Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Win32.Siggen.15

Added to the Dr.Web virus database: 2013-09-04

Virus description added:

Technical Information

To ensure autorun and distribution:
Infects the following executable system files:
  • <SYSTEM32>\rsvp.exe
  • <SYSTEM32>\rtcshare.exe
  • <SYSTEM32>\rsnotify.exe
  • <SYSTEM32>\rsopprov.exe
  • <SYSTEM32>\runas.exe
  • <SYSTEM32>\rwinsta.exe
  • <SYSTEM32>\savedump.exe
  • <SYSTEM32>\rundll32.exe
  • <SYSTEM32>\runonce.exe
  • <SYSTEM32>\rexec.exe
  • <SYSTEM32>\route.exe
  • <SYSTEM32>\replace.exe
  • <SYSTEM32>\reset.exe
  • <SYSTEM32>\routemon.exe
  • <SYSTEM32>\rsmsink.exe
  • <SYSTEM32>\rsmui.exe
  • <SYSTEM32>\rsh.exe
  • <SYSTEM32>\rsm.exe
  • <SYSTEM32>\shrpubw.exe
  • <SYSTEM32>\shutdown.exe
  • <SYSTEM32>\shadow.exe
  • <SYSTEM32>\shmgrate.exe
  • <SYSTEM32>\sigverif.exe
  • <SYSTEM32>\smlogsvc.exe
  • <SYSTEM32>\sndrec32.exe
  • <SYSTEM32>\skeys.exe
  • <SYSTEM32>\smbinst.exe
  • <SYSTEM32>\schtasks.exe
  • <SYSTEM32>\sdbinst.exe
  • <SYSTEM32>\sc.exe
  • <SYSTEM32>\scardsvr.exe
  • <SYSTEM32>\secedit.exe
  • <SYSTEM32>\setup.exe
  • <SYSTEM32>\sfc.exe
  • <SYSTEM32>\sessmgr.exe
  • <SYSTEM32>\sethc.exe
  • <SYSTEM32>\ping6.exe
  • <SYSTEM32>\powercfg.exe
  • <SYSTEM32>\perfmon.exe
  • <SYSTEM32>\ping.exe
  • <SYSTEM32>\PresentationHost.exe
  • <SYSTEM32>\proquota.exe
  • <SYSTEM32>\proxycfg.exe
  • <SYSTEM32>\print.exe
  • <SYSTEM32>\progman.exe
  • <SYSTEM32>\odbcconf.exe
  • <SYSTEM32>\openfiles.exe
  • <SYSTEM32>\nwscript.exe
  • <SYSTEM32>\odbcad32.exe
  • <SYSTEM32>\osk.exe
  • <SYSTEM32>\pathping.exe
  • <SYSTEM32>\pentnt.exe
  • <SYSTEM32>\osuninst.exe
  • <SYSTEM32>\packager.exe
  • <SYSTEM32>\recover.exe
  • <SYSTEM32>\reg.exe
  • <SYSTEM32>\rdsaddin.exe
  • <SYSTEM32>\rdshost.exe
  • <SYSTEM32>\regedt32.exe
  • <SYSTEM32>\regwiz.exe
  • <SYSTEM32>\relog.exe
  • <SYSTEM32>\regini.exe
  • <SYSTEM32>\regsvr32.exe
  • <SYSTEM32>\qwinsta.exe
  • <SYSTEM32>\rasautou.exe
  • <SYSTEM32>\qappsrv.exe
  • <SYSTEM32>\qprocess.exe
  • <SYSTEM32>\rasdial.exe
  • <SYSTEM32>\rcp.exe
  • <SYSTEM32>\rdpclip.exe
  • <SYSTEM32>\rasphone.exe
  • <SYSTEM32>\rcimlby.exe
  • <SYSTEM32>\sndvol32.exe
