Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Control\Session Manager] 'BootExecute' = 'autocheck autochk *'
- [HKLM\SYSTEM\CurrentControlSet\Services\ampa] 'ImagePath' = '<SYSTEM32>\ampa.sys'
- 'ampa' <SYSTEM32>\ampa.sys
- <SYSTEM32>\cmd.exe
- [HKLM\Software\Microsoft\IdentityCRL]
- %HOMEPATH%\desktop\13.jpeg
- %HOMEPATH%\desktop\3.jpeg
- %HOMEPATH%\desktop\4f0bf7ff71f28.jpeg
- %HOMEPATH%\desktop\adhd_and_obesity.docx
- %HOMEPATH%\desktop\coffee.bmp
- %HOMEPATH%\desktop\contosoroot.cer
- %HOMEPATH%\desktop\contoso_1.cer
- %HOMEPATH%\desktop\dial.bmp
- %HOMEPATH%\desktop\hanni_umami_chapter.doc
- %HOMEPATH%\desktop\howto-index.html
- %HOMEPATH%\desktop\iisstart.html
- %HOMEPATH%\desktop\issi2013_template_for_posters.docx
- %HOMEPATH%\desktop\ituneshelpunavailable.htm
- %HOMEPATH%\desktop\parnas_01.jpeg
- %HOMEPATH%\desktop\pmd.cer
- %HOMEPATH%\desktop\region-north-karelia.jpeg
- %HOMEPATH%\desktop\split.avi
- %HOMEPATH%\desktop\tileimage.bmp
- %HOMEPATH%\desktop\toolbar.bmp
- %HOMEPATH%\desktop\tree_view.html
- %HOMEPATH%\desktop\trivial-merge.html
- %TEMP%\~1396858408331679436~\sg.tmp
- %TEMP%\~3018279076044292319\2gpt_bcd
- %TEMP%\~3018279076044292319\2mbr_bcd
- %TEMP%\~3018279076044292319\cf
- %TEMP%\~3018279076044292319\cfg.ini
- %TEMP%\~3018279076044292319\crash2.dmp
- %TEMP%\~3018279076044292319\install.bat
- %TEMP%\~3018279076044292319\lang\cn.txt
- %TEMP%\~3018279076044292319\language.ini
- %TEMP%\~3018279076044292319\license.rtf
- %TEMP%\~3018279076044292319\manual.pdf
- %TEMP%\~3018279076044292319\microsoft.vc80.crt.manifest
- %TEMP%\~3018279076044292319\microsoft.vc80.mfc.manifest
- %TEMP%\~3018279076044292319\other.ini
- %TEMP%\~3018279076044292319\pacfg.ini
- %TEMP%\~3018279076044292319\readme.rtf
- %TEMP%\~3018279076044292319\unins000.dat
- %TEMP%\~3018279076044292319\uninstall.bat
- %TEMP%\~3018279076044292319\winpeshl.ini
- %TEMP%\~3018279076044292319\wnd.ini
- %TEMP%\~3018279076044292319\7z.dll
- %TEMP%\~3018279076044292319\7z.exe
- %TEMP%\~3018279076044292319\ambooter.exe
- %TEMP%\~3018279076044292319\bcdboot.exe
- %TEMP%\~3018279076044292319\botva2.dll
- %TEMP%\~3018279076044292319\callbackctrl.dll
- %TEMP%\~3018279076044292319\dyndiskconverter.exe
- %TEMP%\~3018279076044292319\epw.exe
- %TEMP%\~3018279076044292319\exfat.dll
- %TEMP%\~3018279076044292319\garunonce.exe
- %TEMP%\~3018279076044292319\gptbcd.dll
- %TEMP%\~3018279076044292319\help.exe
- %TEMP%\~3018279076044292319\iconv.dll
- %TEMP%\~3018279076044292319\libgcc_s_sjlj-1.dll
- %TEMP%\~3018279076044292319\libwim-15.dll
- %TEMP%\~3018279076044292319\libxml2-2.dll
- %TEMP%\~3018279076044292319\loaddrv.exe
- %TEMP%\~3018279076044292319\loaddrv_win32.exe
- %TEMP%\~3018279076044292319\loaddrv_x64.exe
- %TEMP%\~3018279076044292319\mfc80.dll
- %TEMP%\~3018279076044292319\mfc80u.dll
- %TEMP%\~3018279076044292319\mfcm80.dll
- %TEMP%\~3018279076044292319\mfcm80u.dll
- %TEMP%\~3018279076044292319\msvcm80.dll
- %TEMP%\~3018279076044292319\msvcp80.dll
