Technical Information
- [<HKLM>\SOFTWARE\Classes\VVPCKTEPWJIMFBD\shell\open\command] '' = '%TEMP%\78rwp2F8NiE35G6.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'winserveupd' = '%TEMP%\78rwp2F8NiE35G6.exe'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\READMETOUNLOCK.txt
- C:\Far2\Plugins\FileCase\READMETOUNLOCK.txt
- C:\Far2\Plugins\FarCmds\READMETOUNLOCK.txt
- C:\Far2\Plugins\ExtSearch\sources\RegExp\READMETOUNLOCK.txt
- C:\Far2\Plugins\HlfViewer\READMETOUNLOCK.txt
- C:\Far2\Plugins\FTP\lib\READMETOUNLOCK.txt
- C:\Far2\Plugins\FTP\READMETOUNLOCK.txt
- C:\Far2\Plugins\ExtSearch\sources\READMETOUNLOCK.txt
- C:\Far2\Plugins\EMenu\READMETOUNLOCK.txt
- C:\Far2\Plugins\EditCase\READMETOUNLOCK.txt
- C:\Far2\Plugins\DrawLine\READMETOUNLOCK.txt
- C:\Far2\Plugins\ExtSearch\keys\READMETOUNLOCK.txt
- C:\Far2\Plugins\ExtSearch\READMETOUNLOCK.txt
- C:\Far2\Plugins\ExtSearch\doc\READMETOUNLOCK.txt
- C:\Far2\Plugins\MacroView\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\DW\1028\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\DW\1025\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\DAO\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\DW\1036\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\DW\1033\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\DW\1031\READMETOUNLOCK.txt
- <Auxiliary element>
- C:\Far2\Plugins\TmpPanel\READMETOUNLOCK.txt
- C:\Far2\Plugins\ProcList\READMETOUNLOCK.txt
- C:\Far2\Plugins\Network\READMETOUNLOCK.txt
- C:\Far2\PluginSDK\Headers.pas\READMETOUNLOCK.txt
- C:\Far2\PluginSDK\Headers.c\READMETOUNLOCK.txt
- C:\Far2\Plugins\WinSCP\READMETOUNLOCK.txt
- C:\Far2\Plugins\Compare\READMETOUNLOCK.txt
- C:\Far2\READMETOUNLOCK.txt
- C:\Far2\Addons\XLat\Russian\READMETOUNLOCK.txt
- C:\Far2\Addons\XLat\READMETOUNLOCK.txt
- C:\Far2\Encyclopedia\READMETOUNLOCK.txt
- C:\Far2\Documentation\rus\READMETOUNLOCK.txt
- C:\Far2\Documentation\eng\READMETOUNLOCK.txt
- C:\Far2\Addons\Shell\READMETOUNLOCK.txt
- C:\Far2\Addons\Colors\READMETOUNLOCK.txt
- C:\Far2\Addons\Colors\Default Highlighting\READMETOUNLOCK.txt
- C:\Far2\Addons\Colors\Custom Highlighting\READMETOUNLOCK.txt
- C:\Far2\Addons\SetUp\READMETOUNLOCK.txt
- C:\Far2\Addons\Macros\READMETOUNLOCK.txt
- C:\Far2\Addons\READMETOUNLOCK.txt
- C:\Far2\FExcept\READMETOUNLOCK.txt
- C:\Far2\Plugins\Colorer\hrc\READMETOUNLOCK.txt
- C:\Far2\Plugins\Colorer\hrc\auto\types\READMETOUNLOCK.txt
- C:\Far2\Plugins\Colorer\hrc\auto\READMETOUNLOCK.txt
- C:\Far2\Plugins\Colorer\hrd\console\contrib\READMETOUNLOCK.txt
- C:\Far2\Plugins\Colorer\hrd\console\READMETOUNLOCK.txt
- C:\Far2\Plugins\Colorer\hrd\READMETOUNLOCK.txt
- C:\Far2\Plugins\Colorer\READMETOUNLOCK.txt
- C:\Far2\Plugins\arclite\READMETOUNLOCK.txt
- C:\Far2\Plugins\Align\READMETOUNLOCK.txt
- C:\Far2\Plugins\7-Zip\READMETOUNLOCK.txt
- C:\Far2\Plugins\Colorer\bin\READMETOUNLOCK.txt
- C:\Far2\Plugins\Brackets\READMETOUNLOCK.txt
- C:\Far2\Plugins\AutoWrap\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\search\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\safebrowsing\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\preferences\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\places\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\feeds\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\preferences\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\history\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\feeds\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\certerror\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\places\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\pageinfo\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\migration\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\tabbrowser\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\en-US\locale\branding\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\communicator\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\feeds\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\downloads