  • <SYSTEM32>\w32tm.exe
  • <SYSTEM32>\wextract.exe
  • <SYSTEM32>\vssadmin.exe
  • <SYSTEM32>\vssvc.exe
  • <SYSTEM32>\wiaacmgr.exe
  • <SYSTEM32>\winmine.exe
  • <SYSTEM32>\winmsd.exe
  • <SYSTEM32>\winchat.exe
  • <SYSTEM32>\winhlp32.exe
  • <SYSTEM32>\ups.exe
  • <SYSTEM32>\userinit.exe
  • <SYSTEM32>\unlodctr.exe
  • <SYSTEM32>\upnpcont.exe
  • <SYSTEM32>\usrmlnka.exe
  • <SYSTEM32>\utilman.exe
  • <SYSTEM32>\verifier.exe
  • <SYSTEM32>\usrprbda.exe
  • <SYSTEM32>\usrshuta.exe
  • %WINDIR%\NOTEPAD.EXE
  • %WINDIR%\regedit.exe
  • <SYSTEM32>\xcopy.exe
  • %WINDIR%\hh.exe
  • %WINDIR%\sfk.exe
  • %WINDIR%\twunk_32.exe
  • %WINDIR%\winhlp32.exe
  • %WINDIR%\sleep.exe
  • %WINDIR%\TASKMAN.EXE
  • <SYSTEM32>\wpnpinst.exe
  • <SYSTEM32>\write.exe
  • <SYSTEM32>\winver.exe
  • <SYSTEM32>\wpabaln.exe
  • <SYSTEM32>\wscntfy.exe
  • <SYSTEM32>\wuauclt1.exe
  • <SYSTEM32>\wupdmgr.exe
  • <SYSTEM32>\wscript.exe
  • <SYSTEM32>\wuauclt.exe
  • <SYSTEM32>\sysocmgr.exe
  • <SYSTEM32>\systeminfo.exe
  • <SYSTEM32>\syncapp.exe
  • <SYSTEM32>\syskey.exe
  • <SYSTEM32>\systray.exe
  • <SYSTEM32>\taskman.exe
  • <SYSTEM32>\taskmgr.exe
  • <SYSTEM32>\taskkill.exe
  • <SYSTEM32>\tasklist.exe
  • <SYSTEM32>\spider.exe
  • <SYSTEM32>\spiisupd.exe
  • <SYSTEM32>\sol.exe
  • <SYSTEM32>\sort.exe
  • <SYSTEM32>\spnpinst.exe
  • <SYSTEM32>\stimon.exe
  • <SYSTEM32>\subst.exe
  • <SYSTEM32>\sprestrt.exe
  • <SYSTEM32>\spupdsvc.exe
  • <SYSTEM32>\tscon.exe
  • <SYSTEM32>\tscupgrd.exe
  • <SYSTEM32>\tracert.exe
  • <SYSTEM32>\tracert6.exe
  • <SYSTEM32>\tsdiscon.exe
  • <SYSTEM32>\TsWpfWrp.exe
  • <SYSTEM32>\typeperf.exe
  • <SYSTEM32>\tskill.exe
  • <SYSTEM32>\tsshutdn.exe
  • <SYSTEM32>\telnet.exe
  • <SYSTEM32>\tftp.exe
  • <SYSTEM32>\tcmsetup.exe
  • <SYSTEM32>\tcpsvcs.exe
  • <SYSTEM32>\tlntadmn.exe
  • <SYSTEM32>\tourstart.exe
  • <SYSTEM32>\tracerpt.exe
  • <SYSTEM32>\tlntsess.exe
  • <SYSTEM32>\tlntsvr.exe
  • <SYSTEM32>\diskperf.exe
  • <SYSTEM32>\dllhost.exe
  • <SYSTEM32>\diantz.exe
  • <SYSTEM32>\diskpart.exe
  • <SYSTEM32>\dllhst3g.exe
  • <SYSTEM32>\doskey.exe
  • <SYSTEM32>\dplaysvr.exe
  • <SYSTEM32>\dmadmin.exe
  • <SYSTEM32>\dmremote.exe
  • <SYSTEM32>\control.exe
  • <SYSTEM32>\convert.exe
