Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'winScreenFilter' = '"%APPDATA%\<File name>.exe"'
- %APPDATA%\<File name>.exe
- %APPDATA%\<File name>.exe
- from %ProgramFiles%\internet explorer\signup\install.ins to %ProgramFiles%\internet explorer\signup\install.ins.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\wsdetect.dll to %ProgramFiles%\java\jre1.8.0_45\bin\wsdetect.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\w2k_lsa_auth.dll to %ProgramFiles%\java\jre1.8.0_45\bin\w2k_lsa_auth.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\verify.dll to %ProgramFiles%\java\jre1.8.0_45\bin\verify.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\unpack200.exe to %ProgramFiles%\java\jre1.8.0_45\bin\unpack200.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\unpack.dll to %ProgramFiles%\java\jre1.8.0_45\bin\unpack.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\tnameserv.exe to %ProgramFiles%\java\jre1.8.0_45\bin\tnameserv.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\t2k.dll to %ProgramFiles%\java\jre1.8.0_45\bin\t2k.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\sunmscapi.dll to %ProgramFiles%\java\jre1.8.0_45\bin\sunmscapi.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\sunec.dll to %ProgramFiles%\java\jre1.8.0_45\bin\sunec.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\ssvagent.exe to %ProgramFiles%\java\jre1.8.0_45\bin\ssvagent.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\ssv.dll to %ProgramFiles%\java\jre1.8.0_45\bin\ssv.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\splashscreen.dll to %ProgramFiles%\java\jre1.8.0_45\bin\splashscreen.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\dtplugin\deployjava1.dll to %ProgramFiles%\java\jre1.8.0_45\bin\dtplugin\deployjava1.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\zip.dll to %ProgramFiles%\java\jre1.8.0_45\bin\zip.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\rmid.exe to %ProgramFiles%\java\jre1.8.0_45\bin\rmid.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\resource.dll to %ProgramFiles%\java\jre1.8.0_45\bin\resource.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\prism_sw.dll to %ProgramFiles%\java\jre1.8.0_45\bin\prism_sw.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\prism_es2.dll to %ProgramFiles%\java\jre1.8.0_45\bin\prism_es2.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\prism_d3d.dll to %ProgramFiles%\java\jre1.8.0_45\bin\prism_d3d.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\prism_common.dll to %ProgramFiles%\java\jre1.8.0_45\bin\prism_common.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\policytool.exe to %ProgramFiles%\java\jre1.8.0_45\bin\policytool.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\pack200.exe to %ProgramFiles%\java\jre1.8.0_45\bin\pack200.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\orbd.exe to %ProgramFiles%\java\jre1.8.0_45\bin\orbd.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\npt.dll to %ProgramFiles%\java\jre1.8.0_45\bin\npt.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\nio.dll to %ProgramFiles%\java\jre1.8.0_45\bin\nio.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\net.dll to %ProgramFiles%\java\jre1.8.0_45\bin\net.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\servertool.exe to %ProgramFiles%\java\jre1.8.0_45\bin\servertool.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\javacpl.cpl to %ProgramFiles%\java\jre1.8.0_45\bin\javacpl.cpl.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\dtplugin\npdeployjava1.dll to %ProgramFiles%\java\jre1.8.0_45\bin\dtplugin\npdeployjava1.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\psfont.properties.ja to %ProgramFiles%\java\jre1.8.0_45\lib\psfont.properties.ja.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\plugin.jar to %ProgramFiles%\java\jre1.8.0_45\lib\plugin.jar.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\net.properties to %ProgramFiles%\java\jre1.8.0_45\lib\net.properties.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\meta-index to %ProgramFiles%\java\jre1.8.0_45\lib\meta-index.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\management-agent.jar to %ProgramFiles%\java\jre1.8.0_45\lib\management-agent.jar.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\logging.properties to %ProgramFiles%\java\jre1.8.0_45\lib\logging.properties.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\jvm.hprof.txt to %ProgramFiles%\java\jre1.8.0_45\lib\jvm.hprof.txt.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\jsse.jar to %ProgramFiles%\java\jre1.8.0_45\lib\jsse.jar.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\jfxswt.jar to %ProgramFiles%\java\jre1.8.0_45\lib\jfxswt.jar.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\jfr.jar to %ProgramFiles%\java\jre1.8.0_45\lib\jfr.jar.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\jce.jar to %ProgramFiles%\java\jre1.8.0_45\lib\jce.jar.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\javaws.jar to %ProgramFiles%\java\jre1.8.0_45\lib\javaws.jar.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\javafx.properties to %ProgramFiles%\java\jre1.8.0_45\lib\javafx.properties.