Technical Information
- <SYSTEM32>\winver.exe with <SYSTEM32>\winver.exe
- <SYSTEM32>\bad8 with <SYSTEM32>\winver.exe
- <SYSTEM32>\winmsd.exe with <SYSTEM32>\winmsd.exe
- <SYSTEM32>\wpabaln.exe with <SYSTEM32>\wpabaln.exe
- <SYSTEM32>\dllhost.exe with <SYSTEM32>\dllhost.exe.new
- <SYSTEM32>\bad9 with <SYSTEM32>\wowdeb.exe
- <SYSTEM32>\diskperf.exe with <SYSTEM32>\diskperf.exe.new
- <SYSTEM32>\winhlp32.exe with <SYSTEM32>\winhlp32.exe
- <SYSTEM32>\bad102 with <SYSTEM32>\winhlp32.exe
- <SYSTEM32>\winchat.exe with <SYSTEM32>\winchat.exe
- <SYSTEM32>\winmine.exe with <SYSTEM32>\winmine.exe
- <SYSTEM32>\bad100 with <SYSTEM32>\winmine.exe
- <SYSTEM32>\winlogon.exe with <SYSTEM32>\winlogon.exe
- <SYSTEM32>\dllhst3g.exe with <SYSTEM32>\dllhst3g.exe.new
- <SYSTEM32>\wuauclt1.exe with <SYSTEM32>\wuauclt1.exe
- <SYSTEM32>\bad42 with <SYSTEM32>\wuauclt1.exe
- <SYSTEM32>\wuauclt.exe with <SYSTEM32>\wuauclt.exe
- <SYSTEM32>\xcopy.exe with <SYSTEM32>\xcopy.exe
- <SYSTEM32>\wupdmgr.exe with <SYSTEM32>\wupdmgr.exe
- <SYSTEM32>\dmadmin.exe with <SYSTEM32>\dmadmin.exe.new
- <SYSTEM32>\bad142 with <SYSTEM32>\wuauclt.exe
- <SYSTEM32>\write.exe with <SYSTEM32>\write.exe
- <SYSTEM32>\bad96 with <SYSTEM32>\write.exe
- <SYSTEM32>\wpnpinst.exe with <SYSTEM32>\wpnpinst.exe
- <SYSTEM32>\wscript.exe with <SYSTEM32>\wscript.exe
- <SYSTEM32>\wscntfy.exe with <SYSTEM32>\wscntfy.exe
- <SYSTEM32>\bad15 with <SYSTEM32>\wscntfy.exe
- <SYSTEM32>\diskpart.exe with <SYSTEM32>\diskpart.exe.new
- <SYSTEM32>\bad53 with <SYSTEM32>\user.exe
- <SYSTEM32>\ups.exe with <SYSTEM32>\ups.exe
- <SYSTEM32>\dfrgfat.exe with <SYSTEM32>\dfrgfat.exe.new
- <SYSTEM32>\usrmlnka.exe with <SYSTEM32>\usrmlnka.exe
- <SYSTEM32>\bad39 with <SYSTEM32>\usrmlnka.exe
- <SYSTEM32>\userinit.exe with <SYSTEM32>\userinit.exe
- <SYSTEM32>\upnpcont.exe with <SYSTEM32>\upnpcont.exe
- <SYSTEM32>\typeperf.exe with <SYSTEM32>\typeperf.exe
- <SYSTEM32>\bad3 with <SYSTEM32>\typeperf.exe
- <SYSTEM32>\defrag.exe with <SYSTEM32>\defrag.exe.new
- <SYSTEM32>\bad140 with <SYSTEM32>\upnpcont.exe
- <SYSTEM32>\unlodctr.exe with <SYSTEM32>\unlodctr.exe
- <SYSTEM32>\bad122 with <SYSTEM32>\unlodctr.exe
- <SYSTEM32>\dfrgntfs.exe with <SYSTEM32>\dfrgntfs.exe.new
- <SYSTEM32>\w32tm.exe with <SYSTEM32>\w32tm.exe
- <SYSTEM32>\vssvc.exe with <SYSTEM32>\vssvc.exe
- <SYSTEM32>\diantz.exe with <SYSTEM32>\diantz.exe.new
- <SYSTEM32>\wiaacmgr.exe with <SYSTEM32>\wiaacmgr.exe
- <SYSTEM32>\bad32 with <SYSTEM32>\wiaacmgr.exe
- <SYSTEM32>\wextract.exe with <SYSTEM32>\wextract.exe
- <SYSTEM32>\vssadmin.exe with <SYSTEM32>\vssadmin.exe
- <SYSTEM32>\usrshuta.exe with <SYSTEM32>\usrshuta.exe
- <SYSTEM32>\bad82 with <SYSTEM32>\usrshuta.exe
- <SYSTEM32>\usrprbda.exe with <SYSTEM32>\usrprbda.exe
- <SYSTEM32>\bad136 with <SYSTEM32>\vssadmin.exe
- <SYSTEM32>\verifier.exe with <SYSTEM32>\verifier.exe
- <SYSTEM32>\bad12 with <SYSTEM32>\utilman.exe
- <SYSTEM32>\dmremote.exe with <SYSTEM32>\dmremote.exe.new
- <SYSTEM32>\extrac32.exe with <SYSTEM32>\extrac32.exe.new
- <SYSTEM32>\expand.exe with <SYSTEM32>\expand.exe.new
- <SYSTEM32>\eventvwr.exe with <SYSTEM32>\eventvwr.exe.new
- <SYSTEM32>\findstr.exe with <SYSTEM32>\findstr.exe.new
- <SYSTEM32>\find.exe with <SYSTEM32>\find.exe.new
- <SYSTEM32>\fc.exe with <SYSTEM32>\fc.exe.new
- <SYSTEM32>\eventtriggers.exe with <SYSTEM32>\eventtriggers.exe.new
- <SYSTEM32>\wbem\wmiprvse.exe with <SYSTEM32>\wbem\wmiprvse.exe
- <SYSTEM32>\wbem\wmic.exe with <SYSTEM32>\wbem\wmic.exe
- <SYSTEM32>\wbem\wmiapsrv.exe with <SYSTEM32>\wbem\wmiapsrv.exe
- <SYSTEM32>\XPSViewer\XPSViewer.exe with <SYSTEM32>\XPSViewer\XPSViewer.exe
- <SYSTEM32>\eventcreate.exe with <SYSTEM32>\eventcreate.exe.new
- <SYSTEM32>\eudcedit.exe with <SYSTEM32>\eudcedit.exe.new
- <SYSTEM32>\finger.exe with <SYSTEM32>\finger.exe.new
- <SYSTEM32>\dllcache\agentsvr.exe with <SYSTEM32>\dllcache\agentsvr.exe.new
- <SYSTEM32>\getmac.exe with <SYSTEM32>\getmac.exe.new
- <SYSTEM32>\ftp.exe with <SYSTEM32>\ftp.exe.new
- <SYSTEM32>\grpconv.exe with <SYSTEM32>\grpconv.exe.new
- <SYSTEM32>\gpupdate.exe with <SYSTEM32>\gpupdate.exe.new
- <SYSTEM32>\gpresult.exe with <SYSTEM32>\gpresult.exe.new
- <SYSTEM32>\fsutil.exe with <SYSTEM32>\fsutil.exe.new
- <SYSTEM32>\fontview.exe with <SYSTEM32>\fontview.exe.new
- <SYSTEM32>\fltMc.exe with <SYSTEM32>\fltmc.exe.new
- <SYSTEM32>\fixmapi.exe with <SYSTEM32>\fixmapi.exe.new
- <SYSTEM32>\freecell.exe with <SYSTEM32>\freecell.exe.new
- <Auxiliary element> with <Auxiliary element>
- <SYSTEM32>\forcedos.exe with <SYSTEM32>\forcedos.exe.new
- <SYSTEM32>\esentutl.exe with <SYSTEM32>\esentutl.exe.new
- <SYSTEM32>\oobe\oobebaln.exe with <SYSTEM32>\oobe\oobebaln.exe
- <SYSTEM32>\drwtsn32.exe with <SYSTEM32>\drwtsn32.exe.new
- <SYSTEM32>\oobe\msoobe.exe with <SYSTEM32>\oobe\msoobe.exe
- <SYSTEM32>\Restore\srdiag.exe with <SYSTEM32>\Restore\srdiag.exe
- <SYSTEM32>\Restore\rstrui.exe with <SYSTEM32>\Restore\rstrui.exe
- <SYSTEM32>\dumprep.exe with <SYSTEM32>\dumprep.exe.new
- <SYSTEM32>\npp\nppagent.exe with <SYSTEM32>\npp\nppagent.exe
- <SYSTEM32>\Com\comrereg.exe with <SYSTEM32>\Com\comrereg.exe
- <SYSTEM32>\Com\comrepl.exe with <SYSTEM32>\Com\comrepl.exe
- <SYSTEM32>\doskey.exe with <SYSTEM32>\doskey.exe.new
- <SYSTEM32>\driverquery.exe with <SYSTEM32>\driverquery.exe.new
- <SYSTEM32>\dpnsvr.exe with <SYSTEM32>\dpnsvr.exe.new
- <SYSTEM32>\dplaysvr.exe with <SYSTEM32>\dplaysvr.exe.new
- <SYSTEM32>\dvdupgrd.exe with <SYSTEM32>\dvdupgrd.exe.new
- <SYSTEM32>\wbem\unsecapp.exe with <SYSTEM32>\wbem\unsecapp.exe
- <SYSTEM32>\wbem\scrcons.exe with <SYSTEM32>\wbem\scrcons.exe
- <SYSTEM32>\dxdiag.exe with <SYSTEM32>\dxdiag.exe.new
- <SYSTEM32>\wbem\wmiadap.exe with <SYSTEM32>\wbem\wmiadap.exe
- <SYSTEM32>\wbem\winmgmt.exe with <SYSTEM32>\wbem\winmgmt.exe
- <SYSTEM32>\wbem\wbemtest.exe with <SYSTEM32>\wbem\wbemtest.exe
- <SYSTEM32>\wbem\mofcomp.exe with <SYSTEM32>\wbem\mofcomp.exe
- <SYSTEM32>\dwwin.exe with <SYSTEM32>\dwwin.exe.new
- <SYSTEM32>\URTTEMP\regtlib.exe with <SYSTEM32>\URTTEMP\regtlib.exe
- <SYSTEM32>\spool\prtprocs\w32x86\printfilterpipelinesvc.exe with <SYSTEM32>\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
- <SYSTEM32>\usmt\migwiz_a.exe with <SYSTEM32>\usmt\migwiz_a.exe
- <SYSTEM32>\usmt\migwiz.exe with <SYSTEM32>\usmt\migwiz.exe
- <SYSTEM32>\usmt\migload.exe with <SYSTEM32>\usmt\migload.exe
- <SYSTEM32>\TsWpfWrp.exe with <SYSTEM32>\TsWpfWrp.exe
- <SYSTEM32>\shutdown.exe with <SYSTEM32>\shutdown.exe
- <SYSTEM32>\shrpubw.exe with <SYSTEM32>\shrpubw.exe
- <SYSTEM32>\bad162 with <SYSTEM32>\shrpubw.exe
- <SYSTEM32>\cmd.exe with <SYSTEM32>\cmd.exe.new
- <SYSTEM32>\sigverif.exe with <SYSTEM32>\sigverif.exe
- <SYSTEM32>\bad81 with <SYSTEM32>\sigverif.exe
- <SYSTEM32>\shmgrate.exe with <SYSTEM32>\shmgrate.exe
- <SYSTEM32>\bad48 with <SYSTEM32>\setver.exe
- <SYSTEM32>\setup.exe with <SYSTEM32>\setup.exe
- <SYSTEM32>\bad63 with <SYSTEM32>\setup.exe
- <SYSTEM32>\clipsrv.exe with <SYSTEM32>\clipsrv.exe.new
- <SYSTEM32>\shadow.exe with <SYSTEM32>\shadow.exe
- <SYSTEM32>\sfc.exe with <SYSTEM32>\sfc.exe
- <SYSTEM32>\skeys.exe with <SYSTEM32>\skeys.exe
- <SYSTEM32>\sol.exe with <SYSTEM32>\sol.exe
- <SYSTEM32>\bad144 with <SYSTEM32>\sol.exe
- <SYSTEM32>\sndvol32.exe with <SYSTEM32>\sndvol32.exe
- <SYSTEM32>\bad74 with <SYSTEM32>\spider.exe
- <SYSTEM32>\sort.exe with <SYSTEM32>\sort.exe
- <SYSTEM32>\cmmon32.exe with <SYSTEM32>\cmmon32.exe.new
- <SYSTEM32>\bad139 with <SYSTEM32>\sndvol32.exe
- <SYSTEM32>\cmdl32.exe with <SYSTEM32>\cmdl32.exe.new
- <SYSTEM32>\smlogsvc.exe with <SYSTEM32>\smlogsvc.exe
- <SYSTEM32>\bad54 with <SYSTEM32>\smbinst.exe
- <SYSTEM32>\sndrec32.exe with <SYSTEM32>\sndrec32.exe
- <SYSTEM32>\bad42 with <SYSTEM32>\sndrec32.exe
- <SYSTEM32>\smss.exe with <SYSTEM32>\smss.exe
- <SYSTEM32>\sethc.exe with <SYSTEM32>\sethc.exe
- <SYSTEM32>\cisvc.exe with <SYSTEM32>\cisvc.exe.new
- <SYSTEM32>\rtcshare.exe with <SYSTEM32>\rtcshare.exe
- <SYSTEM32>\bad127 with <SYSTEM32>\rtcshare.exe
- <SYSTEM32>\runonce.exe with <SYSTEM32>\runonce.exe
- <SYSTEM32>\rundll32.exe with <SYSTEM32>\rundll32.exe
- <SYSTEM32>\runas.exe with <SYSTEM32>\runas.exe
- <SYSTEM32>\rsvp.exe with <SYSTEM32>\rsvp.exe
- <SYSTEM32>\rsnotify.exe with <SYSTEM32>\rsnotify.exe
- <SYSTEM32>\rsmui.exe with <SYSTEM32>\rsmui.exe
- <SYSTEM32>\bad91 with <SYSTEM32>\rsmui.exe
- <SYSTEM32>\rsopprov.exe with <SYSTEM32>\rsopprov.exe
- <SYSTEM32>\cipher.exe with <SYSTEM32>\cipher.exe.new
- <SYSTEM32>\bad167 with <SYSTEM32>\rsopprov.exe
- <SYSTEM32>\rwinsta.exe with <SYSTEM32>\rwinsta.exe
- <SYSTEM32>\secedit.exe with <SYSTEM32>\secedit.exe
- <SYSTEM32>\cleanmgr.exe with <SYSTEM32>\cleanmgr.exe.new
- <SYSTEM32>\sdbinst.exe with <SYSTEM32>\sdbinst.exe
- <SYSTEM32>\clipbrd.exe with <SYSTEM32>\clipbrd.exe.new
- <SYSTEM32>\sessmgr.exe with <SYSTEM32>\sessmgr.exe
- <SYSTEM32>\services.exe with <SYSTEM32>\services.exe
- <SYSTEM32>\bad182 with <SYSTEM32>\sdbinst.exe
- <SYSTEM32>\savedump.exe with <SYSTEM32>\savedump.exe
- <SYSTEM32>\ckcnv.exe with <SYSTEM32>\ckcnv.exe.new
- <SYSTEM32>\bad116 with <SYSTEM32>\savedump.exe
- <SYSTEM32>\schtasks.exe with <SYSTEM32>\schtasks.exe
- <SYSTEM32>\scardsvr.exe with <SYSTEM32>\scardsvr.exe
- <SYSTEM32>\sc.exe with <SYSTEM32>\sc.exe
- <SYSTEM32>\spider.exe with <SYSTEM32>\spider.exe
- <SYSTEM32>\bad49 with <SYSTEM32>\tlntsvr.exe
- <SYSTEM32>\tlntsess.exe with <SYSTEM32>\tlntsess.exe
- <SYSTEM32>\tlntadmn.exe with <SYSTEM32>\tlntadmn.exe
- <SYSTEM32>\tourstart.exe with <SYSTEM32>\tourstart.exe
- <SYSTEM32>\bad143 with <SYSTEM32>\tourstart.exe
- <SYSTEM32>\tlntsvr.exe with <SYSTEM32>\tlntsvr.exe