- %TEMP%\~3018279076044292319\msvcr80.dll
- %TEMP%\~3018279076044292319\native\w2k\x86\fre\ampa.exe
- %TEMP%\~3018279076044292319\native\w2k\x86\fre\ampa.sys
- %TEMP%\~3018279076044292319\native\wlh\amd64\fre\ampa.exe
- %TEMP%\~3018279076044292319\native\wlh\amd64\fre\ampa.sys
- %TEMP%\~3018279076044292319\native\wlh\x86\fre\ampa.exe
- %TEMP%\~3018279076044292319\native\wlh\x86\fre\ampa.sys
- %TEMP%\~3018279076044292319\native\wnet\amd64\fre\ampa.exe
- %TEMP%\~3018279076044292319\native\wnet\amd64\fre\ampa.sys
- %TEMP%\~3018279076044292319\ntfs2fat32.exe
- %TEMP%\~3018279076044292319\partassist.exe
- %TEMP%\~3018279076044292319\pathformat.dll
- %TEMP%\~3018279076044292319\pe.dll
- %TEMP%\~3018279076044292319\pe\driver\amd64\msahci.sys
- %TEMP%\~3018279076044292319\pe\driver\i386\msahci.sys
- %TEMP%\~3018279076044292319\peloaddrv.exe
- %TEMP%\~3018279076044292319\pthreadgc2.dll
- %TEMP%\~3018279076044292319\scanpartition.dll
- %TEMP%\~3018279076044292319\setupgreen32.exe
- %TEMP%\~3018279076044292319\setupgreen64.exe
- %TEMP%\~3018279076044292319\ssdsecurityerase.dll
- %TEMP%\~3018279076044292319\unins000.exe
- %TEMP%\~3018279076044292319\uninstallab.dll
- %TEMP%\~3018279076044292319\upgradeshow.dll
- %TEMP%\~3018279076044292319\version.dll
- %TEMP%\~3018279076044292319\vhdmgr.dll
- %TEMP%\~3018279076044292319\webctrl.dll
- %TEMP%\~3018279076044292319\wimgapi.dll
- %TEMP%\~3018279076044292319\wimlib-imagex.exe
- %TEMP%\~3018279076044292319\wimmgr.dll
- %TEMP%\~3018279076044292319\winchk.exe
- %TEMP%\~3018279076044292319\wintogo.exe
- %WINDIR%\ga_of.dat
- %TEMP%\~3018279076044292319\log\ampa0.log
- %WINDIR%\ampa.exe
- %WINDIR%\syswow64\ampa.sys
- <SYSTEM32>\ampa.sys
- C:\amtag.bin
- C:\amtag.bin
- '%TEMP%\~1396858408331679436~\sg.tmp' x "<Full path to file>" -y -aoa -o"%TEMP%\~3018279076044292319"
- '%TEMP%\~3018279076044292319\partassist.exe'
- '%TEMP%\~3018279076044292319\setupgreen64.exe' -u
- '%TEMP%\~3018279076044292319\loaddrv_x64.exe' -u
- '%TEMP%\~3018279076044292319\setupgreen64.exe'
- '%TEMP%\~3018279076044292319\loaddrv_x64.exe'
- '<SYSTEM32>\cmd.exe' /c set
- '<SYSTEM32>\cmd.exe' \c ""%TEMP%\~3018279076044292319\install.bat""
- '<SYSTEM32>\cmd.exe' /S /D /c" ver"
- '<SYSTEM32>\findstr.exe' "5.0"
- '<SYSTEM32>\findstr.exe' "5.1"
- '<SYSTEM32>\findstr.exe' "5.2"
- '<SYSTEM32>\findstr.exe' "6.0"
- '<SYSTEM32>\findstr.exe' "6.1"
- '<SYSTEM32>\cmd.exe' /c set' (with hidden window)
- '%TEMP%\~1396858408331679436~\sg.tmp' x "<Full path to file>" -y -aoa -o"%TEMP%\~3018279076044292319"' (with hidden window)
- '<SYSTEM32>\cmd.exe' \c ""%TEMP%\~3018279076044292319\install.bat""' (with hidden window)
- '%TEMP%\~3018279076044292319\setupgreen64.exe' -u' (with hidden window)
- '%TEMP%\~3018279076044292319\loaddrv_x64.exe' -u' (with hidden window)
- '%TEMP%\~3018279076044292319\setupgreen64.exe' ' (with hidden window)
- '%TEMP%\~3018279076044292319\loaddrv_x64.exe' ' (with hidden window)