Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'RihsNek' = '<SYSTEM32>\RihsNek.exe'
- hidden files
- file extensions
- Windows Task Manager (Taskmgr)
- Registry Editor (RegEdit)
- ecmd.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFind' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '00000001'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] 'NoFolderOptions' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRun' = '00000001'
- [<HKCU>\Software\Microsoft\Internet Explorer\Main] 'Window Title' = '[ Mas UNFAIR yung: COMPLETE attendance nga, WALA namang ALAM ]'
- [<HKLM>\SOFTWARE\Microsoft\Internet Explorer\Main] 'Window Title' = '[ Mas UNFAIR yung: COMPLETE attendance nga, WALA namang ALAM ]'
- C:\Documents and Settings\LocalService\Cookies.exe
- C:\Documents and Settings\LocalService\Application Data\Unfair kanu shet.RTF
- C:\Documents and Settings\LocalService\Cookies\143anYer.exe
- C:\Documents and Settings\LocalService\Local Settings.exe
- C:\Documents and Settings\LocalService\Cookies\Unfair kanu shet.RTF
- C:\Documents and Settings\Default User\Templates\143anYer.exe
- C:\Documents and Settings\Default User\Templates.exe
- C:\Documents and Settings\Default User\Templates\Unfair kanu shet.RTF
- C:\Documents and Settings\LocalService\Application Data\143anYer.exe
- C:\Documents and Settings\LocalService\Application Data.exe
- C:\Documents and Settings\NetworkService\Cookies\143anYer.exe
- C:\Documents and Settings\NetworkService\Cookies.exe
- C:\Documents and Settings\NetworkService\Cookies\Unfair kanu shet.RTF
- C:\Documents and Settings\NetworkService\Local Settings\143anYer.exe
- C:\Documents and Settings\NetworkService\Local Settings.exe
- C:\Documents and Settings\LocalService\Local Settings\Unfair kanu shet.RTF
- C:\Documents and Settings\LocalService\Local Settings\143anYer.exe
- C:\Documents and Settings\NetworkService\Application Data.exe
- C:\Documents and Settings\NetworkService\Application Data\Unfair kanu shet.RTF
- C:\Documents and Settings\NetworkService\Application Data\143anYer.exe
- C:\Documents and Settings\Default User\NetHood\143anYer.exe
- C:\Documents and Settings\Default User\NetHood.exe
- C:\Documents and Settings\Default User\NetHood\Unfair kanu shet.RTF
- C:\Documents and Settings\Default User\PrintHood\143anYer.exe
- C:\Documents and Settings\Default User\PrintHood.exe
- C:\Documents and Settings\Default User\Local Settings\Unfair kanu shet.RTF
- C:\Documents and Settings\Default User\Local Settings\143anYer.exe
- C:\Documents and Settings\Default User\My Documents.exe
- C:\Documents and Settings\Default User\My Documents\Unfair kanu shet.RTF
- C:\Documents and Settings\Default User\My Documents\143anYer.exe
- C:\Documents and Settings\Default User\SendTo\Unfair kanu shet.RTF
- C:\Documents and Settings\Default User\SendTo\143anYer.exe
- C:\Documents and Settings\Default User\Start Menu.exe
- C:\Documents and Settings\Default User\Start Menu\Unfair kanu shet.RTF
- C:\Documents and Settings\Default User\Start Menu\143anYer.exe
- C:\Documents and Settings\Default User\Recent.exe
- C:\Documents and Settings\Default User\PrintHood\Unfair kanu shet.RTF
- C:\Documents and Settings\Default User\Recent\143anYer.exe
- C:\Documents and Settings\Default User\SendTo.exe
- C:\Documents and Settings\Default User\Recent\Unfair kanu shet.RTF
- C:\Documents and Settings\NetworkService\Local Settings\Unfair kanu shet.RTF
- %HOMEPATH%\Recent\Unfair kanu shet.RTF
- %HOMEPATH%\Recent\143anYer.exe
- %HOMEPATH%\SendTo.exe
- %HOMEPATH%\SendTo\Unfair kanu shet.RTF
- %HOMEPATH%\SendTo\143anYer.exe
- %HOMEPATH%\PrintHood.exe
- %HOMEPATH%\NetHood\Unfair kanu shet.RTF
- %HOMEPATH%\PrintHood\143anYer.exe
- %HOMEPATH%\Recent.exe
- %HOMEPATH%\PrintHood\Unfair kanu shet.RTF
- C:\Far2\Addons\Colors.exe
- %HOMEPATH%\Templates\Unfair kanu shet.RTF
- C:\Far2\Addons\Colors\143anYer.exe
- C:\Far2\Addons\Macros.exe
- C:\Far2\Addons\Colors\Unfair kanu shet.RTF
- %HOMEPATH%\Start Menu\143anYer.exe
- %HOMEPATH%\Start Menu.exe
- %HOMEPATH%\Start Menu\Unfair kanu shet.RTF
- %HOMEPATH%\Templates\143anYer.exe
- %HOMEPATH%\Templates.exe
- %HOMEPATH%\Desktop.exe