- <SYSTEM32>\bad108 with <SYSTEM32>\tlntadmn.exe
- <SYSTEM32>\telnet.exe with <SYSTEM32>\telnet.exe
- <SYSTEM32>\tcpsvcs.exe with <SYSTEM32>\tcpsvcs.exe
- <SYSTEM32>\bad60 with <SYSTEM32>\tcpsvcs.exe
- <SYSTEM32>\convert.exe with <SYSTEM32>\convert.exe.new
- <SYSTEM32>\tftp.exe with <SYSTEM32>\tftp.exe
- <SYSTEM32>\bad7 with <SYSTEM32>\tftp.exe
- <SYSTEM32>\dcomcnfg.exe with <SYSTEM32>\dcomcnfg.exe.new
- <SYSTEM32>\tsdiscon.exe with <SYSTEM32>\tsdiscon.exe
- <SYSTEM32>\bad138 with <SYSTEM32>\tsdiscon.exe
- <SYSTEM32>\bad12 with <SYSTEM32>\tscupgrd.exe
- <SYSTEM32>\bad55 with <SYSTEM32>\TsWpfWrp.exe
- <SYSTEM32>\tsshutdn.exe with <SYSTEM32>\tsshutdn.exe
- <SYSTEM32>\tskill.exe with <SYSTEM32>\tskill.exe
- <SYSTEM32>\tscon.exe with <SYSTEM32>\tscon.exe
- <SYSTEM32>\ddeshare.exe with <SYSTEM32>\ddeshare.exe.new
- <SYSTEM32>\tracert.exe with <SYSTEM32>\tracert.exe
- <SYSTEM32>\tracerpt.exe with <SYSTEM32>\tracerpt.exe
- <SYSTEM32>\bad157 with <SYSTEM32>\tscon.exe
- <SYSTEM32>\tracert6.exe with <SYSTEM32>\tracert6.exe
- <SYSTEM32>\bad74 with <SYSTEM32>\tracert6.exe
- <SYSTEM32>\bad146 with <SYSTEM32>\tcmsetup.exe
- <SYSTEM32>\subst.exe with <SYSTEM32>\subst.exe
- <SYSTEM32>\stimon.exe with <SYSTEM32>\stimon.exe
- <SYSTEM32>\spupdsvc.exe with <SYSTEM32>\spupdsvc.exe
- <SYSTEM32>\syncapp.exe with <SYSTEM32>\syncapp.exe
- <SYSTEM32>\bad36 with <SYSTEM32>\syncapp.exe
- <SYSTEM32>\compact.exe with <SYSTEM32>\compact.exe.new
- <SYSTEM32>\sprestrt.exe with <SYSTEM32>\sprestrt.exe
- <SYSTEM32>\spiisupd.exe with <SYSTEM32>\spiisupd.exe
- <SYSTEM32>\bad7 with <SYSTEM32>\spiisupd.exe
- <SYSTEM32>\cmstp.exe with <SYSTEM32>\cmstp.exe.new
- <SYSTEM32>\comp.exe with <SYSTEM32>\comp.exe.new
- <SYSTEM32>\spoolsv.exe with <SYSTEM32>\spoolsv.exe
- <SYSTEM32>\spnpinst.exe with <SYSTEM32>\spnpinst.exe
- <SYSTEM32>\bad29 with <SYSTEM32>\syskey.exe
- <SYSTEM32>\taskman.exe with <SYSTEM32>\taskman.exe
- <SYSTEM32>\tasklist.exe with <SYSTEM32>\tasklist.exe
- <SYSTEM32>\bad44 with <SYSTEM32>\tasklist.exe
- <SYSTEM32>\control.exe with <SYSTEM32>\control.exe.new
- <SYSTEM32>\taskmgr.exe with <SYSTEM32>\taskmgr.exe
- <SYSTEM32>\bad154 with <SYSTEM32>\taskmgr.exe
- <SYSTEM32>\taskkill.exe with <SYSTEM32>\taskkill.exe
- <SYSTEM32>\conime.exe with <SYSTEM32>\conime.exe.new
- <SYSTEM32>\systeminfo.exe with <SYSTEM32>\systeminfo.exe
- <SYSTEM32>\sysocmgr.exe with <SYSTEM32>\sysocmgr.exe
- <SYSTEM32>\bad196 with <SYSTEM32>\taskkill.exe
- <SYSTEM32>\systray.exe with <SYSTEM32>\systray.exe
- <SYSTEM32>\bad70 with <SYSTEM32>\systray.exe
- <SYSTEM32>\help.exe with <SYSTEM32>\help.exe.new
- <SYSTEM32>\dllcache\clipbrd.exe with <SYSTEM32>\dllcache\clipbrd.exe.new
- <SYSTEM32>\sethc.exe with <SYSTEM32>\sethc.exe.new
- <SYSTEM32>\sessmgr.exe with <SYSTEM32>\sessmgr.exe.new
- <SYSTEM32>\shadow.exe with <SYSTEM32>\shadow.exe.new
- <SYSTEM32>\sfc.exe with <SYSTEM32>\sfc.exe.new
- <SYSTEM32>\setup.exe with <SYSTEM32>\setup.exe.new
- <SYSTEM32>\services.exe with <SYSTEM32>\services.exe.new
- <SYSTEM32>\schtasks.exe with <SYSTEM32>\schtasks.exe.new
- <SYSTEM32>\scardsvr.exe with <SYSTEM32>\scardsvr.exe.new
- <SYSTEM32>\sc.exe with <SYSTEM32>\sc.exe.new
- <SYSTEM32>\secedit.exe with <SYSTEM32>\secedit.exe.new
- <SYSTEM32>\dllcache\cleanmgr.exe with <SYSTEM32>\dllcache\cleanmgr.exe.new
- <SYSTEM32>\sdbinst.exe with <SYSTEM32>\sdbinst.exe.new
- <SYSTEM32>\dllcache\clipsrv.exe with <SYSTEM32>\dllcache\clipsrv.exe.new
- <SYSTEM32>\sndrec32.exe with <SYSTEM32>\sndrec32.exe.new
- <SYSTEM32>\dllcache\cmdl32.exe with <SYSTEM32>\dllcache\cmdl32.exe.new
- <SYSTEM32>\smss.exe with <SYSTEM32>\smss.exe.new
- <SYSTEM32>\dllcache\cmmon32.exe with <SYSTEM32>\dllcache\cmmon32.exe.new
- <SYSTEM32>\sol.exe with <SYSTEM32>\sol.exe.new
- <SYSTEM32>\sndvol32.exe with <SYSTEM32>\sndvol32.exe.new
- <SYSTEM32>\smlogsvc.exe with <SYSTEM32>\smlogsvc.exe.new
- <SYSTEM32>\shutdown.exe with <SYSTEM32>\shutdown.exe.new
- <SYSTEM32>\shrpubw.exe with <SYSTEM32>\shrpubw.exe.new
- <SYSTEM32>\shmgrate.exe with <SYSTEM32>\shmgrate.exe.new
- <SYSTEM32>\skeys.exe with <SYSTEM32>\skeys.exe.new
- <SYSTEM32>\dllcache\cmd.exe with <SYSTEM32>\dllcache\cmd.exe.new
- <SYSTEM32>\sigverif.exe with <SYSTEM32>\sigverif.exe.new
- <SYSTEM32>\dllcache\ckcnv.exe with <SYSTEM32>\dllcache\ckcnv.exe.new
- <SYSTEM32>\dllcache\chkntfs.exe with <SYSTEM32>\dllcache\chkntfs.exe.new
- <SYSTEM32>\route.exe with <SYSTEM32>\route.exe.new
- <SYSTEM32>\rexec.exe with <SYSTEM32>\rexec.exe.new
- <SYSTEM32>\rsm.exe with <SYSTEM32>\rsm.exe.new
- <SYSTEM32>\rsh.exe with <SYSTEM32>\rsh.exe.new
- <SYSTEM32>\routemon.exe with <SYSTEM32>\routemon.exe.new
- <SYSTEM32>\reset.exe with <SYSTEM32>\reset.exe.new
- <SYSTEM32>\regwiz.exe with <SYSTEM32>\regwiz.exe.new
- <SYSTEM32>\regsvr32.exe with <SYSTEM32>\regsvr32.exe.new
- <SYSTEM32>\dllcache\charmap.exe with <SYSTEM32>\dllcache\charmap.exe.new
- <SYSTEM32>\replace.exe with <SYSTEM32>\replace.exe.new
- <SYSTEM32>\dllcache\chkdsk.exe with <SYSTEM32>\dllcache\chkdsk.exe.new
- <SYSTEM32>\relog.exe with <SYSTEM32>\relog.exe.new
- <SYSTEM32>\dllcache\cidaemon.exe with <SYSTEM32>\dllcache\cidaemon.exe.new
- <SYSTEM32>\rundll32.exe with <SYSTEM32>\rundll32.exe.new
- <SYSTEM32>\dllcache\cisvc.exe with <SYSTEM32>\dllcache\cisvc.exe.new
- <SYSTEM32>\runas.exe with <SYSTEM32>\runas.exe.new
- <SYSTEM32>\savedump.exe with <SYSTEM32>\savedump.exe.new
- <SYSTEM32>\rwinsta.exe with <SYSTEM32>\rwinsta.exe.new
- <SYSTEM32>\runonce.exe with <SYSTEM32>\runonce.exe.new
- <SYSTEM32>\rtcshare.exe with <SYSTEM32>\rtcshare.exe.new
- <SYSTEM32>\rsnotify.exe with <SYSTEM32>\rsnotify.exe.new
- <SYSTEM32>\rsmui.exe with <SYSTEM32>\rsmui.exe.new
- <SYSTEM32>\rsmsink.exe with <SYSTEM32>\rsmsink.exe.new
- <SYSTEM32>\rsvp.exe with <SYSTEM32>\rsvp.exe.new
- <SYSTEM32>\dllcache\cipher.exe with <SYSTEM32>\dllcache\cipher.exe.new
- <SYSTEM32>\rsopprov.exe with <SYSTEM32>\rsopprov.exe.new
- <SYSTEM32>\sort.exe with <SYSTEM32>\sort.exe.new
- <SYSTEM32>\typeperf.exe with <SYSTEM32>\typeperf.exe.new
- <SYSTEM32>\dllcache\defrag.exe with <SYSTEM32>\dllcache\defrag.exe.new
- <SYSTEM32>\tsshutdn.exe with <SYSTEM32>\tsshutdn.exe.new
- <SYSTEM32>\dllcache\dfrgfat.exe with <SYSTEM32>\dllcache\dfrgfat.exe.new
- <SYSTEM32>\upnpcont.exe with <SYSTEM32>\upnpcont.exe.new
- <SYSTEM32>\unlodctr.exe with <SYSTEM32>\unlodctr.exe.new
- <SYSTEM32>\tskill.exe with <SYSTEM32>\tskill.exe.new
- <SYSTEM32>\dllcache\ddeshare.exe with <SYSTEM32>\dllcache\ddeshare.exe.new
- <SYSTEM32>\tracert.exe with <SYSTEM32>\tracert.exe.new
- <SYSTEM32>\tracerpt.exe with <SYSTEM32>\tracerpt.exe.new
- <SYSTEM32>\tsdiscon.exe with <SYSTEM32>\tsdiscon.exe.new
- <SYSTEM32>\tscon.exe with <SYSTEM32>\tscon.exe.new
- <SYSTEM32>\tracert6.exe with <SYSTEM32>\tracert6.exe.new
- <SYSTEM32>\ups.exe with <SYSTEM32>\ups.exe.new
- <SYSTEM32>\dllcache\diskpart.exe with <SYSTEM32>\dllcache\diskpart.exe.new
- <SYSTEM32>\wiaacmgr.exe with <SYSTEM32>\wiaacmgr.exe.new
- <SYSTEM32>\wextract.exe with <SYSTEM32>\wextract.exe.new
- <SYSTEM32>\winlogon.exe with <SYSTEM32>\winlogon.exe.new
- <SYSTEM32>\winhlp32.exe with <SYSTEM32>\winhlp32.exe.new
- <SYSTEM32>\winchat.exe with <SYSTEM32>\winchat.exe.new
- <SYSTEM32>\w32tm.exe with <SYSTEM32>\w32tm.exe.new
- <SYSTEM32>\verifier.exe with <SYSTEM32>\verifier.exe.new
- <SYSTEM32>\dllcache\dfrgntfs.exe with <SYSTEM32>\dllcache\dfrgntfs.exe.new
- <SYSTEM32>\userinit.exe with <SYSTEM32>\userinit.exe.new
- <SYSTEM32>\vssvc.exe with <SYSTEM32>\vssvc.exe.new
- <SYSTEM32>\dllcache\diantz.exe with <SYSTEM32>\dllcache\diantz.exe.new
- <SYSTEM32>\vssadmin.exe with <SYSTEM32>\vssadmin.exe.new
- <SYSTEM32>\dllcache\dcomcnfg.exe with <SYSTEM32>\dllcache\dcomcnfg.exe.new
- <SYSTEM32>\dllcache\compact.exe with <SYSTEM32>\dllcache\compact.exe.new
- <SYSTEM32>\subst.exe with <SYSTEM32>\subst.exe.new
- <SYSTEM32>\stimon.exe with <SYSTEM32>\stimon.exe.new
- <SYSTEM32>\systeminfo.exe with <SYSTEM32>\systeminfo.exe.new
- <SYSTEM32>\sysocmgr.exe with <SYSTEM32>\sysocmgr.exe.new
- <SYSTEM32>\syncapp.exe with <SYSTEM32>\syncapp.exe.new
- <SYSTEM32>\dllcache\comp.exe with <SYSTEM32>\dllcache\comp.exe.new
- <SYSTEM32>\spiisupd.exe with <SYSTEM32>\spiisupd.exe.new
- <SYSTEM32>\dllcache\cmstp.exe with <SYSTEM32>\dllcache\cmstp.exe.new
- <SYSTEM32>\spider.exe with <SYSTEM32>\spider.exe.new
- <SYSTEM32>\sprestrt.exe with <SYSTEM32>\sprestrt.exe.new
- <SYSTEM32>\spoolsv.exe with <SYSTEM32>\spoolsv.exe.new
- <SYSTEM32>\spnpinst.exe with <SYSTEM32>\spnpinst.exe.new
- <SYSTEM32>\dllcache\conime.exe with <SYSTEM32>\dllcache\conime.exe.new
- <SYSTEM32>\tlntadmn.exe with <SYSTEM32>\tlntadmn.exe.new
- <SYSTEM32>\dllcache\convert.exe with <SYSTEM32>\dllcache\convert.exe.new
- <SYSTEM32>\tftp.exe with <SYSTEM32>\tftp.exe.new
- <SYSTEM32>\tourstart.exe with <SYSTEM32>\tourstart.exe.new
- <SYSTEM32>\tlntsvr.exe with <SYSTEM32>\tlntsvr.exe.new
- <SYSTEM32>\tlntsess.exe with <SYSTEM32>\tlntsess.exe.new
- <SYSTEM32>\telnet.exe with <SYSTEM32>\telnet.exe.new
- <SYSTEM32>\tasklist.exe with <SYSTEM32>\tasklist.exe.new
- <SYSTEM32>\taskkill.exe with <SYSTEM32>\taskkill.exe.new
- <SYSTEM32>\systray.exe with <SYSTEM32>\systray.exe.new
- <SYSTEM32>\tcpsvcs.exe with <SYSTEM32>\tcpsvcs.exe.new
- <SYSTEM32>\dllcache\control.exe with <SYSTEM32>\dllcache\control.exe.new
- <SYSTEM32>\taskmgr.exe with <SYSTEM32>\taskmgr.exe.new
- <SYSTEM32>\regini.exe with <SYSTEM32>\regini.exe.new
- <SYSTEM32>\mqtgsvc.exe with <SYSTEM32>\mqtgsvc.exe.new
- <SYSTEM32>\mqsvc.exe with <SYSTEM32>\mqsvc.exe.new
- <SYSTEM32>\mqbkup.exe with <SYSTEM32>\mqbkup.exe.new
- <SYSTEM32>\msdtc.exe with <SYSTEM32>\msdtc.exe.new