  • <SYSTEM32>\compact.exe
  • <SYSTEM32>\conime.exe
  • <SYSTEM32>\dcomcnfg.exe
  • <SYSTEM32>\dfrgfat.exe
  • <SYSTEM32>\dfrgntfs.exe
  • <SYSTEM32>\ddeshare.exe
  • <SYSTEM32>\defrag.exe
  • <SYSTEM32>\eventcreate.exe
  • <SYSTEM32>\eventtriggers.exe
  • <SYSTEM32>\esentutl.exe
  • <SYSTEM32>\eudcedit.exe
  • <SYSTEM32>\eventvwr.exe
  • <SYSTEM32>\fc.exe
  • <SYSTEM32>\find.exe
  • <SYSTEM32>\expand.exe
  • <SYSTEM32>\extrac32.exe
  • <SYSTEM32>\driverquery.exe
  • <SYSTEM32>\drwtsn32.exe
  • <SYSTEM32>\dpnsvr.exe
  • <SYSTEM32>\dpvsetup.exe
  • <SYSTEM32>\dumprep.exe
  • <SYSTEM32>\dwwin.exe
  • <SYSTEM32>\dxdiag.exe
  • <SYSTEM32>\dvdplay.exe
  • <SYSTEM32>\dvdupgrd.exe
  • <SYSTEM32>\autochk.exe
  • <SYSTEM32>\autoconv.exe
  • <SYSTEM32>\attrib.exe
  • <SYSTEM32>\auditusr.exe
  • <SYSTEM32>\autofmt.exe
  • <SYSTEM32>\bootcfg.exe
  • <SYSTEM32>\bootok.exe
  • <SYSTEM32>\autolfn.exe
  • <SYSTEM32>\blastcln.exe
  • <SYSTEM32>\ahui.exe
  • <SYSTEM32>\arp.exe
  • <SYSTEM32>\accwiz.exe
  • <SYSTEM32>\actmovie.exe
  • <SYSTEM32>\asr_fmt.exe
  • <SYSTEM32>\at.exe
  • <SYSTEM32>\atmadm.exe
  • <SYSTEM32>\asr_ldm.exe
  • <SYSTEM32>\asr_pfu.exe
  • <SYSTEM32>\cliconfg.exe
  • <SYSTEM32>\clipbrd.exe
  • <SYSTEM32>\ckcnv.exe
  • <SYSTEM32>\cleanmgr.exe
  • <SYSTEM32>\clipsrv.exe
  • <SYSTEM32>\cmstp.exe
  • <SYSTEM32>\comp.exe
  • <SYSTEM32>\cmdl32.exe
  • <SYSTEM32>\cmmon32.exe
  • <SYSTEM32>\calc.exe
  • <SYSTEM32>\charmap.exe
  • <SYSTEM32>\bootvrfy.exe
  • <SYSTEM32>\cacls.exe
  • <SYSTEM32>\chkdsk.exe
  • <SYSTEM32>\cipher.exe
  • <SYSTEM32>\cisvc.exe
  • <SYSTEM32>\chkntfs.exe
  • <SYSTEM32>\cidaemon.exe
  • <SYSTEM32>\findstr.exe
  • <SYSTEM32>\msdtc.exe
  • <SYSTEM32>\msg.exe
  • <SYSTEM32>\mqtgsvc.exe
  • <SYSTEM32>\mrinfo.exe
  • <SYSTEM32>\mshearts.exe
  • <SYSTEM32>\mspaint.exe
  • <SYSTEM32>\msswchx.exe
  • <SYSTEM32>\mshta.exe
  • <SYSTEM32>\msiexec.exe
  • <SYSTEM32>\mnmsrvc.exe
  • <SYSTEM32>\mobsync.exe
  • <SYSTEM32>\migpwd.exe
  • <SYSTEM32>\mmc.exe
  • <SYSTEM32>\mountvol.exe
  • <SYSTEM32>\mqbkup.exe
  • <SYSTEM32>\mqsvc.exe
  • <SYSTEM32>\mplay32.exe
  • <SYSTEM32>\mpnotify.exe
  • <SYSTEM32>\notepad.exe
  • <SYSTEM32>\nslookup.exe
