Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'zsevice-455' = '%APPDATA%\lfwhfhe45.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'zsevice-34' = '%APPDATA%\lfwhfhe45.exe'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\help_recover_instructions+ado.txt
- '%APPDATA%\lfwhfhe45.exe'
- '<SYSTEM32>\cmd.exe' /c DEL <Full path to virus>
- <SYSTEM32>\cmd.exe
- ecmd.exe
- C:\Documents and Settings\Default User\Local Settings\History\History.IE5\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Local Settings\History\History.IE5\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Local Settings\History\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Local Settings\History\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Local Settings\Temp\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Local Settings\Temp\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Application Data\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Cookies\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Cookies\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Application Data\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Favorites\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\9.0\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\9.0\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Favorites\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Media Player\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Media Player\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Recent\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\SendTo\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\SendTo\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Start Menu\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Start Menu\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Start Menu\Programs\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Startup\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Startup\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Local Settings\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Local Settings\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\PrintHood\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\PrintHood\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Recent\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\NetHood\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\My Documents\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\My Documents\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\NetHood\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Documents\My Videos\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Documents\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Documents\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Documents\My Videos\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Documents\My Pictures\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Documents\My Pictures\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\DRM\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\DRM\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Favorites\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Favorites\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Documents\My Music\My Playlists\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Documents\My Music\My Playlists\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\help_recover_instructions+ado.txt
- <Current directory>\help_recover_instructions+ado.html
- %APPDATA%\lfwhfhe45.exe
- %HOMEPATH%\My Documents\recover_file_chgqfotve.txt
- <Current directory>\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Documents\My Music\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Documents\My Music\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\0338E140\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\0338E140\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\Media Player\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\Media Player\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs\help_recover_instructions+ado.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs\help_recover_instructions+ado.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Games\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Start Menu\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Templates\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Templates\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Start Menu\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Games\help_recover_instructions+ado.html
- %ALLUSERSPROFILE%\Start Menu\Programs\help_recover_instructions+ado.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\help_recover_instructions+ado.html
- 'su###est.com':80
- 'www.ne###vis.org':80
- 'ya####gulten.com':80
- 'sa####atrading.com':80
- 'ip.#yk.nu':80
- 'www.sh#######wakarmaengworks.com':80
- 'su#####housebuyers.com':80
- http://ip.#yk.nu/
- http://su###est.com/mssys.php
- http://www.ne###vis.org/administrator/components/com_acymailing/extensions/plg_editors_acyeditor/acyeditor/ckeditor/plugins/image/dialogs/miscinfo.php
- http://ya####gulten.com/dbsys.php
- http://www.sh#######wakarmaengworks.com/mssys.php
- http://su#####housebuyers.com/images/watermarks/original/mssys.php
- http://sa####atrading.com/mssys.php
- DNS ASK su###est.com
- DNS ASK www.ne###vis.org
- DNS ASK ya####gulten.com
- DNS ASK sa####atrading.com
- DNS ASK ip.#yk.nu
- DNS ASK www.sh#######wakarmaengworks.com
- DNS ASK su#####housebuyers.com
- ClassName: 'Indicator' WindowName: ''