- <SYSTEM32>\dllcache\accwiz.exe with <SYSTEM32>\dllcache\accwiz.exe.new
- <SYSTEM32>\mrinfo.exe with <SYSTEM32>\mrinfo.exe.new
- <SYSTEM32>\mpnotify.exe with <SYSTEM32>\mpnotify.exe.new
- <SYSTEM32>\mobsync.exe with <SYSTEM32>\mobsync.exe.new
- <SYSTEM32>\mnmsrvc.exe with <SYSTEM32>\mnmsrvc.exe.new
- <SYSTEM32>\dllcache\notiflag.exe with <SYSTEM32>\dllcache\notiflag.exe.new
- <SYSTEM32>\mplay32.exe with <SYSTEM32>\mplay32.exe.new
- <SYSTEM32>\dllcache\uploadm.exe with <SYSTEM32>\dllcache\uploadm.exe.new
- <SYSTEM32>\mountvol.exe with <SYSTEM32>\mountvol.exe.new
- <SYSTEM32>\msg.exe with <SYSTEM32>\msg.exe.new
- <SYSTEM32>\narrator.exe with <SYSTEM32>\narrator.exe.new
- <SYSTEM32>\mstsc.exe with <SYSTEM32>\mstsc.exe.new
- <SYSTEM32>\dllcache\ahui.exe with <SYSTEM32>\dllcache\ahui.exe.new
- <SYSTEM32>\net.exe with <SYSTEM32>\net.exe.new
- <SYSTEM32>\nddeapir.exe with <SYSTEM32>\nddeapir.exe.new
- <SYSTEM32>\nbtstat.exe with <SYSTEM32>\nbtstat.exe.new
- <SYSTEM32>\mstinit.exe with <SYSTEM32>\mstinit.exe.new
- <SYSTEM32>\msiexec.exe with <SYSTEM32>\msiexec.exe.new
- <SYSTEM32>\mshta.exe with <SYSTEM32>\mshta.exe.new
- <SYSTEM32>\mshearts.exe with <SYSTEM32>\mshearts.exe.new
- <SYSTEM32>\msswchx.exe with <SYSTEM32>\msswchx.exe.new
- <SYSTEM32>\mspaint.exe with <SYSTEM32>\mspaint.exe.new
- <SYSTEM32>\dllcache\actmovie.exe with <SYSTEM32>\dllcache\actmovie.exe.new
- <SYSTEM32>\mmc.exe with <SYSTEM32>\mmc.exe.new
- <SYSTEM32>\dllcache\helphost.exe with <SYSTEM32>\dllcache\helphost.exe.new
- <SYSTEM32>\ipv6.exe with <SYSTEM32>\ipv6.exe.new
- <SYSTEM32>\ipsec6.exe with <SYSTEM32>\ipsec6.exe.new
- <SYSTEM32>\lights.exe with <SYSTEM32>\lights.exe.new
- <SYSTEM32>\label.exe with <SYSTEM32>\label.exe.new
- <SYSTEM32>\ipxroute.exe with <SYSTEM32>\ipxroute.exe.new
- <SYSTEM32>\ipconfig.exe with <SYSTEM32>\ipconfig.exe.new
- <SYSTEM32>\ie4uinit.exe with <SYSTEM32>\ie4uinit.exe.new
- <SYSTEM32>\hostname.exe with <SYSTEM32>\hostname.exe.new
- <SYSTEM32>\dllcache\muisetup.exe with <SYSTEM32>\dllcache\muisetup.exe.new
- <SYSTEM32>\imapi.exe with <SYSTEM32>\imapi.exe.new
- <SYSTEM32>\iexpress.exe with <SYSTEM32>\iexpress.exe.new
- <SYSTEM32>\dllcache\helpctr.exe with <SYSTEM32>\dllcache\helpctr.exe.new
- <SYSTEM32>\lnkstub.exe with <SYSTEM32>\lnkstub.exe.new
- <SYSTEM32>\lpr.exe with <SYSTEM32>\lpr.exe.new
- <SYSTEM32>\dllcache\hscupd.exe with <SYSTEM32>\dllcache\hscupd.exe.new
- <SYSTEM32>\lpq.exe with <SYSTEM32>\lpq.exe.new
- <SYSTEM32>\dllcache\msconfig.exe with <SYSTEM32>\dllcache\msconfig.exe.new
- <SYSTEM32>\makecab.exe with <SYSTEM32>\makecab.exe.new
- <SYSTEM32>\magnify.exe with <SYSTEM32>\magnify.exe.new
- <SYSTEM32>\logonui.exe with <SYSTEM32>\logonui.exe.new
- <SYSTEM32>\logagent.exe with <SYSTEM32>\logagent.exe.new
- <SYSTEM32>\lodctr.exe with <SYSTEM32>\lodctr.exe.new
- <SYSTEM32>\locator.exe with <SYSTEM32>\locator.exe.new
- <SYSTEM32>\logoff.exe with <SYSTEM32>\logoff.exe.new
- <SYSTEM32>\dllcache\helpsvc.exe with <SYSTEM32>\dllcache\helpsvc.exe.new
- <SYSTEM32>\logman.exe with <SYSTEM32>\logman.exe.new
- <SYSTEM32>\net1.exe with <SYSTEM32>\net1.exe.new
- <SYSTEM32>\qappsrv.exe with <SYSTEM32>\qappsrv.exe.new
- <SYSTEM32>\proxycfg.exe with <SYSTEM32>\proxycfg.exe.new
- <SYSTEM32>\proquota.exe with <SYSTEM32>\proquota.exe.new
- <SYSTEM32>\qwinsta.exe with <SYSTEM32>\qwinsta.exe.new
- <SYSTEM32>\dllcache\autolfn.exe with <SYSTEM32>\dllcache\autolfn.exe.new
- <SYSTEM32>\qprocess.exe with <SYSTEM32>\qprocess.exe.new
- <SYSTEM32>\dllcache\autofmt.exe with <SYSTEM32>\dllcache\autofmt.exe.new
- <SYSTEM32>\dllcache\autoconv.exe with <SYSTEM32>\dllcache\autoconv.exe.new
- <SYSTEM32>\ping6.exe with <SYSTEM32>\ping6.exe.new
- <SYSTEM32>\ping.exe with <SYSTEM32>\ping.exe.new
- <SYSTEM32>\progman.exe with <SYSTEM32>\progman.exe.new
- <SYSTEM32>\print.exe with <SYSTEM32>\print.exe.new
- <SYSTEM32>\powercfg.exe with <SYSTEM32>\powercfg.exe.new
- <SYSTEM32>\rasautou.exe with <SYSTEM32>\rasautou.exe.new
- <SYSTEM32>\recover.exe with <SYSTEM32>\recover.exe.new
- <SYSTEM32>\rdshost.exe with <SYSTEM32>\rdshost.exe.new
- <SYSTEM32>\rdsaddin.exe with <SYSTEM32>\rdsaddin.exe.new
- <SYSTEM32>\regedt32.exe with <SYSTEM32>\regedt32.exe.new
- <SYSTEM32>\reg.exe with <SYSTEM32>\reg.exe.new
- <SYSTEM32>\dllcache\calc.exe with <SYSTEM32>\dllcache\calc.exe.new
- <SYSTEM32>\dllcache\cacls.exe with <SYSTEM32>\dllcache\cacls.exe.new
- <SYSTEM32>\rasphone.exe with <SYSTEM32>\rasphone.exe.new
- <SYSTEM32>\dllcache\blastcln.exe with <SYSTEM32>\dllcache\blastcln.exe.new
- <SYSTEM32>\rasdial.exe with <SYSTEM32>\rasdial.exe.new
- <SYSTEM32>\rdpclip.exe with <SYSTEM32>\rdpclip.exe.new
- <SYSTEM32>\rcp.exe with <SYSTEM32>\rcp.exe.new
- <SYSTEM32>\rcimlby.exe with <SYSTEM32>\rcimlby.exe.new
- <SYSTEM32>\perfmon.exe with <SYSTEM32>\perfmon.exe.new
- <SYSTEM32>\dllcache\asr_ldm.exe with <SYSTEM32>\dllcache\asr_ldm.exe.new
- <SYSTEM32>\ntbackup.exe with <SYSTEM32>\ntbackup.exe.new
- <SYSTEM32>\nslookup.exe with <SYSTEM32>\nslookup.exe.new
- <SYSTEM32>\ntsd.exe with <SYSTEM32>\ntsd.exe.new
- <SYSTEM32>\dllcache\at.exe with <SYSTEM32>\dllcache\at.exe.new
- <SYSTEM32>\dllcache\asr_pfu.exe with <SYSTEM32>\dllcache\asr_pfu.exe.new
- <SYSTEM32>\notepad.exe with <SYSTEM32>\notepad.exe.new
- <SYSTEM32>\netsetup.exe with <SYSTEM32>\netsetup.exe.new
- <SYSTEM32>\netdde.exe with <SYSTEM32>\netdde.exe.new
- <SYSTEM32>\dllcache\arp.exe with <SYSTEM32>\dllcache\arp.exe.new
- <SYSTEM32>\dllcache\asr_fmt.exe with <SYSTEM32>\dllcache\asr_fmt.exe.new
- <SYSTEM32>\netstat.exe with <SYSTEM32>\netstat.exe.new
- <SYSTEM32>\netsh.exe with <SYSTEM32>\netsh.exe.new
- <SYSTEM32>\dllcache\atmadm.exe with <SYSTEM32>\dllcache\atmadm.exe.new
- <SYSTEM32>\packager.exe with <SYSTEM32>\packager.exe.new
- <SYSTEM32>\osuninst.exe with <SYSTEM32>\osuninst.exe.new
- <SYSTEM32>\osk.exe with <SYSTEM32>\osk.exe.new
- <SYSTEM32>\pentnt.exe with <SYSTEM32>\pentnt.exe.new
- <SYSTEM32>\dllcache\autochk.exe with <SYSTEM32>\dllcache\autochk.exe.new
- <SYSTEM32>\pathping.exe with <SYSTEM32>\pathping.exe.new
- <SYSTEM32>\dllcache\auditusr.exe with <SYSTEM32>\dllcache\auditusr.exe.new
- <SYSTEM32>\dllcache\attrib.exe with <SYSTEM32>\dllcache\attrib.exe.new
- <SYSTEM32>\nwscript.exe with <SYSTEM32>\nwscript.exe.new
- <SYSTEM32>\ntvdm.exe with <SYSTEM32>\ntvdm.exe.new
- <SYSTEM32>\openfiles.exe with <SYSTEM32>\openfiles.exe.new
- <SYSTEM32>\odbcconf.exe with <SYSTEM32>\odbcconf.exe.new
- <SYSTEM32>\odbcad32.exe with <SYSTEM32>\odbcad32.exe.new
- %WINDIR%\pchealth\helpctr\binaries\HelpSvc.exe with %WINDIR%\pchealth\helpctr\binaries\HelpSvc.exe
- <SYSTEM32>\dllcache\setup50.exe with <SYSTEM32>\dllcache\setup50.exe.new
- %WINDIR%\pchealth\helpctr\binaries\HelpHost.exe with %WINDIR%\pchealth\helpctr\binaries\HelpHost.exe
- %WINDIR%\pchealth\helpctr\binaries\HscUpd.exe with %WINDIR%\pchealth\helpctr\binaries\HscUpd.exe
- <SYSTEM32>\dllcache\wabmig.exe with <SYSTEM32>\dllcache\wabmig.exe.new
- <SYSTEM32>\dllcache\wab.exe with <SYSTEM32>\dllcache\wab.exe.new
- %WINDIR%\pchealth\helpctr\binaries\HelpCtr.exe with %WINDIR%\pchealth\helpctr\binaries\HelpCtr.exe
- %WINDIR%\msagent\agentsvr.exe with %WINDIR%\msagent\agentsvr.exe
- <SYSTEM32>\dllcache\wb32.exe with <SYSTEM32>\dllcache\wb32.exe.new
- <SYSTEM32>\dllcache\conf.exe with <SYSTEM32>\dllcache\conf.exe.new
- <SYSTEM32>\dllcache\oemig50.exe with <SYSTEM32>\dllcache\oemig50.exe.new
- <SYSTEM32>\dllcache\msimn.exe with <SYSTEM32>\dllcache\msimn.exe.new
- %WINDIR%\mui\muisetup.exe with %WINDIR%\mui\muisetup.exe
- %WINDIR%\pchealth\helpctr\binaries\msconfig.exe with %WINDIR%\pchealth\helpctr\binaries\msconfig.exe
- <SYSTEM32>\alg.exe with <SYSTEM32>\alg.exe
- <SYSTEM32>\ahui.exe with <SYSTEM32>\ahui.exe
- <SYSTEM32>\actmovie.exe with <SYSTEM32>\actmovie.exe
- <SYSTEM32>\dllcache\dialer.exe with <SYSTEM32>\dllcache\dialer.exe.new
- <SYSTEM32>\asr_fmt.exe with <SYSTEM32>\asr_fmt.exe
- <SYSTEM32>\arp.exe with <SYSTEM32>\arp.exe
- <SYSTEM32>\accwiz.exe with <SYSTEM32>\accwiz.exe
- <SYSTEM32>\dllcache\mplayer2.exe with <SYSTEM32>\dllcache\mplayer2.exe.new
- <SYSTEM32>\dllcache\migrate.exe with <SYSTEM32>\dllcache\migrate.exe.new
- %WINDIR%\pchealth\helpctr\binaries\notiflag.exe with %WINDIR%\pchealth\helpctr\binaries\notiflag.exe
- <SYSTEM32>\dllcache\wmplayer.exe with <SYSTEM32>\dllcache\wmplayer.exe.new
- <SYSTEM32>\dllcache\setup_wm.exe with <SYSTEM32>\dllcache\setup_wm.exe.new
- %WINDIR%\pchealth\UploadLB\Binaries\UploadM.exe with %WINDIR%\pchealth\UploadLB\Binaries\UploadM.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ngen.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ngen.exe
- <SYSTEM32>\dllcache\chkrzm.exe with <SYSTEM32>\dllcache\chkrzm.exe.new
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\regtlibv12.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\regtlibv12.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad171 with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\jsc.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\jsc.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ilasm.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ilasm.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\Microsoft.Workflow.Compiler.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\Microsoft.Workflow.Compiler.exe
- %WINDIR%\Help\Tours\mmTour\tour.exe with %WINDIR%\Help\Tours\mmTour\tour.exe.new
- <SYSTEM32>\dllcache\hrtzzm.exe with <SYSTEM32>\dllcache\hrtzzm.exe.new
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe
- <SYSTEM32>\dllcache\cb32.exe with <SYSTEM32>\dllcache\cb32.exe.new
- <SYSTEM32>\dllcache\zclientm.exe with <SYSTEM32>\dllcache\zclientm.exe.new
