Technical Information
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] '<File name>.exe' = '<SYSTEM32>\<File name>.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.exe
- <Drive name for removable media>:\delete.avi.id-f0851abd.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\dial.bmp.id-f0851abd.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\dashborder_192.bmp.id-f0851abd.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\coffee.bmp.id-f0851abd.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\contosoroot.cer.id-f0851abd.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\contosoroot_1.cer.id-f0851abd.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\pmd.cer.id-f0851abd.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\fi51.doc
- <Drive name for removable media>:\winmine.exe.id-f0851abd.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\tcm851ax32.exe
- <Drive name for removable media>:\notepad.exe.id-f0851abd.[pexdatax@gmail.com].roger
- <Drive name for removable media>:\utorrent.exe
- <SYSTEM32>\<File name>.exe
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\startup\<File name>.exe
- C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\desktop.ini.id-f0851abd.[pexdatax@gmail.com].roger
- D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\desktop.ini.id-f0851abd.[pexdatax@gmail.com].roger
- D:\install.log.id-f0851abd.[pexdatax@gmail.com].roger
- C:\far2\addons\readme.txt.id-f0851abd.[pexdatax@gmail.com].roger
- C:\far2\documentation\eng\arc_support.txt.id-f0851abd.[pexdatax@gmail.com].roger
- C:\far2\documentation\eng\far_faq.txt.id-f0851abd.[pexdatax@gmail.com].roger
- C:\far2\documentation\eng\plugins_install.txt.id-f0851abd.[pexdatax@gmail.com].roger
- C:\far2\documentation\eng\plugins_review.txt.id-f0851abd.[pexdatax@gmail.com].roger
- C:\far2\documentation\eng\techinfo.txt.id-f0851abd.[pexdatax@gmail.com].roger
- C:\far2\documentation\rus\arc_support.txt.id-f0851abd.[pexdatax@gmail.com].roger
- C:\far2\addons\colors\custom_highlighting\black_from_july.reg.id-f0851abd.[pexdatax@gmail.com].roger
- C:\far2\addons\colors\custom_highlighting\black_from_myodov.reg.id-f0851abd.[pexdatax@gmail.com].roger
- C:\far2\documentation\eng\bug_report.txt.id-f0851abd.[pexdatax@gmail.com].roger
- C:\far2\addons\colors\custom_highlighting\colors_from_admin_essp_ru.reg.id-f0851abd.[pexdatax@gmail.com].roger
- C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\desktop.ini.id-f0851abd.[pexdatax@gmail.com].roger
- D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\desktop.ini.id-f0851abd.[pexdatax@gmail.com].roger
- '<SYSTEM32>\cmd.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\mode.com' con cp select=1251