  • <SYSTEM32>\netsh.exe
  • <SYSTEM32>\netstat.exe
  • <SYSTEM32>\ntbackup.exe
  • <SYSTEM32>\ntsd.exe
  • <SYSTEM32>\ntvdm.exe
  • <SYSTEM32>\ntkrnlpa.exe
  • <SYSTEM32>\ntoskrnl.exe
  • <SYSTEM32>\narrator.exe
  • <SYSTEM32>\nbtstat.exe
  • <SYSTEM32>\mstinit.exe
  • <SYSTEM32>\mstsc.exe
  • <SYSTEM32>\nddeapir.exe
  • <SYSTEM32>\netdde.exe
  • <SYSTEM32>\netsetup.exe
  • <SYSTEM32>\net.exe
  • <SYSTEM32>\net1.exe
  • <SYSTEM32>\gpupdate.exe
  • <SYSTEM32>\grpconv.exe
  • <SYSTEM32>\getmac.exe
  • <SYSTEM32>\gpresult.exe
  • <SYSTEM32>\help.exe
  • <SYSTEM32>\ie4uinit.exe
  • <SYSTEM32>\iexpress.exe
  • <SYSTEM32>\hostname.exe
  • <SYSTEM32>\icardagt.exe
  • <SYSTEM32>\fltMc.exe
  • <SYSTEM32>\fontview.exe
  • <SYSTEM32>\finger.exe
  • <SYSTEM32>\fixmapi.exe
  • <SYSTEM32>\forcedos.exe
  • <SYSTEM32>\fsutil.exe
  • <SYSTEM32>\ftp.exe
  • <SYSTEM32>\freecell.exe
  • <SYSTEM32>\fsquirt.exe
  • <SYSTEM32>\logman.exe
  • <SYSTEM32>\logoff.exe
  • <SYSTEM32>\lodctr.exe
  • <SYSTEM32>\logagent.exe
  • <SYSTEM32>\logonui.exe
  • <SYSTEM32>\magnify.exe
  • <SYSTEM32>\makecab.exe
  • <SYSTEM32>\lpq.exe
  • <SYSTEM32>\lpr.exe
  • <SYSTEM32>\ipsec6.exe
  • <SYSTEM32>\ipv6.exe
  • <SYSTEM32>\imapi.exe
  • <SYSTEM32>\ipconfig.exe
  • <SYSTEM32>\ipxroute.exe
  • <SYSTEM32>\lnkstub.exe
  • <SYSTEM32>\locator.exe
  • <SYSTEM32>\label.exe
  • <SYSTEM32>\lights.exe
Substitutes the following executable system files:
  • <SYSTEM32>\makecab.exe with <SYSTEM32>\makecab.exe.new
  • <SYSTEM32>\magnify.exe with <SYSTEM32>\magnify.exe.new
  • <SYSTEM32>\mmc.exe with <SYSTEM32>\mmc.exe.new
  • <SYSTEM32>\dllcache\ahui.exe with <SYSTEM32>\dllcache\ahui.exe.new
  • <SYSTEM32>\dllcache\actmovie.exe with <SYSTEM32>\dllcache\actmovie.exe.new
  • <SYSTEM32>\logonui.exe with <SYSTEM32>\logonui.exe.new
  • <SYSTEM32>\dllcache\accwiz.exe with <SYSTEM32>\dllcache\accwiz.exe.new
  • <SYSTEM32>\lpr.exe with <SYSTEM32>\lpr.exe.new
  • <SYSTEM32>\lpq.exe with <SYSTEM32>\lpq.exe.new
  • <SYSTEM32>\mnmsrvc.exe with <SYSTEM32>\mnmsrvc.exe.new
  • <SYSTEM32>\mqbkup.exe with <SYSTEM32>\mqbkup.exe.new
  • <SYSTEM32>\dllcache\asr_fmt.exe with <SYSTEM32>\dllcache\asr_fmt.exe.new
  • <SYSTEM32>\dllcache\asr_ldm.exe with <SYSTEM32>\dllcache\asr_ldm.exe.new