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\SetupUtility.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\SetupUtility.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\Setup.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\Setup.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\SetupUtility.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\SetupUtility.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\WsatConfig.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\WsatConfig.exe
- <SYSTEM32>\dllcache\rvsezm.exe with <SYSTEM32>\dllcache\rvsezm.exe.new
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ServiceModelReg.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ServiceModelReg.exe
- <SYSTEM32>\dllcache\shvlzm.exe with <SYSTEM32>\dllcache\shvlzm.exe.new
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\vbc.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\vbc.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad122 with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\vbc.exe
- <SYSTEM32>\asr_ldm.exe with <SYSTEM32>\asr_ldm.exe
- <SYSTEM32>\compact.exe with <SYSTEM32>\compact.exe
- <SYSTEM32>\comp.exe with <SYSTEM32>\comp.exe
- <SYSTEM32>\bad53 with <SYSTEM32>\comp.exe
- <SYSTEM32>\convert.exe with <SYSTEM32>\convert.exe
- <SYSTEM32>\control.exe with <SYSTEM32>\control.exe
- <SYSTEM32>\conime.exe with <SYSTEM32>\conime.exe
- <SYSTEM32>\cmstp.exe with <SYSTEM32>\cmstp.exe
- <SYSTEM32>\bad69 with <SYSTEM32>\cmdl32.exe
- <SYSTEM32>\cmd.exe with <SYSTEM32>\cmd.exe
- <SYSTEM32>\dllcache\regedit.exe with <SYSTEM32>\dllcache\regedit.exe.new
- <SYSTEM32>\cmmon32.exe with <SYSTEM32>\cmmon32.exe
- <SYSTEM32>\dllcache\taskman.exe with <SYSTEM32>\dllcache\taskman.exe.new
- <SYSTEM32>\cmdl32.exe with <SYSTEM32>\cmdl32.exe
- <SYSTEM32>\csrss.exe with <SYSTEM32>\csrss.exe
- <SYSTEM32>\dfrgntfs.exe with <SYSTEM32>\dfrgntfs.exe
- <SYSTEM32>\dfrgfat.exe with <SYSTEM32>\dfrgfat.exe
- <SYSTEM32>\defrag.exe with <SYSTEM32>\defrag.exe
- <SYSTEM32>\diskperf.exe with <SYSTEM32>\diskperf.exe
- <SYSTEM32>\diskpart.exe with <SYSTEM32>\diskpart.exe
- <SYSTEM32>\diantz.exe with <SYSTEM32>\diantz.exe
- <SYSTEM32>\dllcache\twunk_32.exe with <SYSTEM32>\dllcache\twunk_32.exe.new
- <SYSTEM32>\dcomcnfg.exe with <SYSTEM32>\dcomcnfg.exe
- <SYSTEM32>\ctfmon.exe with <SYSTEM32>\ctfmon.exe
- <SYSTEM32>\bad97 with <SYSTEM32>\ctfmon.exe
- <SYSTEM32>\bad20 with <SYSTEM32>\debug.exe
- <SYSTEM32>\ddeshare.exe with <SYSTEM32>\ddeshare.exe
- <SYSTEM32>\bad138 with <SYSTEM32>\ddeshare.exe
- <SYSTEM32>\clipsrv.exe with <SYSTEM32>\clipsrv.exe
- <SYSTEM32>\dllcache\pinball.exe with <SYSTEM32>\dllcache\pinball.exe.new
- <SYSTEM32>\autofmt.exe with <SYSTEM32>\autofmt.exe
- <SYSTEM32>\autoconv.exe with <SYSTEM32>\autoconv.exe
- <SYSTEM32>\cacls.exe with <SYSTEM32>\cacls.exe
- <SYSTEM32>\blastcln.exe with <SYSTEM32>\blastcln.exe
- <SYSTEM32>\autolfn.exe with <SYSTEM32>\autolfn.exe
- <SYSTEM32>\autochk.exe with <SYSTEM32>\autochk.exe
- <SYSTEM32>\atmadm.exe with <SYSTEM32>\atmadm.exe
- <SYSTEM32>\at.exe with <SYSTEM32>\at.exe
- <SYSTEM32>\asr_pfu.exe with <SYSTEM32>\asr_pfu.exe
- <SYSTEM32>\dllcache\wordpad.exe with <SYSTEM32>\dllcache\wordpad.exe.new
- <SYSTEM32>\auditusr.exe with <SYSTEM32>\auditusr.exe
- <SYSTEM32>\attrib.exe with <SYSTEM32>\attrib.exe
- <SYSTEM32>\dllcache\hh.exe with <SYSTEM32>\dllcache\hh.exe.new
- <SYSTEM32>\cleanmgr.exe with <SYSTEM32>\cleanmgr.exe
- <SYSTEM32>\ckcnv.exe with <SYSTEM32>\ckcnv.exe
- <SYSTEM32>\cisvc.exe with <SYSTEM32>\cisvc.exe
- <SYSTEM32>\bad140 with <SYSTEM32>\clipsrv.exe
- <SYSTEM32>\clipbrd.exe with <SYSTEM32>\clipbrd.exe
- <SYSTEM32>\cliconfg.exe with <SYSTEM32>\cliconfg.exe
- <SYSTEM32>\cipher.exe with <SYSTEM32>\cipher.exe
- <SYSTEM32>\chkdsk.exe with <SYSTEM32>\chkdsk.exe
- <SYSTEM32>\charmap.exe with <SYSTEM32>\charmap.exe
- <SYSTEM32>\calc.exe with <SYSTEM32>\calc.exe
- <SYSTEM32>\cidaemon.exe with <SYSTEM32>\cidaemon.exe
- <SYSTEM32>\dllcache\notepad.exe with <SYSTEM32>\dllcache\notepad.exe.new
- <SYSTEM32>\chkntfs.exe with <SYSTEM32>\chkntfs.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\EdmGen.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\EdmGen.exe
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\vbc.exe with %WINDIR%\Microsoft.NET\Framework\v1.1.4322\vbc.exe
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\RegSvcs.exe with %WINDIR%\Microsoft.NET\Framework\v1.1.4322\RegSvcs.exe
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\RegAsm.exe with %WINDIR%\Microsoft.NET\Framework\v1.1.4322\RegAsm.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\ngen.exe with %WINDIR%\Microsoft.NET\Framework\v1.1.4322\ngen.exe
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\jsc.exe with %WINDIR%\Microsoft.NET\Framework\v1.1.4322\jsc.exe
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\InstallUtil.exe with %WINDIR%\Microsoft.NET\Framework\v1.1.4322\InstallUtil.exe
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\ilasm.exe with %WINDIR%\Microsoft.NET\Framework\v1.1.4322\ilasm.exe
- <SYSTEM32>\dllcache\inetwiz.exe with <SYSTEM32>\dllcache\inetwiz.exe.new
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\MigPolWin.exe with %WINDIR%\Microsoft.NET\Framework\v1.1.4322\MigPolWin.exe
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\MigPol.exe with %WINDIR%\Microsoft.NET\Framework\v1.1.4322\MigPol.exe
- <SYSTEM32>\dllcache\isignup.exe with <SYSTEM32>\dllcache\isignup.exe.new
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\cvtres.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\cvtres.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\csc.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\csc.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ilasm.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ilasm.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\IEExec.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad173 with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\csc.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\CasPol.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad149 with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\IEExec.exe with %WINDIR%\Microsoft.NET\Framework\v1.1.4322\IEExec.exe
- %WINDIR%\winhlp32.exe with %WINDIR%\winhlp32.exe
- <SYSTEM32>\dllcache\sapisvr.exe with <SYSTEM32>\dllcache\sapisvr.exe.new
- %WINDIR%\twunk_32.exe with %WINDIR%\twunk_32.exe
- %WINDIR%\Help\Tours\mmTour\tour.exe with %WINDIR%\Help\Tours\mmTour\tour.exe
- <SYSTEM32>\dllcache\iexplore.exe with <SYSTEM32>\dllcache\iexplore.exe.new
- <SYSTEM32>\dllcache\iedw.exe with <SYSTEM32>\dllcache\iedw.exe.new
- %WINDIR%\TASKMAN.EXE with %WINDIR%\TASKMAN.EXE
- %WINDIR%\regedit.exe with %WINDIR%\regedit.exe
- %WINDIR%\NOTEPAD.EXE with %WINDIR%\NOTEPAD.EXE
- %WINDIR%\hh.exe with %WINDIR%\hh.exe
- %WINDIR%\sleep.exe with %WINDIR%\sleep.exe
- <SYSTEM32>\dllcache\msinfo32.exe with <SYSTEM32>\dllcache\msinfo32.exe.new
- %WINDIR%\sfk.exe with %WINDIR%\sfk.exe
- %WINDIR%\Microsoft.NET\NETFXRepair.exe with %WINDIR%\Microsoft.NET\NETFXRepair.exe
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\CasPol.exe with %WINDIR%\Microsoft.NET\Framework\v1.1.4322\CasPol.exe
- <SYSTEM32>\dllcache\icwtutor.exe with <SYSTEM32>\dllcache\icwtutor.exe.new
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe with %WINDIR%\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\cvtres.exe with %WINDIR%\Microsoft.NET\Framework\v1.1.4322\cvtres.exe
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\csc.exe with %WINDIR%\Microsoft.NET\Framework\v1.1.4322\csc.exe
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe with %WINDIR%\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe with %WINDIR%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
- <SYSTEM32>\dllcache\icwconn2.exe with <SYSTEM32>\dllcache\icwconn2.exe.new
- <SYSTEM32>\dllcache\icwconn1.exe with <SYSTEM32>\dllcache\icwconn1.exe.new
- %WINDIR%\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5\Microsoft.Workflow.Compiler.exe with %WINDIR%\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5\Microsoft.Workflow.Compiler.exe
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\aspnet_regiis.exe with %WINDIR%\Microsoft.NET\Framework\v1.1.4322\aspnet_regiis.exe
- %WINDIR%\Microsoft.NET\Framework\NETFXSBS10.exe with %WINDIR%\Microsoft.NET\Framework\NETFXSBS10.exe
- <SYSTEM32>\dllcache\icwrmind.exe with <SYSTEM32>\dllcache\icwrmind.exe.new
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad102 with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\jsc.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_regbrowsers.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_regbrowsers.exe
- %WINDIR%\NOTEPAD.EXE with %WINDIR%\notepad.exe.new
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
- %WINDIR%\regedit.exe with %WINDIR%\regedit.exe.new
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad91 with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_regiis.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\AddInProcess.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\AddInProcess.exe
- %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe with %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
- %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\DeleteTemp.exe with %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\DeleteTemp.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\AddInUtil.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\AddInUtil.exe