- %HOMEPATH%\Cookies\Unfair kanu shet.RTF
- %HOMEPATH%\Desktop\143anYer.exe
- %HOMEPATH%\Favorites.exe
- %HOMEPATH%\Desktop\Unfair kanu shet.RTF
- %APPDATA%\143anYer.exe
- %APPDATA%.exe
- %APPDATA%\Unfair kanu shet.RTF
- %HOMEPATH%\Cookies\143anYer.exe
- %HOMEPATH%\Cookies.exe
- %HOMEPATH%\My Documents\143anYer.exe
- %HOMEPATH%\My Documents.exe
- %HOMEPATH%\My Documents\Unfair kanu shet.RTF
- %HOMEPATH%\NetHood\143anYer.exe
- %HOMEPATH%\NetHood.exe
- %HOMEPATH%\Favorites\Unfair kanu shet.RTF
- %HOMEPATH%\Favorites\143anYer.exe
- %HOMEPATH%\Local Settings.exe
- %HOMEPATH%\Local Settings\Unfair kanu shet.RTF
- %HOMEPATH%\Local Settings\143anYer.exe
- C:\Documents and Settings\Default User\Local Settings.exe
- C:\Documents and Settings\NetworkService\Unfair kanu shet.RTF
- C:\Documents and Settings\NetworkService\143anYer.exe
- %HOMEPATH%.exe
- %HOMEPATH%\Unfair kanu shet.RTF
- %HOMEPATH%\143anYer.exe
- C:\Documents and Settings\LocalService.exe
- C:\Documents and Settings\Default User\Unfair kanu shet.RTF
- C:\Documents and Settings\LocalService\143anYer.exe
- C:\Documents and Settings\NetworkService.exe
- C:\Documents and Settings\LocalService\Unfair kanu shet.RTF
- C:\Far2\Encyclopedia.exe
- C:\Far2\Documentation\Unfair kanu shet.RTF
- C:\Far2\Encyclopedia\143anYer.exe
- C:\Far2\FExcept.exe
- C:\Far2\Encyclopedia\Unfair kanu shet.RTF
- C:\Far2\Addons\143anYer.exe
- C:\Far2\Addons.exe
- C:\Far2\Addons\Unfair kanu shet.RTF
- C:\Far2\Documentation\143anYer.exe
- C:\Far2\Documentation.exe
- <Current directory>\Unfair kanu shet.RTF
- <Current directory>\143anYer.exe
- C:\Documents and Settings.exe
- C:\Documents and Settings\Unfair kanu shet.RTF
- C:\Documents and Settings\143anYer.exe
- C:\KenShir.exe
- <SYSTEM32>\RihsNek.exe
- C:\Unfair kanu shet.RTF
- C:\143anYer.exe
- <Current directory>.exe
- %ALLUSERSPROFILE%\143anYer.exe
- %ALLUSERSPROFILE%.exe
- %ALLUSERSPROFILE%\Unfair kanu shet.RTF
- C:\Documents and Settings\Default User\143anYer.exe
- C:\Documents and Settings\Default User.exe
- C:\Far2\143anYer.exe
- C:\Far2.exe
- C:\Far2\Unfair kanu shet.RTF
- <Auxiliary element>
- C:\<Auxiliary name>.exe
- C:\Far2\FExcept\143anYer.exe
- %ALLUSERSPROFILE%\Templates\143anYer.exe
- %ALLUSERSPROFILE%\Templates.exe
- %ALLUSERSPROFILE%\Templates\Unfair kanu shet.RTF
- C:\Documents and Settings\Default User\Application Data\143anYer.exe
- C:\Documents and Settings\Default User\Application Data.exe
- %ALLUSERSPROFILE%\Favorites\Unfair kanu shet.RTF
- %ALLUSERSPROFILE%\Favorites\143anYer.exe
- %ALLUSERSPROFILE%\Start Menu.exe
- %ALLUSERSPROFILE%\Start Menu\Unfair kanu shet.RTF
- %ALLUSERSPROFILE%\Start Menu\143anYer.exe
- C:\Documents and Settings\Default User\Desktop\Unfair kanu shet.RTF
- C:\Documents and Settings\Default User\Desktop\143anYer.exe
- C:\Documents and Settings\Default User\Favorites.exe
- C:\Documents and Settings\Default User\Favorites\Unfair kanu shet.RTF
- C:\Documents and Settings\Default User\Favorites\143anYer.exe
- C:\Documents and Settings\Default User\Cookies.exe
- C:\Documents and Settings\Default User\Application Data\Unfair kanu shet.RTF
- C:\Documents and Settings\Default User\Cookies\143anYer.exe
- C:\Documents and Settings\Default User\Desktop.exe
- C:\Documents and Settings\Default User\Cookies\Unfair kanu shet.RTF
- C:\Far2\PluginSDK\Unfair kanu shet.RTF
- C:\Far2\PluginSDK\143anYer.exe
- %ALLUSERSPROFILE%\Application Data.exe
- %ALLUSERSPROFILE%\Application Data\Unfair kanu shet.RTF
- %ALLUSERSPROFILE%\Application Data\143anYer.exe
- C:\Far2\Plugins.exe
- C:\Far2\FExcept\Unfair kanu shet.RTF
- C:\Far2\Plugins\143anYer.exe
- C:\Far2\PluginSDK.exe
- C:\Far2\Plugins\Unfair kanu shet.RTF
- %ALLUSERSPROFILE%\DRM.exe
- %ALLUSERSPROFILE%\Documents\Unfair kanu shet.RTF
- %ALLUSERSPROFILE%\DRM\143anYer.exe
- %ALLUSERSPROFILE%\Favorites.exe
- %ALLUSERSPROFILE%\DRM\Unfair kanu shet.RTF
- %ALLUSERSPROFILE%\Desktop\143anYer.exe
- %ALLUSERSPROFILE%\Desktop.exe
- %ALLUSERSPROFILE%\Desktop\Unfair kanu shet.RTF
- %ALLUSERSPROFILE%\Documents\143anYer.exe
- %ALLUSERSPROFILE%\Documents.exe
- C:\KenShir.exe
- <SYSTEM32>\RihsNek.exe
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''