  • <SYSTEM32>\mqsvc.exe with <SYSTEM32>\mqsvc.exe.new
  • <SYSTEM32>\mpnotify.exe with <SYSTEM32>\mpnotify.exe.new
  • <SYSTEM32>\mobsync.exe with <SYSTEM32>\mobsync.exe.new
  • <SYSTEM32>\dllcache\arp.exe with <SYSTEM32>\dllcache\arp.exe.new
  • <SYSTEM32>\mplay32.exe with <SYSTEM32>\mplay32.exe.new
  • <SYSTEM32>\mountvol.exe with <SYSTEM32>\mountvol.exe.new
  • <SYSTEM32>\logoff.exe with <SYSTEM32>\logoff.exe.new
  • <SYSTEM32>\iexpress.exe with <SYSTEM32>\iexpress.exe.new
  • <SYSTEM32>\ie4uinit.exe with <SYSTEM32>\ie4uinit.exe.new
  • <SYSTEM32>\ipconfig.exe with <SYSTEM32>\ipconfig.exe.new
  • <SYSTEM32>\imapi.exe with <SYSTEM32>\imapi.exe.new
  • <SYSTEM32>\hostname.exe with <SYSTEM32>\hostname.exe.new
  • <SYSTEM32>\gpupdate.exe with <SYSTEM32>\gpupdate.exe.new
  • <SYSTEM32>\gpresult.exe with <SYSTEM32>\gpresult.exe.new
  • <SYSTEM32>\help.exe with <SYSTEM32>\help.exe.new
  • <SYSTEM32>\grpconv.exe with <SYSTEM32>\grpconv.exe.new
  • <SYSTEM32>\ipsec6.exe with <SYSTEM32>\ipsec6.exe.new
  • <SYSTEM32>\lodctr.exe with <SYSTEM32>\lodctr.exe.new
  • <SYSTEM32>\locator.exe with <SYSTEM32>\locator.exe.new
  • <SYSTEM32>\logman.exe with <SYSTEM32>\logman.exe.new
  • <SYSTEM32>\logagent.exe with <SYSTEM32>\logagent.exe.new
  • <SYSTEM32>\lnkstub.exe with <SYSTEM32>\lnkstub.exe.new
  • <SYSTEM32>\ipxroute.exe with <SYSTEM32>\ipxroute.exe.new
  • <SYSTEM32>\ipv6.exe with <SYSTEM32>\ipv6.exe.new
  • <SYSTEM32>\lights.exe with <SYSTEM32>\lights.exe.new
  • <SYSTEM32>\label.exe with <SYSTEM32>\label.exe.new
  • <SYSTEM32>\mqtgsvc.exe with <SYSTEM32>\mqtgsvc.exe.new
  • <SYSTEM32>\nslookup.exe with <SYSTEM32>\nslookup.exe.new
  • <SYSTEM32>\notepad.exe with <SYSTEM32>\notepad.exe.new
  • <SYSTEM32>\ntbackup.exe with <SYSTEM32>\ntbackup.exe.new
  • <SYSTEM32>\dllcache\autoconv.exe with <SYSTEM32>\dllcache\autoconv.exe.new
  • <SYSTEM32>\netstat.exe with <SYSTEM32>\netstat.exe.new
  • <SYSTEM32>\netsetup.exe with <SYSTEM32>\netsetup.exe.new
  • <SYSTEM32>\netdde.exe with <SYSTEM32>\netdde.exe.new
  • <SYSTEM32>\dllcache\autochk.exe with <SYSTEM32>\dllcache\autochk.exe.new
  • <SYSTEM32>\netsh.exe with <SYSTEM32>\netsh.exe.new