- %WINDIR%\hh.exe with %WINDIR%\hh.exe.new
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_regsql.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_regsql.exe
- <SYSTEM32>\dllcache\bckgzm.exe with <SYSTEM32>\dllcache\bckgzm.exe.new
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\cvtres.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\cvtres.exe
- %WINDIR%\winhlp32.exe with %WINDIR%\winhlp32.exe.new
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad76 with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\DataSvcUtil.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\DataSvcUtil.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\csc.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\csc.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe
- %WINDIR%\TASKMAN.EXE with %WINDIR%\taskman.exe.new
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
- %WINDIR%\twunk_32.exe with %WINDIR%\twunk_32.exe.new
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ComSvcConfig.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ComSvcConfig.exe
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\CasPol.exe with %WINDIR%\Microsoft.NET\Framework\v4.0.30319\CasPol.exe
- %WINDIR%\Microsoft.NET\Framework\v3.5\WFServicesReg.exe with %WINDIR%\Microsoft.NET\Framework\v3.5\WFServicesReg.exe
- %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ComSvcConfig.exe with %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ComSvcConfig.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad59 with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe
- %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe with %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
- %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelReg.exe with %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelReg.exe
- %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe with %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\jsc.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\jsc.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ngen.exe with %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ngen.exe
- %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\WsatConfig.exe with %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\WsatConfig.exe
- %WINDIR%\Microsoft.NET\Framework\v3.5\EdmGen.exe with %WINDIR%\Microsoft.NET\Framework\v3.5\EdmGen.exe
- %WINDIR%\Microsoft.NET\Framework\v3.5\DataSvcUtil.exe with %WINDIR%\Microsoft.NET\Framework\v3.5\DataSvcUtil.exe
- %WINDIR%\Microsoft.NET\Framework\v3.5\csc.exe with %WINDIR%\Microsoft.NET\Framework\v3.5\csc.exe
- %WINDIR%\Microsoft.NET\Framework\v3.5\vbc.exe with %WINDIR%\Microsoft.NET\Framework\v3.5\vbc.exe
- %WINDIR%\Microsoft.NET\Framework\v3.5\MSBuild.exe with %WINDIR%\Microsoft.NET\Framework\v3.5\MSBuild.exe
- %WINDIR%\Microsoft.NET\Framework\v3.5\bad2 with %WINDIR%\Microsoft.NET\Framework\v3.5\MSBuild.exe
- %WINDIR%\Microsoft.NET\Framework\v3.5\AddInUtil.exe with %WINDIR%\Microsoft.NET\Framework\v3.5\AddInUtil.exe
- %WINDIR%\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe with %WINDIR%\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
- <SYSTEM32>\dllcache\moviemk.exe with <SYSTEM32>\dllcache\moviemk.exe.new
- %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\PerformanceCounterInstaller.exe with %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\PerformanceCounterInstaller.exe
- %WINDIR%\Microsoft.NET\Framework\v3.5\AddInProcess32.exe with %WINDIR%\Microsoft.NET\Framework\v3.5\AddInProcess32.exe
- %WINDIR%\Microsoft.NET\Framework\v3.5\AddInProcess.exe with %WINDIR%\Microsoft.NET\Framework\v3.5\AddInProcess.exe
- %WINDIR%\Microsoft.NET\Framework\v3.0\WPF\XamlViewer\XamlViewer_v0300.exe with %WINDIR%\Microsoft.NET\Framework\v3.0\WPF\XamlViewer\XamlViewer_v0300.exe
- <SYSTEM32>\bad132 with <SYSTEM32>\dllhost.exe
- <SYSTEM32>\attrib.exe with <SYSTEM32>\attrib.exe.new
- <SYSTEM32>\bad29 with <SYSTEM32>\nwscript.exe
- <SYSTEM32>\bad68 with <SYSTEM32>\nw16.exe
- <SYSTEM32>\odbcad32.exe with <SYSTEM32>\odbcad32.exe
- <SYSTEM32>\bad101 with <SYSTEM32>\odbcad32.exe
- <SYSTEM32>\nwscript.exe with <SYSTEM32>\nwscript.exe
- <SYSTEM32>\ntvdm.exe with <SYSTEM32>\ntvdm.exe
- <SYSTEM32>\ntoskrnl.exe with <SYSTEM32>\ntoskrnl.exe
- <SYSTEM32>\asr_pfu.exe with <SYSTEM32>\asr_pfu.exe.new
- <SYSTEM32>\ntkrnlpa.exe with <SYSTEM32>\ntkrnlpa.exe
- <SYSTEM32>\atmadm.exe with <SYSTEM32>\atmadm.exe.new
- <SYSTEM32>\ntsd.exe with <SYSTEM32>\ntsd.exe
- <SYSTEM32>\at.exe with <SYSTEM32>\at.exe.new
- <SYSTEM32>\odbcconf.exe with <SYSTEM32>\odbcconf.exe
- <SYSTEM32>\bad126 with <SYSTEM32>\pentnt.exe
- <SYSTEM32>\autochk.exe with <SYSTEM32>\autochk.exe.new
- <SYSTEM32>\pathping.exe with <SYSTEM32>\pathping.exe
- <SYSTEM32>\perfmon.exe with <SYSTEM32>\perfmon.exe
- <SYSTEM32>\bad92 with <SYSTEM32>\perfmon.exe
- <SYSTEM32>\pentnt.exe with <SYSTEM32>\pentnt.exe
- <SYSTEM32>\bad111 with <SYSTEM32>\pathping.exe
- <SYSTEM32>\auditusr.exe with <SYSTEM32>\auditusr.exe.new
- <SYSTEM32>\openfiles.exe with <SYSTEM32>\openfiles.exe
- <SYSTEM32>\bad156 with <SYSTEM32>\openfiles.exe
- <SYSTEM32>\packager.exe with <SYSTEM32>\packager.exe
- <SYSTEM32>\osuninst.exe with <SYSTEM32>\osuninst.exe
- <SYSTEM32>\osk.exe with <SYSTEM32>\osk.exe
- <SYSTEM32>\bad63 with <SYSTEM32>\ntkrnlpa.exe
- <SYSTEM32>\bad17 with <SYSTEM32>\nbtstat.exe
- <SYSTEM32>\narrator.exe with <SYSTEM32>\narrator.exe
- <SYSTEM32>\bad119 with <SYSTEM32>\narrator.exe
- <SYSTEM32>\net.exe with <SYSTEM32>\net.exe
- <SYSTEM32>\nddeapir.exe with <SYSTEM32>\nddeapir.exe
- <SYSTEM32>\nbtstat.exe with <SYSTEM32>\nbtstat.exe
- <SYSTEM32>\mstsc.exe with <SYSTEM32>\mstsc.exe
- <SYSTEM32>\mspaint.exe with <SYSTEM32>\mspaint.exe
- <SYSTEM32>\bad171 with <SYSTEM32>\mspaint.exe
- <SYSTEM32>\msiexec.exe with <SYSTEM32>\msiexec.exe
- <SYSTEM32>\ahui.exe with <SYSTEM32>\ahui.exe.new
- <SYSTEM32>\mstinit.exe with <SYSTEM32>\mstinit.exe
- <SYSTEM32>\msswchx.exe with <SYSTEM32>\msswchx.exe
- <SYSTEM32>\bad129 with <SYSTEM32>\net1.exe
- <SYSTEM32>\bad191 with <SYSTEM32>\nslookup.exe
- <SYSTEM32>\notepad.exe with <SYSTEM32>\notepad.exe
- <SYSTEM32>\asr_fmt.exe with <SYSTEM32>\asr_fmt.exe.new
- <SYSTEM32>\asr_ldm.exe with <SYSTEM32>\asr_ldm.exe.new
- <SYSTEM32>\ntbackup.exe with <SYSTEM32>\ntbackup.exe
- <SYSTEM32>\nslookup.exe with <SYSTEM32>\nslookup.exe
- <SYSTEM32>\bad62 with <SYSTEM32>\nlsfunc.exe
- <SYSTEM32>\netdde.exe with <SYSTEM32>\netdde.exe
- <SYSTEM32>\arp.exe with <SYSTEM32>\arp.exe.new
- <SYSTEM32>\net1.exe with <SYSTEM32>\net1.exe
- <SYSTEM32>\netstat.exe with <SYSTEM32>\netstat.exe
- <SYSTEM32>\netsh.exe with <SYSTEM32>\netsh.exe
- <SYSTEM32>\netsetup.exe with <SYSTEM32>\netsetup.exe
- <SYSTEM32>\ping.exe with <SYSTEM32>\ping.exe
- <SYSTEM32>\regsvr32.exe with <SYSTEM32>\regsvr32.exe
- <SYSTEM32>\charmap.exe with <SYSTEM32>\charmap.exe.new
- <SYSTEM32>\regini.exe with <SYSTEM32>\regini.exe
- <SYSTEM32>\relog.exe with <SYSTEM32>\relog.exe
- <SYSTEM32>\regwiz.exe with <SYSTEM32>\regwiz.exe
- <SYSTEM32>\bad194 with <SYSTEM32>\regwiz.exe
- <SYSTEM32>\regedt32.exe with <SYSTEM32>\regedt32.exe
- <SYSTEM32>\recover.exe with <SYSTEM32>\recover.exe
- <SYSTEM32>\rdshost.exe with <SYSTEM32>\rdshost.exe
- <SYSTEM32>\bad77 with <SYSTEM32>\rdshost.exe
- <SYSTEM32>\reg.exe with <SYSTEM32>\reg.exe
- <SYSTEM32>\bad141 with <SYSTEM32>\redir.exe
- <SYSTEM32>\calc.exe with <SYSTEM32>\calc.exe.new
- <SYSTEM32>\chkdsk.exe with <SYSTEM32>\chkdsk.exe.new
- <SYSTEM32>\bad172 with <SYSTEM32>\rsm.exe
- <SYSTEM32>\rsh.exe with <SYSTEM32>\rsh.exe
- <SYSTEM32>\routemon.exe with <SYSTEM32>\routemon.exe
- <SYSTEM32>\rsmsink.exe with <SYSTEM32>\rsmsink.exe
- <SYSTEM32>\cidaemon.exe with <SYSTEM32>\cidaemon.exe.new
- <SYSTEM32>\rsm.exe with <SYSTEM32>\rsm.exe
- <SYSTEM32>\chkntfs.exe with <SYSTEM32>\chkntfs.exe.new
- <SYSTEM32>\reset.exe with <SYSTEM32>\reset.exe
- <SYSTEM32>\bad124 with <SYSTEM32>\reset.exe
- <SYSTEM32>\replace.exe with <SYSTEM32>\replace.exe
- <SYSTEM32>\route.exe with <SYSTEM32>\route.exe
- <SYSTEM32>\bad2 with <SYSTEM32>\route.exe
- <SYSTEM32>\rexec.exe with <SYSTEM32>\rexec.exe
- <SYSTEM32>\rdsaddin.exe with <SYSTEM32>\rdsaddin.exe
- <SYSTEM32>\autofmt.exe with <SYSTEM32>\autofmt.exe.new
- <SYSTEM32>\progman.exe with <SYSTEM32>\progman.exe
- <SYSTEM32>\bad115 with <SYSTEM32>\progman.exe
- <SYSTEM32>\qappsrv.exe with <SYSTEM32>\qappsrv.exe
- <SYSTEM32>\proxycfg.exe with <SYSTEM32>\proxycfg.exe
- <SYSTEM32>\proquota.exe with <SYSTEM32>\proquota.exe
- <SYSTEM32>\print.exe with <SYSTEM32>\print.exe
- <SYSTEM32>\autoconv.exe with <SYSTEM32>\autoconv.exe.new
- <SYSTEM32>\ping6.exe with <SYSTEM32>\ping6.exe
- <SYSTEM32>\bad24 with <SYSTEM32>\ping6.exe
- <SYSTEM32>\bad57 with <SYSTEM32>\print.exe
- <SYSTEM32>\PresentationHost.exe with <SYSTEM32>\PresentationHost.exe
- <SYSTEM32>\powercfg.exe with <SYSTEM32>\powercfg.exe
- <SYSTEM32>\autolfn.exe with <SYSTEM32>\autolfn.exe.new
- <SYSTEM32>\rcp.exe with <SYSTEM32>\rcp.exe
- <SYSTEM32>\rcimlby.exe with <SYSTEM32>\rcimlby.exe
- <SYSTEM32>\bad58 with <SYSTEM32>\rcimlby.exe
- <SYSTEM32>\bad69 with <SYSTEM32>\rdsaddin.exe
- <SYSTEM32>\cacls.exe with <SYSTEM32>\cacls.exe.new
- <SYSTEM32>\rdpclip.exe with <SYSTEM32>\rdpclip.exe
- <SYSTEM32>\rasphone.exe with <SYSTEM32>\rasphone.exe
- <SYSTEM32>\rasautou.exe with <SYSTEM32>\rasautou.exe
- <SYSTEM32>\qwinsta.exe with <SYSTEM32>\qwinsta.exe
- <SYSTEM32>\qprocess.exe with <SYSTEM32>\qprocess.exe
- <SYSTEM32>\bad192 with <SYSTEM32>\rasphone.exe
- <SYSTEM32>\blastcln.exe with <SYSTEM32>\blastcln.exe.new
- <SYSTEM32>\rasdial.exe with <SYSTEM32>\rasdial.exe