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\hijrah-config-umalqura.properties to %ProgramFiles%\java\jre1.8.0_45\lib\hijrah-config-umalqura.properties.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\fontconfig.properties.src to %ProgramFiles%\java\jre1.8.0_45\lib\fontconfig.properties.src.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\fontconfig.bfc to %ProgramFiles%\java\jre1.8.0_45\lib\fontconfig.bfc.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\flavormap.properties to %ProgramFiles%\java\jre1.8.0_45\lib\flavormap.properties.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\deploy.jar to %ProgramFiles%\java\jre1.8.0_45\lib\deploy.jar.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\currency.data to %ProgramFiles%\java\jre1.8.0_45\lib\currency.data.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\content-types.properties to %ProgramFiles%\java\jre1.8.0_45\lib\content-types.properties.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\classlist to %ProgramFiles%\java\jre1.8.0_45\lib\classlist.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\charsets.jar to %ProgramFiles%\java\jre1.8.0_45\lib\charsets.jar.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\calendars.properties to %ProgramFiles%\java\jre1.8.0_45\lib\calendars.properties.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\accessibility.properties to %ProgramFiles%\java\jre1.8.0_45\lib\accessibility.properties.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\server\xusage.txt to %ProgramFiles%\java\jre1.8.0_45\bin\server\xusage.txt.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\server\jvm.dll to %ProgramFiles%\java\jre1.8.0_45\bin\server\jvm.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\plugin2\npjp2.dll to %ProgramFiles%\java\jre1.8.0_45\bin\plugin2\npjp2.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\msvcr100.dll to %ProgramFiles%\java\jre1.8.0_45\bin\msvcr100.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\rmiregistry.exe to %ProgramFiles%\java\jre1.8.0_45\bin\rmiregistry.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\mlib_image.dll to %ProgramFiles%\java\jre1.8.0_45\bin\mlib_image.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\management.dll to %ProgramFiles%\java\jre1.8.0_45\bin\management.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\lcms.dll to %ProgramFiles%\java\jre1.8.0_45\bin\lcms.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\eula.dll to %ProgramFiles%\java\jre1.8.0_45\bin\eula.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\java-rmi.exe to %ProgramFiles%\java\jre1.8.0_45\bin\java-rmi.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jabswitch.exe to %ProgramFiles%\java\jre1.8.0_45\bin\jabswitch.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jaas_nt.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jaas_nt.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\j2pkcs11.dll to %ProgramFiles%\java\jre1.8.0_45\bin\j2pkcs11.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\j2pcsc.dll to %ProgramFiles%\java\jre1.8.0_45\bin\j2pcsc.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\instrument.dll to %ProgramFiles%\java\jre1.8.0_45\bin\instrument.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\hprof.dll to %ProgramFiles%\java\jre1.8.0_45\bin\hprof.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\gstreamer-lite.dll to %ProgramFiles%\java\jre1.8.0_45\bin\gstreamer-lite.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\glib-lite.dll to %ProgramFiles%\java\jre1.8.0_45\bin\glib-lite.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\glass.dll to %ProgramFiles%\java\jre1.8.0_45\bin\glass.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\fxplugins.dll to %ProgramFiles%\java\jre1.8.0_45\bin\fxplugins.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\fontmanager.dll to %ProgramFiles%\java\jre1.8.0_45\bin\fontmanager.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\dt_socket.dll to %ProgramFiles%\java\jre1.8.0_45\bin\dt_socket.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\java.exe to %ProgramFiles%\java\jre1.8.0_45\bin\java.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\dt_shmem.dll to %ProgramFiles%\java\jre1.8.0_45\bin\dt_shmem.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\deploy.dll to %ProgramFiles%\java\jre1.8.0_45\bin\deploy.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\decora_sse.dll to %ProgramFiles%\java\jre1.8.0_45\bin\decora_sse.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\dcpr.dll to %ProgramFiles%\java\jre1.8.0_45\bin\dcpr.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\bci.dll to %ProgramFiles%\java\jre1.8.0_45\bin\bci.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\awt.dll to %ProgramFiles%\java\jre1.8.0_45\bin\awt.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\thirdpartylicensereadme.txt to %ProgramFiles%\java\jre1.8.0_45\thirdpartylicensereadme.txt.null
- from %ProgramFiles%\java\jre1.8.0_45\thirdpartylicensereadme-javafx.txt to %ProgramFiles%\java\jre1.8.0_45\thirdpartylicensereadme-javafx.txt.null
- from %ProgramFiles%\java\jre1.8.0_45\release to %ProgramFiles%\java\jre1.8.0_45\release.null
- from %ProgramFiles%\java\jre1.8.0_45\readme.txt to %ProgramFiles%\java\jre1.8.0_45\readme.txt.null