  • <SYSTEM32>\dllcache\autofmt.exe with <SYSTEM32>\dllcache\autofmt.exe.new
  • <SYSTEM32>\ntsd.exe with <SYSTEM32>\ntsd.exe.new
  • <SYSTEM32>\dllcache\cacls.exe with <SYSTEM32>\dllcache\cacls.exe.new
  • <SYSTEM32>\dllcache\calc.exe with <SYSTEM32>\dllcache\calc.exe.new
  • <SYSTEM32>\ntvdm.exe with <SYSTEM32>\ntvdm.exe.new
  • <SYSTEM32>\dllcache\bootvrfy.exe with <SYSTEM32>\dllcache\bootvrfy.exe.new
  • <SYSTEM32>\dllcache\blastcln.exe with <SYSTEM32>\dllcache\blastcln.exe.new
  • <SYSTEM32>\dllcache\autolfn.exe with <SYSTEM32>\dllcache\autolfn.exe.new
  • <SYSTEM32>\dllcache\bootok.exe with <SYSTEM32>\dllcache\bootok.exe.new
  • <SYSTEM32>\dllcache\bootcfg.exe with <SYSTEM32>\dllcache\bootcfg.exe.new
  • <SYSTEM32>\dllcache\auditusr.exe with <SYSTEM32>\dllcache\auditusr.exe.new
  • <SYSTEM32>\msiexec.exe with <SYSTEM32>\msiexec.exe.new
  • <SYSTEM32>\mshta.exe with <SYSTEM32>\mshta.exe.new
  • <SYSTEM32>\mspaint.exe with <SYSTEM32>\mspaint.exe.new
  • <SYSTEM32>\dllcache\at.exe with <SYSTEM32>\dllcache\at.exe.new
  • <SYSTEM32>\mshearts.exe with <SYSTEM32>\mshearts.exe.new
  • <SYSTEM32>\msdtc.exe with <SYSTEM32>\msdtc.exe.new
  • <SYSTEM32>\mrinfo.exe with <SYSTEM32>\mrinfo.exe.new
  • <SYSTEM32>\dllcache\asr_pfu.exe with <SYSTEM32>\dllcache\asr_pfu.exe.new
  • <SYSTEM32>\msg.exe with <SYSTEM32>\msg.exe.new
  • <SYSTEM32>\msswchx.exe with <SYSTEM32>\msswchx.exe.new
  • <SYSTEM32>\nddeapir.exe with <SYSTEM32>\nddeapir.exe.new
  • <SYSTEM32>\nbtstat.exe with <SYSTEM32>\nbtstat.exe.new
  • <SYSTEM32>\net1.exe with <SYSTEM32>\net1.exe.new
  • <SYSTEM32>\net.exe with <SYSTEM32>\net.exe.new
  • <SYSTEM32>\dllcache\attrib.exe with <SYSTEM32>\dllcache\attrib.exe.new
  • <SYSTEM32>\dllcache\atmadm.exe with <SYSTEM32>\dllcache\atmadm.exe.new
  • <SYSTEM32>\mstinit.exe with <SYSTEM32>\mstinit.exe.new
  • <SYSTEM32>\narrator.exe with <SYSTEM32>\narrator.exe.new
  • <SYSTEM32>\mstsc.exe with <SYSTEM32>\mstsc.exe.new
  • <SYSTEM32>\getmac.exe with <SYSTEM32>\getmac.exe.new
  • <SYSTEM32>\cisvc.exe with <SYSTEM32>\cisvc.exe.new
  • <SYSTEM32>\cipher.exe with <SYSTEM32>\cipher.exe.new
  • <SYSTEM32>\cleanmgr.exe with <SYSTEM32>\cleanmgr.exe.new
  • <SYSTEM32>\ckcnv.exe with <SYSTEM32>\ckcnv.exe.new