- <SYSTEM32>\actmovie.exe with <SYSTEM32>\actmovie.exe.new
- <SYSTEM32>\forcedos.exe with <SYSTEM32>\forcedos.exe
- <SYSTEM32>\bad85 with <SYSTEM32>\forcedos.exe
- <SYSTEM32>\fontview.exe with <SYSTEM32>\fontview.exe
- <SYSTEM32>\bad102 with <SYSTEM32>\fsquirt.exe
- <SYSTEM32>\dllcache\tourW.exe with <SYSTEM32>\dllcache\tourW.exe.new
- <SYSTEM32>\freecell.exe with <SYSTEM32>\freecell.exe
- <SYSTEM32>\fltMc.exe with <SYSTEM32>\fltMc.exe
- <SYSTEM32>\find.exe with <SYSTEM32>\find.exe
- <SYSTEM32>\bad31 with <SYSTEM32>\find.exe
- <SYSTEM32>\fc.exe with <SYSTEM32>\fc.exe
- <SYSTEM32>\fixmapi.exe with <SYSTEM32>\fixmapi.exe
- <SYSTEM32>\finger.exe with <SYSTEM32>\finger.exe
- <SYSTEM32>\findstr.exe with <SYSTEM32>\findstr.exe
- <SYSTEM32>\fsquirt.exe with <SYSTEM32>\fsquirt.exe
- %WINDIR%\mui\muisetup.exe with %WINDIR%\mui\muisetup.exe.new
- <SYSTEM32>\help.exe with <SYSTEM32>\help.exe
- <SYSTEM32>\grpconv.exe with <SYSTEM32>\grpconv.exe
- <SYSTEM32>\icardagt.exe with <SYSTEM32>\icardagt.exe
- <SYSTEM32>\hostname.exe with <SYSTEM32>\hostname.exe
- <SYSTEM32>\bad3 with <SYSTEM32>\hostname.exe
- <SYSTEM32>\gpupdate.exe with <SYSTEM32>\gpupdate.exe
- <SYSTEM32>\bad14 with <SYSTEM32>\gdi.exe
- <SYSTEM32>\ftp.exe with <SYSTEM32>\ftp.exe
- <SYSTEM32>\fsutil.exe with <SYSTEM32>\fsutil.exe
- <SYSTEM32>\gpresult.exe with <SYSTEM32>\gpresult.exe
- %WINDIR%\msagent\agentsvr.exe with %WINDIR%\msagent\agentsvr.exe.new
- <SYSTEM32>\getmac.exe with <SYSTEM32>\getmac.exe
- <SYSTEM32>\extrac32.exe with <SYSTEM32>\extrac32.exe
- <SYSTEM32>\bad183 with <SYSTEM32>\dpvsetup.exe
- <SYSTEM32>\dpnsvr.exe with <SYSTEM32>\dpnsvr.exe
- <SYSTEM32>\dllcache\winhlp32.exe with <SYSTEM32>\dllcache\winhlp32.exe.new
- <SYSTEM32>\drwtsn32.exe with <SYSTEM32>\drwtsn32.exe
- <SYSTEM32>\driverquery.exe with <SYSTEM32>\driverquery.exe
- <SYSTEM32>\bad116 with <SYSTEM32>\driverquery.exe
- <SYSTEM32>\dplaysvr.exe with <SYSTEM32>\dplaysvr.exe
- <SYSTEM32>\dmadmin.exe with <SYSTEM32>\dmadmin.exe
- <SYSTEM32>\dllhst3g.exe with <SYSTEM32>\dllhst3g.exe
- <SYSTEM32>\dllhost.exe with <SYSTEM32>\dllhost.exe
- <SYSTEM32>\doskey.exe with <SYSTEM32>\doskey.exe
- <SYSTEM32>\bad21 with <SYSTEM32>\doskey.exe
- <SYSTEM32>\dmremote.exe with <SYSTEM32>\dmremote.exe
- <SYSTEM32>\dumprep.exe with <SYSTEM32>\dumprep.exe
- <SYSTEM32>\bad185 with <SYSTEM32>\eventvwr.exe
- <SYSTEM32>\eventtriggers.exe with <SYSTEM32>\eventtriggers.exe
- <SYSTEM32>\eventcreate.exe with <SYSTEM32>\eventcreate.exe
- <SYSTEM32>\expand.exe with <SYSTEM32>\expand.exe
- <SYSTEM32>\bad183 with <SYSTEM32>\exe2bin.exe
- <SYSTEM32>\eventvwr.exe with <SYSTEM32>\eventvwr.exe
- <SYSTEM32>\eudcedit.exe with <SYSTEM32>\eudcedit.exe
- <SYSTEM32>\dwwin.exe with <SYSTEM32>\dwwin.exe
- <SYSTEM32>\dvdupgrd.exe with <SYSTEM32>\dvdupgrd.exe
- <SYSTEM32>\dvdplay.exe with <SYSTEM32>\dvdplay.exe
- <SYSTEM32>\bad199 with <SYSTEM32>\eudcedit.exe
- <SYSTEM32>\esentutl.exe with <SYSTEM32>\esentutl.exe
- <SYSTEM32>\dxdiag.exe with <SYSTEM32>\dxdiag.exe
- <SYSTEM32>\bad197 with <SYSTEM32>\ie4uinit.exe
- <SYSTEM32>\mountvol.exe with <SYSTEM32>\mountvol.exe
- %WINDIR%\pchealth\UploadLB\Binaries\UploadM.exe with %WINDIR%\pchealth\UploadLB\Binaries\uploadm.exe.new
- <SYSTEM32>\mobsync.exe with <SYSTEM32>\mobsync.exe
- <SYSTEM32>\mpnotify.exe with <SYSTEM32>\mpnotify.exe
- <SYSTEM32>\bad88 with <SYSTEM32>\mpnotify.exe
- <SYSTEM32>\mplay32.exe with <SYSTEM32>\mplay32.exe
- <SYSTEM32>\mnmsrvc.exe with <SYSTEM32>\mnmsrvc.exe
- <SYSTEM32>\bad89 with <SYSTEM32>\migpwd.exe
- %WINDIR%\pchealth\helpctr\binaries\msconfig.exe with %WINDIR%\pchealth\helpctr\binaries\msconfig.exe.new
- <SYSTEM32>\makecab.exe with <SYSTEM32>\makecab.exe
- %WINDIR%\pchealth\helpctr\binaries\notiflag.exe with %WINDIR%\pchealth\helpctr\binaries\notiflag.exe.new
- <SYSTEM32>\mmc.exe with <SYSTEM32>\mmc.exe
- <SYSTEM32>\migpwd.exe with <SYSTEM32>\migpwd.exe
- <SYSTEM32>\mqbkup.exe with <SYSTEM32>\mqbkup.exe
- <SYSTEM32>\msg.exe with <SYSTEM32>\msg.exe
- <SYSTEM32>\msdtc.exe with <SYSTEM32>\msdtc.exe
- <SYSTEM32>\bad181 with <SYSTEM32>\msdtc.exe
- <SYSTEM32>\mshta.exe with <SYSTEM32>\mshta.exe
- <SYSTEM32>\bad2 with <SYSTEM32>\mshta.exe
- <SYSTEM32>\mshearts.exe with <SYSTEM32>\mshearts.exe
- <SYSTEM32>\accwiz.exe with <SYSTEM32>\accwiz.exe.new
- <SYSTEM32>\bad28 with <SYSTEM32>\mqtgsvc.exe
- <SYSTEM32>\mqsvc.exe with <SYSTEM32>\mqsvc.exe
- <SYSTEM32>\bad176 with <SYSTEM32>\mqsvc.exe
- <SYSTEM32>\bad170 with <SYSTEM32>\mscdexnt.exe
- <SYSTEM32>\mrinfo.exe with <SYSTEM32>\mrinfo.exe
- <SYSTEM32>\mqtgsvc.exe with <SYSTEM32>\mqtgsvc.exe
- <SYSTEM32>\magnify.exe with <SYSTEM32>\magnify.exe
- <SYSTEM32>\ipxroute.exe with <SYSTEM32>\ipxroute.exe
- %WINDIR%\pchealth\helpctr\binaries\HelpHost.exe with %WINDIR%\pchealth\helpctr\binaries\helphost.exe.new
- <SYSTEM32>\ipv6.exe with <SYSTEM32>\ipv6.exe
- <SYSTEM32>\lnkstub.exe with <SYSTEM32>\lnkstub.exe
- <SYSTEM32>\lights.exe with <SYSTEM32>\lights.exe
- <SYSTEM32>\label.exe with <SYSTEM32>\label.exe
- <SYSTEM32>\ipsec6.exe with <SYSTEM32>\ipsec6.exe
- <SYSTEM32>\bad194 with <SYSTEM32>\iexpress.exe
- %WINDIR%\pchealth\helpctr\binaries\HelpCtr.exe with %WINDIR%\pchealth\helpctr\binaries\helpctr.exe.new
- <SYSTEM32>\ie4uinit.exe with <SYSTEM32>\ie4uinit.exe
- <SYSTEM32>\ipconfig.exe with <SYSTEM32>\ipconfig.exe
- <SYSTEM32>\imapi.exe with <SYSTEM32>\imapi.exe
- <SYSTEM32>\iexpress.exe with <SYSTEM32>\iexpress.exe
- <SYSTEM32>\locator.exe with <SYSTEM32>\locator.exe
- <SYSTEM32>\lpq.exe with <SYSTEM32>\lpq.exe
- %WINDIR%\pchealth\helpctr\binaries\HscUpd.exe with %WINDIR%\pchealth\helpctr\binaries\hscupd.exe.new
- <SYSTEM32>\bad95 with <SYSTEM32>\lpq.exe
- <SYSTEM32>\bad160 with <SYSTEM32>\magnify.exe
- <SYSTEM32>\lsass.exe with <SYSTEM32>\lsass.exe
- <SYSTEM32>\lpr.exe with <SYSTEM32>\lpr.exe
- <SYSTEM32>\logonui.exe with <SYSTEM32>\logonui.exe
- <SYSTEM32>\logagent.exe with <SYSTEM32>\logagent.exe
- <SYSTEM32>\bad189 with <SYSTEM32>\logagent.exe
- <SYSTEM32>\lodctr.exe with <SYSTEM32>\lodctr.exe
- <SYSTEM32>\logoff.exe with <SYSTEM32>\logoff.exe
- <SYSTEM32>\logman.exe with <SYSTEM32>\logman.exe
- %WINDIR%\pchealth\helpctr\binaries\HelpSvc.exe with %WINDIR%\pchealth\helpctr\binaries\helpsvc.exe.new
- <Auxiliary element>
- C:\boot00.exe
- <Full path to virus>.exe
- C:\boot00.exe (downloaded from the Internet)
- %PROGRAM_FILES%\Windows Media Player\mplayer2.exe
- %PROGRAM_FILES%\Windows Media Player\setup_wm.exe
- %PROGRAM_FILES%\Outlook Express\wabmig.exe
- %PROGRAM_FILES%\Windows Media Player\migrate.exe
- %PROGRAM_FILES%\Windows NT\hypertrm.exe
- %PROGRAM_FILES%\Windows NT\Accessories\wordpad.exe
- %PROGRAM_FILES%\Windows Media Player\wmplayer.exe
- %PROGRAM_FILES%\Windows NT\dialer.exe
- %PROGRAM_FILES%\Outlook Express\wab.exe
- %PROGRAM_FILES%\NetMeeting\cb32.exe
- %PROGRAM_FILES%\NetMeeting\conf.exe
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\shvlzm.exe
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\zClientm.exe
- %PROGRAM_FILES%\Outlook Express\oemig50.exe
- %PROGRAM_FILES%\Outlook Express\setup50.exe
- %PROGRAM_FILES%\NetMeeting\wb32.exe
- %PROGRAM_FILES%\Outlook Express\msimn.exe
- %PROGRAM_FILES%\Windows NT\Pinball\PINBALL.EXE
- %WINDIR%\taskman.exe
- %WINDIR%\twunk_16.exe
- %WINDIR%\notepad.exe
- %WINDIR%\regedit.exe
- %WINDIR%\winhlp32.exe
- %WINDIR%\Help\Tours\mmTour\tour.exe
- %WINDIR%\twunk_32.exe
- %WINDIR%\winhelp.exe
- %WINDIR%\hh.exe
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\fifo.log
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP15\rp.log
- <Auxiliary element>
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP15\RestorePointSize
- <PATH_<Auxiliary name>.EXE>
- <PATH_<Auxiliary name>.EXE>_
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\drivetable.txt
- <Auxiliary name>
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\Rvsezm.exe
- %PROGRAM_FILES%\FireFox\plugin-container.exe
- %PROGRAM_FILES%\FireFox\shlibsign.exe
- %PROGRAM_FILES%\FireFox\mangle.exe
- %PROGRAM_FILES%\FireFox\nsinstall.exe
- %PROGRAM_FILES%\FireFox\xpidl.exe
- %PROGRAM_FILES%\FireFox\xpt_dump.exe
- %PROGRAM_FILES%\FireFox\updater.exe
- %PROGRAM_FILES%\FireFox\xpcshell.exe
- %PROGRAM_FILES%\FireFox\js.exe
- %CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE
- %CommonProgramFiles%\Microsoft Shared\DW\DWTRIG20.EXE
- C:\boot00.exe
- C:\Far2\Far.exe
- %PROGRAM_FILES%\FireFox\crashreporter.exe
- %PROGRAM_FILES%\FireFox\firefox.exe
- %CommonProgramFiles%\Microsoft Shared\MSInfo\msinfo32.exe
- %CommonProgramFiles%\Microsoft Shared\Speech\sapisvr.exe
- %PROGRAM_FILES%\FireFox\xpt_link.exe
- %PROGRAM_FILES%\MSN\MSNCoreFiles\Install\msnsusii.exe
- %PROGRAM_FILES%\MSN\MSNCoreFiles\Install\MSN9Components\Digcore.exe
- %PROGRAM_FILES%\Messenger\msmsgs.exe
- %PROGRAM_FILES%\Movie Maker\moviemk.exe
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\chkrzm.exe
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\hrtzzm.exe
- %PROGRAM_FILES%\MSN\MSNCoreFiles\Install\MSN9Components\Msncli.exe
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\bckgzm.exe
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\isignup.exe
- %PROGRAM_FILES%\Internet Explorer\IEXPLORE.EXE
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\icwconn1.exe
- %PROGRAM_FILES%\FireFox\uninstall\helper.exe
- %PROGRAM_FILES%\Internet Explorer\iedw.exe
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\icwtutor.exe
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\inetwiz.exe
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\icwconn2.exe
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\icwrmind.exe