- from %ProgramFiles%\java\jre1.8.0_45\license to %ProgramFiles%\java\jre1.8.0_45\license.null
- from %ProgramFiles%\java\jre1.8.0_45\copyright to %ProgramFiles%\java\jre1.8.0_45\copyright.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\psfontj2d.properties to %ProgramFiles%\java\jre1.8.0_45\lib\psfontj2d.properties.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\plugin2\msvcr100.dll to %ProgramFiles%\java\jre1.8.0_45\bin\plugin2\msvcr100.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\javaaccessbridge-64.dll to %ProgramFiles%\java\jre1.8.0_45\bin\javaaccessbridge-64.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\javafx_font.dll to %ProgramFiles%\java\jre1.8.0_45\bin\javafx_font.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\java.dll to %ProgramFiles%\java\jre1.8.0_45\bin\java.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\ktab.exe to %ProgramFiles%\java\jre1.8.0_45\bin\ktab.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\klist.exe to %ProgramFiles%\java\jre1.8.0_45\bin\klist.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\kinit.exe to %ProgramFiles%\java\jre1.8.0_45\bin\kinit.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\keytool.exe to %ProgramFiles%\java\jre1.8.0_45\bin\keytool.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\kcms.dll to %ProgramFiles%\java\jre1.8.0_45\bin\kcms.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jsoundds.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jsoundds.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jsound.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jsound.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jsdt.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jsdt.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jpeg.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jpeg.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jp2ssv.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jp2ssv.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jp2native.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jp2native.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jp2launcher.exe to %ProgramFiles%\java\jre1.8.0_45\bin\jp2launcher.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jp2iexp.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jp2iexp.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jli.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jli.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jjs.exe to %ProgramFiles%\java\jre1.8.0_45\bin\jjs.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jfxwebkit.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jfxwebkit.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jfxmedia.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jfxmedia.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jfr.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jfr.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jdwp.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jdwp.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jawtaccessbridge-64.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jawtaccessbridge-64.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\jawt.dll to %ProgramFiles%\java\jre1.8.0_45\bin\jawt.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\java_crw_demo.dll to %ProgramFiles%\java\jre1.8.0_45\bin\java_crw_demo.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\javaws.exe to %ProgramFiles%\java\jre1.8.0_45\bin\javaws.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\javaw.exe to %ProgramFiles%\java\jre1.8.0_45\bin\javaw.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\javafx_iio.dll to %ProgramFiles%\java\jre1.8.0_45\bin\javafx_iio.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\javafx_font_t2k.dll to %ProgramFiles%\java\jre1.8.0_45\bin\javafx_font_t2k.dll.null
- from %ProgramFiles%\java\jre1.8.0_45\bin\javacpl.exe to %ProgramFiles%\java\jre1.8.0_45\bin\javacpl.exe.null
- from %ProgramFiles%\java\jre1.8.0_45\lib\resources.jar to %ProgramFiles%\java\jre1.8.0_45\lib\resources.jar.null
- C:\kms\kms_vl_all_aio.cmd
- C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\setup.xml
- C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\excelmui.xml
- C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\excelmui.msi
- C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\excellr.cab
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\setup.xml
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\propsww2.cab
- C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\powerpointmui.msi
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\propsww.cab
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\proplusww.msi
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\pkeyconfig-office.xrm-ms
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\owow32ww.cab
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\office32ww.xml
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\office32ww.msi
- C:\kms\kms_vl_all_aio_debug.log
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\proplusww.xml
- C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\powerpointmui.xml
- '%APPDATA%\<File name>.exe'