILES%\FireFox\res\ res.exe
- %PROGRAM_FILES%\FireFox\uninstall\ uninstall.exe
- %PROGRAM_FILES%\FireFox\searchplugins\ searchplugins.exe
- %PROGRAM_FILES%\FireFox\components\ components.exe
- %PROGRAM_FILES%\FireFox\chrome\ chrome.exe
- %PROGRAM_FILES%\FireFox\defaults\ defaults.exe
- %PROGRAM_FILES%\FireFox\extensions\ extensions.exe
- %PROGRAM_FILES%\FireFox\dictionaries\ dictionaries.exe
- C:\Far2\Plugins\Brackets\ Brackets.exe
- C:\Far2\Plugins\AutoWrap\ AutoWrap.exe
- C:\Far2\Plugins\Colorer\ Colorer.exe
- C:\Far2\Plugins\DrawLine\ DrawLine.exe
- C:\Far2\Plugins\Compare\ Compare.exe
- C:\Far2\Documentation\rus\ rus.exe
- C:\Far2\Documentation\eng\ eng.exe
- C:\Far2\Plugins\7-Zip\ 7-Zip.exe
- C:\Far2\Plugins\arclite\ arclite.exe
- C:\Far2\Plugins\Align\ Align.exe
- C:\Far2\Plugins\HlfViewer\ HlfViewer.exe
- C:\Far2\Plugins\FTP\ FTP.exe
- C:\Far2\Plugins\MacroView\ MacroView.exe
- C:\Far2\Plugins\ProcList\ ProcList.exe
- C:\Far2\Plugins\Network\ Network.exe
- C:\Far2\Plugins\EMenu\ EMenu.exe
- C:\Far2\Plugins\EditCase\ EditCase.exe
- C:\Far2\Plugins\ExtSearch\ ExtSearch.exe
- C:\Far2\Plugins\FileCase\ FileCase.exe
- C:\Far2\Plugins\FarCmds\ FarCmds.exe
- %ALLUSERSPROFILE%\Application Data\ Application Data.exe
- %PROGRAM_FILES%\MSN\ MSN.exe
- %PROGRAM_FILES%\MSBuild\ MSBuild.exe
- %PROGRAM_FILES%\MSN Gaming Zone\ MSN Gaming Zone.exe
- %PROGRAM_FILES%\Online Services\ Online Services.exe
- %PROGRAM_FILES%\NetMeeting\ NetMeeting.exe
- %PROGRAM_FILES%\Messenger\ Messenger.exe
- %PROGRAM_FILES%\Internet Explorer\ Internet Explorer.exe
- %PROGRAM_FILES%\microsoft frontpage\ microsoft frontpage.exe
- %PROGRAM_FILES%\Movie Maker\ Movie Maker.exe
- %PROGRAM_FILES%\Microsoft.NET\ Microsoft.NET.exe
- %PROGRAM_FILES%\xerox\ xerox.exe
- %PROGRAM_FILES%\WindowsUpdate\ WindowsUpdate.exe
- C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\ S-1-5-21-2052111302-484763869-725345543-1003.exe
- %WINDIR%\$NtUninstallKB942288-v3$\ $NtUninstallKB942288-v3$.exe
- <Auxiliary element>
- %PROGRAM_FILES%\Reference Assemblies\ Reference Assemblies.exe
- %PROGRAM_FILES%\Outlook Express\ Outlook Express.exe
- %PROGRAM_FILES%\Uninstall Information\ Uninstall Information.exe
- %PROGRAM_FILES%\Windows NT\ Windows NT.exe
- %PROGRAM_FILES%\Windows Media Player\ Windows Media Player.exe
- %ALLUSERSPROFILE%\ All Users.exe
- <SYSTEM32>\dllcache\file.txt
- C:\Documents and Settings\Default User\ Default User.exe
- C:\Documents and Settings\NetworkService\ NetworkService.exe
- C:\Documents and Settings\LocalService\ LocalService.exe
- <SYSTEM32>\7321\Virus.exe
- <SYSTEM32>\7321\smss.exe
- <SYSTEM32>\7321\system
- <SYSTEM32>\7321\services.exe
- C:\Far2\PluginSDK\ PluginSDK.exe
- C:\Far2\Plugins\ Plugins.exe
- %CommonProgramFiles%\ Common Files.exe
- %PROGRAM_FILES%\FireFox\ FireFox.exe
- %PROGRAM_FILES%\ComPlus Applications\ ComPlus Applications.exe
- C:\Far2\Addons\ Addons.exe
- %HOMEPATH%\ %USERNAME%.exe
- C:\Far2\Documentation\ Documentation.exe
- C:\Far2\FExcept\ FExcept.exe
- C:\Far2\Encyclopedia\ Encyclopedia.exe
- %WINDIR%\$NtUninstallWIC$\ $NtUninstallWIC$.exe
- %WINDIR%\Provisioning\ Provisioning.exe
- %WINDIR%\Prefetch\ Prefetch.exe
- %WINDIR%\pss\ pss.exe
- %WINDIR%\repair\ repair.exe
- %WINDIR%\Registration\ Registration.exe
- %WINDIR%\ocx\ ocx.exe
- %WINDIR%\mui\ mui.exe
- %WINDIR%\Offline Web Pages\ Offline Web Pages.exe
- %WINDIR%\PeerNet\ PeerNet.exe
- %WINDIR%\pchealth\ pchealth.exe
- %WINDIR%\Temp\ Temp.exe
- <SYSTEM32>\ system32.exe
- %WINDIR%\twain_32\ twain_32.exe
- %WINDIR%\WinSxS\ WinSxS.exe
- %WINDIR%\Web\ Web.exe
- %WINDIR%\security\ security.exe
- %WINDIR%\Resources\ Resources.exe
- %WINDIR%\SoftwareDistribution\ SoftwareDistribution.exe
- %WINDIR%\system\ system.exe
- %WINDIR%\srchasst\ srchasst.exe
- %WINDIR%\Debug\ Debug.exe
- %WINDIR%\Cursors\ Cursors.exe
- %WINDIR%\Downloaded Program Files\ Downloaded Program Files.exe
- %WINDIR%\ehome\ ehome.exe
- %WINDIR%\Driver Cache\ Driver Cache.exe
- %WINDIR%\AppPatch\ AppPatch.exe
- %WINDIR%\addins\ addins.exe
- %WINDIR%\assembly\ assembly.exe
- %WINDIR%\Connection Wizard\ Connection Wizard.exe
- %WINDIR%\Config\ Config.exe
- %WINDIR%\Media\ Media.exe
- %WINDIR%\java\ java.exe
- %WINDIR%\Microsoft.NET\ Microsoft.NET.exe
- %WINDIR%\msapps\ msapps.exe
- %WINDIR%\msagent\ msagent.exe
- %WINDIR%\Help\ Help.exe
- %WINDIR%\Fonts\ Fonts.exe
- %WINDIR%\ime\ ime.exe
- %WINDIR%\Installer\ Installer.exe
- %WINDIR%\inf\ inf.exe
- <SYSTEM32>\7321\Virus.exe
- %TEMP%\~DFCB33.tmp
- %TEMP%\~DFB985.tmp
- ClassName: '' WindowName: 'smss'
- ClassName: '' WindowName: ''
- ClassName: '' WindowName: 'services'
- ClassName: '' WindowName: '<Virus name>'
- ClassName: '' WindowName: 'userinit'