- %PROGRAM_FILES%\Windows Media Player\bad142
- %PROGRAM_FILES%\Windows Media Player\bad163
- %PROGRAM_FILES%\Windows Media Player\bad51
- %PROGRAM_FILES%\Windows NT\bad124
- %PROGRAM_FILES%\Windows Media Player\bad180
- %PROGRAM_FILES%\Outlook Express\bad10
- %PROGRAM_FILES%\Outlook Express\bad52
- %PROGRAM_FILES%\Outlook Express\bad154
- %PROGRAM_FILES%\Outlook Express\bad187
- %PROGRAM_FILES%\Outlook Express\bad26
- %PROGRAM_FILES%\Windows NT\Accessories\bad27
- %WINDIR%\bad182
- %WINDIR%\bad4
- %WINDIR%\bad89
- %WINDIR%\Help\Tours\mmTour\bad131
- %WINDIR%\bad65
- %WINDIR%\bad75
- %PROGRAM_FILES%\Windows NT\Pinball\bad166
- %WINDIR%\bad145
- %WINDIR%\bad114
- %WINDIR%\bad146
- %PROGRAM_FILES%\NetMeeting\bad133
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad128
- %PROGRAM_FILES%\Internet Explorer\bad17
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad144
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad177
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad123
- <Current directory>\bad36
- C:\boot00.exe
- %CommonProgramFiles%\Microsoft Shared\MSInfo\bad43
- %PROGRAM_FILES%\Internet Explorer\bad179
- %CommonProgramFiles%\Microsoft Shared\Speech\bad38
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad91
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad129
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad174
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad125
- %PROGRAM_FILES%\NetMeeting\bad39
- %PROGRAM_FILES%\NetMeeting\bad137
- %PROGRAM_FILES%\Movie Maker\bad3
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad44
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad41
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad118
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad153
- <SYSTEM32>\bad127
- <SYSTEM32>\bad39
- <SYSTEM32>\bad92
- <SYSTEM32>\bad42
- <SYSTEM32>\bad24
- <SYSTEM32>\bad73
- <SYSTEM32>\bad141
- <SYSTEM32>\bad167
- <SYSTEM32>\bad49
- <SYSTEM32>\bad154
- <SYSTEM32>\bad76
- <SYSTEM32>\bad191
- <SYSTEM32>\bad5
- <SYSTEM32>\bad159
- <SYSTEM32>\bad110
- <SYSTEM32>\bad101
- <SYSTEM32>\bad157
- <SYSTEM32>\bad86
- <SYSTEM32>\bad9
- <SYSTEM32>\bad29
- <SYSTEM32>\bad198
- <SYSTEM32>\bad133
- <SYSTEM32>\bad195
- <SYSTEM32>\bad19
- <SYSTEM32>\bad74
- <SYSTEM32>\bad70
- <SYSTEM32>\bad65
- <SYSTEM32>\bad60
- <SYSTEM32>\bad22
- <SYSTEM32>\bad142
- <SYSTEM32>\bad30
- <SYSTEM32>\bad15
- <SYSTEM32>\bad90
- <SYSTEM32>\bad107
- <SYSTEM32>\bad79
- <SYSTEM32>\bad91
- <SYSTEM32>\bad162
- <SYSTEM32>\bad48
- <SYSTEM32>\bad50
- <SYSTEM32>\bad10
- <SYSTEM32>\bad18
- <SYSTEM32>\bad62
- <SYSTEM32>\bad143
- <SYSTEM32>\bad171
- <SYSTEM32>\bad7
- <SYSTEM32>\bad56
- <SYSTEM32>\bad126
- <SYSTEM32>\bad181
- <SYSTEM32>\bad84
- <SYSTEM32>\bad32
- <SYSTEM32>\bad184
- <SYSTEM32>\bad40
- <SYSTEM32>\bad160
- <SYSTEM32>\bad77
- <SYSTEM32>\bad149
- <SYSTEM32>\bad95
- <SYSTEM32>\bad85
- <SYSTEM32>\bad165
- <SYSTEM32>\bad14
- <SYSTEM32>\bad88
- <SYSTEM32>\bad81
- <SYSTEM32>\bad156
- <SYSTEM32>\bad169
- <SYSTEM32>\bad63
- <SYSTEM32>\bad122
- <SYSTEM32>\bad120
- <SYSTEM32>\bad190
- <SYSTEM32>\bad58
- <SYSTEM32>\bad11
- <SYSTEM32>\bad129
- <SYSTEM32>\bad111
- <SYSTEM32>\bad148
- <SYSTEM32>\bad28
- <SYSTEM32>\bad172
- <SYSTEM32>\bad166
- <SYSTEM32>\bad44
- <SYSTEM32>\bad100
- <SYSTEM32>\bad114
- <SYSTEM32>\bad2
- <SYSTEM32>\bad192
- <SYSTEM32>\bad189
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad174
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad129
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad118
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad41
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad153
- %PROGRAM_FILES%\NetMeeting\bad133
- %PROGRAM_FILES%\Outlook Express\bad52
- %PROGRAM_FILES%\NetMeeting\bad39
- %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad125
- %PROGRAM_FILES%\NetMeeting\bad137
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad128
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad144
- %PROGRAM_FILES%\Internet Explorer\bad17
- %CommonProgramFiles%\Microsoft Shared\Speech\bad38
- %PROGRAM_FILES%\Internet Explorer\bad179
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad44
- %PROGRAM_FILES%\Movie Maker\bad3
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad91
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad123
- %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad177
- %WINDIR%\bad146
- %WINDIR%\bad114
- %WINDIR%\bad145
- %PROGRAM_FILES%\Windows NT\Pinball\bad166
- %WINDIR%\bad75
- %WINDIR%\bad65
- %WINDIR%\Help\Tours\mmTour\bad131
- %WINDIR%\bad89
- %WINDIR%\bad4
- %WINDIR%\bad182
- %PROGRAM_FILES%\Outlook Express\bad187
- %PROGRAM_FILES%\Windows Media Player\bad163
- %PROGRAM_FILES%\Outlook Express\bad26
- %PROGRAM_FILES%\Outlook Express\bad10
- %PROGRAM_FILES%\Outlook Express\bad154
- %PROGRAM_FILES%\Windows NT\bad124
- %PROGRAM_FILES%\Windows NT\Accessories\bad27
- %PROGRAM_FILES%\Windows Media Player\bad180
- %PROGRAM_FILES%\Windows Media Player\bad142
- %PROGRAM_FILES%\Windows Media Player\bad51
- %CommonProgramFiles%\Microsoft Shared\MSInfo\bad43
- <SYSTEM32>\bad52
- <SYSTEM32>\bad47
- <SYSTEM32>\bad51
- <SYSTEM32>\bad121
- <SYSTEM32>\bad87
- <SYSTEM32>\Com\bad124
- <SYSTEM32>\npp\bad161
- <SYSTEM32>\Com\bad145
- <SYSTEM32>\bad46
- <SYSTEM32>\bad193
- <SYSTEM32>\bad71
- <SYSTEM32>\bad83
- <SYSTEM32>\bad130
- <SYSTEM32>\bad82
- <SYSTEM32>\bad55
- <SYSTEM32>\bad93
- <SYSTEM32>\bad45
- <SYSTEM32>\bad64
- <SYSTEM32>\bad38
- <SYSTEM32>\bad96
- <SYSTEM32>\wbem\bad18
- <SYSTEM32>\wbem\bad144
- <SYSTEM32>\wbem\bad164
- <SYSTEM32>\wbem\bad196
- <SYSTEM32>\wbem\bad80
- <SYSTEM32>\XPSViewer\bad52
- <Auxiliary element>
- <SYSTEM32>\wbem\bad3
- <SYSTEM32>\wbem\bad102
- <SYSTEM32>\wbem\bad47
- <SYSTEM32>\Restore\bad69
- <SYSTEM32>\spool\prtprocs\w32x86\bad55
- <SYSTEM32>\Restore\bad43
- <SYSTEM32>\oobe\bad93
- <SYSTEM32>\oobe\bad131
- <SYSTEM32>\usmt\bad169
- <SYSTEM32>\wbem\bad192
- <SYSTEM32>\usmt\bad74
- <SYSTEM32>\URTTEMP\bad3
- <SYSTEM32>\usmt\bad136
- <SYSTEM32>\bad117
- %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\bad124
- %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\bad14
- %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\bad33
- %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\bad53
- %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\bad19
- %WINDIR%\Microsoft.NET\Framework\v3.5\bad38
- %WINDIR%\Microsoft.NET\Framework\v3.5\bad66
- %WINDIR%\Microsoft.NET\Framework\v3.5\bad11
- %WINDIR%\Microsoft.NET\Framework\v3.0\WPF\bad185
- %WINDIR%\Microsoft.NET\Framework\v3.0\WPF\XamlViewer\bad171
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad123
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad74
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad31
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad11
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad102
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad69
- %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\bad63
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad129
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad20
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad12
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad170
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad23
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad182
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad98
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad91
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad37
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad171
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad76
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad190
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad65
- %WINDIR%\Microsoft.NET\Framework\v3.5\bad17
- %WINDIR%\Microsoft.NET\Framework\v3.5\bad151
- %WINDIR%\Microsoft.NET\Framework\v3.5\bad2
- %WINDIR%\Microsoft.NET\Framework\v3.5\bad196
- %WINDIR%\Microsoft.NET\Framework\v3.5\bad71
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad178
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad165
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad73
- %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\bad93
- %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\bad182
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad104
- %WINDIR%\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5\bad60
- %WINDIR%\Microsoft.NET\Framework\bad45
- %WINDIR%\Microsoft.NET\bad120
- %WINDIR%\bad8
- %WINDIR%\Help\Tours\mmTour\bad115
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad97
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad107
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad64
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad111
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad84
- %WINDIR%\bad78
- %WINDIR%\bad35
- %WINDIR%\bad30
- <Current directory>\bad36
- %WINDIR%\bad121
- %WINDIR%\bad49
- %WINDIR%\bad7
- %WINDIR%\bad119
- %WINDIR%\bad197
- %WINDIR%\bad105
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad131
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad149
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad24
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad9
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad20
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad51
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad59
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad19
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad173
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad29