  • <SYSTEM32>\cidaemon.exe with <SYSTEM32>\cidaemon.exe.new
  • <SYSTEM32>\charmap.exe with <SYSTEM32>\charmap.exe.new
  • <SYSTEM32>\calc.exe with <SYSTEM32>\calc.exe.new
  • <SYSTEM32>\chkntfs.exe with <SYSTEM32>\chkntfs.exe.new
  • <SYSTEM32>\chkdsk.exe with <SYSTEM32>\chkdsk.exe.new
  • <SYSTEM32>\clipbrd.exe with <SYSTEM32>\clipbrd.exe.new
  • <SYSTEM32>\conime.exe with <SYSTEM32>\conime.exe.new
  • <SYSTEM32>\compact.exe with <SYSTEM32>\compact.exe.new
  • <SYSTEM32>\convert.exe with <SYSTEM32>\convert.exe.new
  • <SYSTEM32>\control.exe with <SYSTEM32>\control.exe.new
  • <SYSTEM32>\comp.exe with <SYSTEM32>\comp.exe.new
  • <SYSTEM32>\cmdl32.exe with <SYSTEM32>\cmdl32.exe.new
  • <SYSTEM32>\clipsrv.exe with <SYSTEM32>\clipsrv.exe.new
  • <SYSTEM32>\cmstp.exe with <SYSTEM32>\cmstp.exe.new
  • <SYSTEM32>\cmmon32.exe with <SYSTEM32>\cmmon32.exe.new
  • <SYSTEM32>\cacls.exe with <SYSTEM32>\cacls.exe.new
  • <SYSTEM32>\asr_pfu.exe with <SYSTEM32>\asr_pfu.exe.new
  • <SYSTEM32>\asr_ldm.exe with <SYSTEM32>\asr_ldm.exe.new
  • <SYSTEM32>\atmadm.exe with <SYSTEM32>\atmadm.exe.new
  • <SYSTEM32>\at.exe with <SYSTEM32>\at.exe.new
  • <SYSTEM32>\asr_fmt.exe with <SYSTEM32>\asr_fmt.exe.new
  • <SYSTEM32>\actmovie.exe with <SYSTEM32>\actmovie.exe.new
  • <SYSTEM32>\accwiz.exe with <SYSTEM32>\accwiz.exe.new
  • <SYSTEM32>\arp.exe with <SYSTEM32>\arp.exe.new
  • <SYSTEM32>\ahui.exe with <SYSTEM32>\ahui.exe.new
  • <SYSTEM32>\attrib.exe with <SYSTEM32>\attrib.exe.new
  • <SYSTEM32>\bootcfg.exe with <SYSTEM32>\bootcfg.exe.new
  • <SYSTEM32>\blastcln.exe with <SYSTEM32>\blastcln.exe.new
  • <SYSTEM32>\bootvrfy.exe with <SYSTEM32>\bootvrfy.exe.new
  • <SYSTEM32>\bootok.exe with <SYSTEM32>\bootok.exe.new
  • <SYSTEM32>\autolfn.exe with <SYSTEM32>\autolfn.exe.new
  • <SYSTEM32>\autochk.exe with <SYSTEM32>\autochk.exe.new
  • <SYSTEM32>\auditusr.exe with <SYSTEM32>\auditusr.exe.new
  • <SYSTEM32>\autofmt.exe with <SYSTEM32>\autofmt.exe.new
  • <SYSTEM32>\autoconv.exe with <SYSTEM32>\autoconv.exe.new
  • <SYSTEM32>\dcomcnfg.exe with <SYSTEM32>\dcomcnfg.exe.new
  • <SYSTEM32>\expand.exe with <SYSTEM32>\expand.exe.new
  • <SYSTEM32>\eventvwr.exe with <SYSTEM32>\eventvwr.exe.new