\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\tabview\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\feeds\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\tabview\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\tabbrowser\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\preferences\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\places\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\bookmarks\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\VC\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\Speech\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\Speech\1033\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\web server extensions\40\bin\1033\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\Web Folders\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\VGX\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\MSInfo\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\DW\1042\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\DW\1041\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\DW\1040\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\DW\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\DW\3082\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\DW\2052\READMETOUNLOCK.txt
- %CommonProgramFiles%\Microsoft Shared\web server extensions\40\bin\READMETOUNLOCK.txt
- %CommonProgramFiles%\System\Ole DB\READMETOUNLOCK.txt
- %CommonProgramFiles%\System\msadc\READMETOUNLOCK.txt
- %CommonProgramFiles%\System\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\chrome\browser\content\branding\READMETOUNLOCK.txt
- %PROGRAM_FILES%\FireFox\READMETOUNLOCK.txt
- %CommonProgramFiles%\System\ado\READMETOUNLOCK.txt
- %CommonProgramFiles%\Services\READMETOUNLOCK.txt
- %CommonProgramFiles%\MSSoap\Binaries\Resources\1033\READMETOUNLOCK.txt
- %CommonProgramFiles%\MSSoap\Binaries\READMETOUNLOCK.txt
- %CommonProgramFiles%\SpeechEngines\Microsoft\TTS\1033\READMETOUNLOCK.txt
- %CommonProgramFiles%\SpeechEngines\Microsoft\READMETOUNLOCK.txt
- %CommonProgramFiles%\SpeechEngines\Microsoft\Lexicon\1033\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\SendTo\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Local Settings\History\History.IE5\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Media Player\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Cookies\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Local Settings\History\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Local Settings\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\9.0\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Start Menu\READMETOUNLOCK.txt
- C:\Documents and Settings\LocalService\Local Settings\READMETOUNLOCK.txt
- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\READMETOUNLOCK.txt
- C:\Documents and Settings\LocalService\Local Settings\Application Data\READMETOUNLOCK.txt
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\BGGTYMH1\READMETOUNLOCK.txt
- C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\READMETOUNLOCK.txt
- C:\Documents and Settings\LocalService\Local Settings\History\READMETOUNLOCK.txt
- C:\Documents and Settings\LocalService\Cookies\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Templates\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Startup\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\READMETOUNLOCK.txt
- C:\Documents and Settings\Default User\Application Data\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Application Data\Microsoft\Network\Connections\Pbk\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Documents\My Music\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Documents\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Application Data\Microsoft\Media Player\READMETOUNLOCK.txt
- <Current directory>\READMETOUNLOCK.txt
- C:\READMETOUNLOCK.txt
- %TEMP%\78rwp2F8NiE35G6.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\Dr Watson\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Application Data\Microsoft\Crypto\RSA\S-1-5-18\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Application Data\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\0338E140\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Games\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Documents\My Videos\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Documents\My Pictures\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\Start Menu\READMETOUNLOCK.txt
- %ALLUSERSPROFILE%\DRM\READMETOUNLOCK.txt
- <LS_APPDATA>\Mozilla\Firefox\Profiles\cwdgt0y8.default\READMETOUNLOCK.txt
- <LS_APPDATA>\Mozilla\Firefox\Profiles\cwdgt0y8.default\startupCache\READMETOUNLOCK.txt
- <LS_APPDATA>\Mozilla\Firefox\Profiles\cwdgt0y8.default\Cache\READMETOUNLOCK.txt
- %HOMEPATH%\Local Settings\History\READMETOUNLOCK.txt
- %HOMEPATH%\Local Settings\READMETOUNLOCK.txt
- <LS_APPDATA>\VMware\READMETOUNLOCK.txt
- <LS_APPDATA>\Microsoft\Windows Media\9.0\READMETOUNLOCK.txt
- <LS_APPDATA>\READMETOUNLOCK.txt
- %HOMEPATH%\Favorites\Links\READMETOUNLOCK.txt
- %HOMEPATH%\Favorites\READMETOUNLOCK.txt
- <LS_APPDATA>\Microsoft\Windows\READMETOUNLOCK.txt
- <LS_APPDATA>\Microsoft\Media Player\READMETOUNLOCK.txt
- <LS_APPDATA>\Identities\{5518F2FB-DB74-45A3-BEC1-4575D8D9DC84}\Microsoft\Outlook Express\READMETOUNLOCK.txt
- %HOMEPATH%\Local Settings\History\History.IE5\READMETOUNLOCK.txt
- %HOMEPATH%\My Documents\My Pictures\READMETOUNLOCK.txt
- %HOMEPATH%\My Documents\My Music\READMETOUNLOCK.txt
- %HOMEPATH%\My Documents\READMETOUNLOCK.txt
- %HOMEPATH%\SendTo\READMETOUNLOCK.txt
- %HOMEPATH%\Recent\READMETOUNLOCK.txt
- %HOMEPATH%\READMETOUNLOCK.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\READMETOUNLOCK.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\READMETOUNLOCK.txt
- %TEMP%\READMETOUNLOCK.txt
- %HOMEPATH%\Local Settings\History\History.IE5\MSHist012011111020111111\READMETOUNLOCK.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\READMETOUNLOCK.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\READMETOUNLOCK.txt
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\READMETOUNLOCK.txt
- %HOMEPATH%\Cookies\READMETOUNLOCK.txt
- C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\READMETOUNLOCK.txt
- C:\Documents and Settings\NetworkService\Local Settings\History\READMETOUNLOCK.txt
- C:\Documents and Settings\NetworkService\Local Settings\READMETOUNLOCK.txt
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\READMETOUNLOCK.txt
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\READMETOUNLOCK.txt
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\READMETOUNLOCK.txt
- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\READMETOUNLOCK.txt
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\LBMMC3H3\READMETOUNLOCK.txt
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\READMETOUNLOCK.txt
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\READMETOUNLOCK.txt
- C:\Documents and Settings\LocalService\READMETOUNLOCK.txt
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\READMETOUNLOCK.txt
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\MOE00UY1\READMETOUNLOCK.txt
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\READMETOUNLOCK.txt
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\bookmarkbackups\READMETOUNLOCK.txt
- %APPDATA%\Microsoft\Windows\Themes\READMETOUNLOCK.txt
- %APPDATA%\Microsoft\Media Player\READMETOUNLOCK.txt
- %APPDATA%\Mozilla\Firefox\READMETOUNLOCK.txt
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\chrome\READMETOUNLOCK.txt
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\READMETOUNLOCK.txt
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\READMETOUNLOCK.txt
- C:\Documents and Settings\NetworkService\READMETOUNLOCK.txt
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\READMETOUNLOCK.txt
- C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\READMETOUNLOCK.txt
- %APPDATA%\Microsoft\Internet Explorer\READMETOUNLOCK.txt
- %APPDATA%\Microsoft\Address Book\READMETOUNLOCK.txt
- %APPDATA%\READMETOUNLOCK.txt