  • <SYSTEM32>\fc.exe with <SYSTEM32>\fc.exe.new
  • <SYSTEM32>\extrac32.exe with <SYSTEM32>\extrac32.exe.new
  • <SYSTEM32>\eventtriggers.exe with <SYSTEM32>\eventtriggers.exe.new
  • <SYSTEM32>\esentutl.exe with <SYSTEM32>\esentutl.exe.new
  • <SYSTEM32>\dxdiag.exe with <SYSTEM32>\dxdiag.exe.new
  • <SYSTEM32>\eventcreate.exe with <SYSTEM32>\eventcreate.exe.new
  • <SYSTEM32>\eudcedit.exe with <SYSTEM32>\eudcedit.exe.new
  • <SYSTEM32>\find.exe with <SYSTEM32>\find.exe.new
  • <SYSTEM32>\freecell.exe with <SYSTEM32>\freecell.exe.new
  • <SYSTEM32>\forcedos.exe with <SYSTEM32>\forcedos.exe.new
  • <SYSTEM32>\ftp.exe with <SYSTEM32>\ftp.exe.new
  • <SYSTEM32>\fsutil.exe with <SYSTEM32>\fsutil.exe.new
  • <SYSTEM32>\fontview.exe with <SYSTEM32>\fontview.exe.new
  • <SYSTEM32>\finger.exe with <SYSTEM32>\finger.exe.new
  • <SYSTEM32>\findstr.exe with <SYSTEM32>\findstr.exe.new
  • <SYSTEM32>\fltMc.exe with <SYSTEM32>\fltmc.exe.new
  • <SYSTEM32>\fixmapi.exe with <SYSTEM32>\fixmapi.exe.new
  • <SYSTEM32>\dwwin.exe with <SYSTEM32>\dwwin.exe.new
  • <SYSTEM32>\diskperf.exe with <SYSTEM32>\diskperf.exe.new
  • <SYSTEM32>\diskpart.exe with <SYSTEM32>\diskpart.exe.new
  • <SYSTEM32>\dllhst3g.exe with <SYSTEM32>\dllhst3g.exe.new
  • <SYSTEM32>\dllhost.exe with <SYSTEM32>\dllhost.exe.new
  • <SYSTEM32>\diantz.exe with <SYSTEM32>\diantz.exe.new
  • <SYSTEM32>\defrag.exe with <SYSTEM32>\defrag.exe.new
  • <SYSTEM32>\ddeshare.exe with <SYSTEM32>\ddeshare.exe.new
  • <SYSTEM32>\dfrgntfs.exe with <SYSTEM32>\dfrgntfs.exe.new
  • <SYSTEM32>\dfrgfat.exe with <SYSTEM32>\dfrgfat.exe.new
  • <SYSTEM32>\dmadmin.exe with <SYSTEM32>\dmadmin.exe.new
  • <SYSTEM32>\drwtsn32.exe with <SYSTEM32>\drwtsn32.exe.new
  • <SYSTEM32>\driverquery.exe with <SYSTEM32>\driverquery.exe.new
  • <SYSTEM32>\dvdupgrd.exe with <SYSTEM32>\dvdupgrd.exe.new
  • <SYSTEM32>\dumprep.exe with <SYSTEM32>\dumprep.exe.new
  • <SYSTEM32>\dpvsetup.exe with <SYSTEM32>\dpvsetup.exe.new
  • <SYSTEM32>\doskey.exe with <SYSTEM32>\doskey.exe.new
  • <SYSTEM32>\dmremote.exe with <SYSTEM32>\dmremote.exe.new
  • <SYSTEM32>\dpnsvr.exe with <SYSTEM32>\dpnsvr.exe.new
  • <SYSTEM32>\dplaysvr.exe with <SYSTEM32>\dplaysvr.exe.new