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad32
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad46
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad22
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad37
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad135
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad128
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad44
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad139
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad62
- %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad52
- <SYSTEM32>\bad134
- <SYSTEM32>\bad75
- <SYSTEM32>\bad116
- <SYSTEM32>\bad108
- <SYSTEM32>\bad138
- <SYSTEM32>\bad20
- <SYSTEM32>\bad176
- <SYSTEM32>\bad68
- <SYSTEM32>\bad135
- <SYSTEM32>\bad36
- <SYSTEM32>\bad99
- <SYSTEM32>\bad69
- <SYSTEM32>\bad33
- <SYSTEM32>\bad57
- <SYSTEM32>\bad89
- <SYSTEM32>\bad152
- <SYSTEM32>\bad119
- <SYSTEM32>\bad185
- <SYSTEM32>\bad3
- <SYSTEM32>\bad139
- <SYSTEM32>\bad102
- <SYSTEM32>\bad150
- <SYSTEM32>\bad175
- <SYSTEM32>\bad104
- <SYSTEM32>\bad0
- <SYSTEM32>\bad41
- <SYSTEM32>\bad35
- <SYSTEM32>\bad199
- <SYSTEM32>\bad31
- <SYSTEM32>\bad115
- <SYSTEM32>\bad132
- <SYSTEM32>\bad67
- <SYSTEM32>\bad170
- <SYSTEM32>\bad97
- <SYSTEM32>\bad144
- <SYSTEM32>\bad21
- <SYSTEM32>\bad197
- <SYSTEM32>\bad187
- <SYSTEM32>\bad124
- <SYSTEM32>\bad8
- <SYSTEM32>\bad196
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad192
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\bad111
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad72
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad24
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad94
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\WPF\bad157
- %WINDIR%\msagent\bad12
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\bad70
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\bad8
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\bad21
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad83
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad127
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad125
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad122
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad21
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad162
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad0
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad4
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad26
- %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad174
- <SYSTEM32>\bad194
- <SYSTEM32>\bad178
- <SYSTEM32>\bad17
- <SYSTEM32>\bad158
- <SYSTEM32>\bad6
- <SYSTEM32>\bad136
- <SYSTEM32>\bad182
- <SYSTEM32>\bad53
- <SYSTEM32>\bad153
- <SYSTEM32>\bad34
- %WINDIR%\pchealth\helpctr\binaries\bad22
- %WINDIR%\pchealth\helpctr\binaries\bad9
- %WINDIR%\pchealth\helpctr\binaries\bad132
- %WINDIR%\mui\bad10
- %WINDIR%\pchealth\helpctr\binaries\bad41
- <SYSTEM32>\bad140
- <SYSTEM32>\bad78
- %WINDIR%\pchealth\UploadLB\Binaries\bad194
- %WINDIR%\pchealth\helpctr\binaries\bad112
- %WINDIR%\pchealth\helpctr\binaries\bad2
- from <SYSTEM32>\netsetup.exe to <SYSTEM32>\bad76
- from <SYSTEM32>\netsh.exe to <SYSTEM32>\bad191
- from <SYSTEM32>\netdde.exe to <SYSTEM32>\bad5
- from <SYSTEM32>\nddeapir.exe to <SYSTEM32>\bad159
- from <SYSTEM32>\net.exe to <SYSTEM32>\bad110
- from <SYSTEM32>\ntoskrnl.exe to <SYSTEM32>\bad86
- from <SYSTEM32>\ntsd.exe to <SYSTEM32>\bad101
- from <SYSTEM32>\ntbackup.exe to <SYSTEM32>\bad2
- from <SYSTEM32>\netstat.exe to <SYSTEM32>\bad9
- from <SYSTEM32>\notepad.exe to <SYSTEM32>\bad29
- from <SYSTEM32>\mqbkup.exe to <SYSTEM32>\bad140
- from <SYSTEM32>\msg.exe to <SYSTEM32>\bad11
- from <SYSTEM32>\mplay32.exe to <SYSTEM32>\bad111
- from <SYSTEM32>\mobsync.exe to <SYSTEM32>\bad169
- from <SYSTEM32>\mountvol.exe to <SYSTEM32>\bad129
- from <SYSTEM32>\mstinit.exe to <SYSTEM32>\bad116
- from <SYSTEM32>\mstsc.exe to <SYSTEM32>\bad18
- from <SYSTEM32>\msswchx.exe to <SYSTEM32>\bad132
- from <SYSTEM32>\mshearts.exe to <SYSTEM32>\bad190
- from <SYSTEM32>\msiexec.exe to <SYSTEM32>\bad58
- from <SYSTEM32>\ntvdm.exe to <SYSTEM32>\bad157
- from <SYSTEM32>\rdpclip.exe to <SYSTEM32>\bad28
- from <SYSTEM32>\recover.exe to <SYSTEM32>\bad79
- from <SYSTEM32>\rasdial.exe to <SYSTEM32>\bad107
- from <SYSTEM32>\qwinsta.exe to <SYSTEM32>\bad141
- from <SYSTEM32>\rasautou.exe to <SYSTEM32>\bad69
- from <SYSTEM32>\regsvr32.exe to <SYSTEM32>\bad53
- from <SYSTEM32>\relog.exe to <SYSTEM32>\bad50
- from <SYSTEM32>\regini.exe to <SYSTEM32>\bad15
- from <SYSTEM32>\reg.exe to <SYSTEM32>\bad90
- from <SYSTEM32>\regedt32.exe to <SYSTEM32>\bad30
- from <SYSTEM32>\packager.exe to <SYSTEM32>\bad127
- from <SYSTEM32>\ping.exe to <SYSTEM32>\bad39
- from <SYSTEM32>\osuninst.exe to <SYSTEM32>\bad92
- from <SYSTEM32>\odbcconf.exe to <SYSTEM32>\bad42
- from <SYSTEM32>\osk.exe to <SYSTEM32>\bad24
- from <SYSTEM32>\qappsrv.exe to <SYSTEM32>\bad73
- from <SYSTEM32>\qprocess.exe to <SYSTEM32>\bad95
- from <SYSTEM32>\proxycfg.exe to <SYSTEM32>\bad167
- from <SYSTEM32>\powercfg.exe to <SYSTEM32>\bad49
- from <SYSTEM32>\PresentationHost.exe to <SYSTEM32>\bad154
- from <SYSTEM32>\fontview.exe to <SYSTEM32>\bad171
- from <SYSTEM32>\freecell.exe to <SYSTEM32>\bad62
- from <SYSTEM32>\fltMc.exe to <SYSTEM32>\bad56
- from <SYSTEM32>\finger.exe to <SYSTEM32>\bad165
- from <SYSTEM32>\fixmapi.exe to <SYSTEM32>\bad7
- from <SYSTEM32>\gpupdate.exe to <SYSTEM32>\bad84
- from <SYSTEM32>\grpconv.exe to <SYSTEM32>\bad126
- from <SYSTEM32>\gpresult.exe to <SYSTEM32>\bad184
- from <SYSTEM32>\fsutil.exe to <SYSTEM32>\bad143
- from <SYSTEM32>\getmac.exe to <SYSTEM32>\bad32
- from <SYSTEM32>\eventcreate.exe to <SYSTEM32>\bad77
- from <SYSTEM32>\eventtriggers.exe to <SYSTEM32>\bad40
- from <SYSTEM32>\esentutl.exe to <SYSTEM32>\bad95
- from <SYSTEM32>\dxdiag.exe to <SYSTEM32>\bad117
- from <SYSTEM32>\edlin.exe to <SYSTEM32>\bad149
- from <SYSTEM32>\fc.exe to <SYSTEM32>\bad14
- from <SYSTEM32>\findstr.exe to <SYSTEM32>\bad85
- from <SYSTEM32>\fastopen.exe to <SYSTEM32>\bad81
- from <SYSTEM32>\expand.exe to <SYSTEM32>\bad160
- from <SYSTEM32>\extrac32.exe to <SYSTEM32>\bad88
- from <SYSTEM32>\help.exe to <SYSTEM32>\bad181
- from <SYSTEM32>\logoff.exe to <SYSTEM32>\bad114
- from <SYSTEM32>\logonui.exe to <SYSTEM32>\bad122
- from <SYSTEM32>\logman.exe to <SYSTEM32>\bad149
- from <SYSTEM32>\locator.exe to <SYSTEM32>\bad2
- from <SYSTEM32>\lodctr.exe to <SYSTEM32>\bad100
- from <SYSTEM32>\mmc.exe to <SYSTEM32>\bad63
- from <SYSTEM32>\mnmsrvc.exe to <SYSTEM32>\bad156
- from <SYSTEM32>\mem.exe to <SYSTEM32>\bad120
- from <SYSTEM32>\lpr.exe to <SYSTEM32>\bad20
- from <SYSTEM32>\lsass.exe to <SYSTEM32>\bad186
- from <SYSTEM32>\ipsec6.exe to <SYSTEM32>\bad3
- from <SYSTEM32>\ipv6.exe to <SYSTEM32>\bad148
- from <SYSTEM32>\ipconfig.exe to <SYSTEM32>\bad172
- from <SYSTEM32>\icardagt.exe to <SYSTEM32>\bad166
- from <SYSTEM32>\imapi.exe to <SYSTEM32>\bad44
- from <SYSTEM32>\lights.exe to <SYSTEM32>\bad194
- from <SYSTEM32>\lnkstub.exe to <SYSTEM32>\bad189
- from <SYSTEM32>\label.exe to <SYSTEM32>\bad192
- from <SYSTEM32>\ipxroute.exe to <SYSTEM32>\bad28
- from <SYSTEM32>\krnl386.exe to <SYSTEM32>\bad53
- from <SYSTEM32>\replace.exe to <SYSTEM32>\bad10
- from <SYSTEM32>\wowexec.exe to <SYSTEM32>\bad82
- from <SYSTEM32>\wpabaln.exe to <SYSTEM32>\bad199
- from <SYSTEM32>\winspool.exe to <SYSTEM32>\bad47
- from <SYSTEM32>\winlogon.exe to <SYSTEM32>\bad131
- from <SYSTEM32>\winmsd.exe to <SYSTEM32>\bad3
- from <SYSTEM32>\Com\comrepl.exe to <SYSTEM32>\Com\bad145
- from <SYSTEM32>\Com\comrereg.exe to <SYSTEM32>\Com\bad124
- from <SYSTEM32>\xcopy.exe to <SYSTEM32>\bad192
- from <SYSTEM32>\wpnpinst.exe to <SYSTEM32>\bad46
- from <SYSTEM32>\wscript.exe to <SYSTEM32>\bad193
- from <SYSTEM32>\usrprbda.exe to <SYSTEM32>\bad45
- from <SYSTEM32>\verifier.exe to <SYSTEM32>\bad70
- from <SYSTEM32>\userinit.exe to <SYSTEM32>\bad42
- from <SYSTEM32>\tsshutdn.exe to <SYSTEM32>\bad93
- from <SYSTEM32>\ups.exe to <SYSTEM32>\bad88
- from <SYSTEM32>\wextract.exe to <SYSTEM32>\bad63
- from <SYSTEM32>\winchat.exe to <SYSTEM32>\bad52
- from <SYSTEM32>\w32tm.exe to <SYSTEM32>\bad51
- from <SYSTEM32>\vssvc.exe to <SYSTEM32>\bad121
- from <SYSTEM32>\vwipxspx.exe to <SYSTEM32>\bad87
- from <SYSTEM32>\npp\nppagent.exe to <SYSTEM32>\npp\bad161
- from <SYSTEM32>\wbem\winmgmt.exe to <SYSTEM32>\wbem\bad18
- from <SYSTEM32>\wbem\wmiadap.exe to <SYSTEM32>\wbem\bad144
- from <SYSTEM32>\wbem\wbemtest.exe to <SYSTEM32>\wbem\bad164
- from <SYSTEM32>\wbem\scrcons.exe to <SYSTEM32>\wbem\bad196
- from <SYSTEM32>\wbem\unsecapp.exe to <SYSTEM32>\wbem\bad80
- from <SYSTEM32>\XPSViewer\XPSViewer.exe to <SYSTEM32>\XPSViewer\bad52
- from <Auxiliary element> to <Auxiliary element>
- from <SYSTEM32>\wbem\wmiprvse.exe to <SYSTEM32>\wbem\bad3
- from <SYSTEM32>\wbem\wmiapsrv.exe to <SYSTEM32>\wbem\bad102
- from <SYSTEM32>\wbem\wmic.exe to <SYSTEM32>\wbem\bad47
- from <SYSTEM32>\Restore\srdiag.exe to <SYSTEM32>\Restore\bad69
- from <SYSTEM32>\spool\prtprocs\w32x86\printfilterpipelinesvc.exe to <SYSTEM32>\spool\prtprocs\w32x86\bad55
- from <SYSTEM32>\Restore\rstrui.exe to <SYSTEM32>\Restore\bad43
- from <SYSTEM32>\oobe\msoobe.exe to <SYSTEM32>\oobe\bad93
- from <SYSTEM32>\oobe\oobebaln.exe to <SYSTEM32>\oobe\bad131
- from <SYSTEM32>\usmt\migwiz_a.exe to <SYSTEM32>\usmt\bad169
- from <SYSTEM32>\wbem\mofcomp.exe to <SYSTEM32>\wbem\bad192
- from <SYSTEM32>\usmt\migwiz.exe to <SYSTEM32>\usmt\bad74
- from <SYSTEM32>\URTTEMP\regtlib.exe to <SYSTEM32>\URTTEMP\bad3
- from <SYSTEM32>\usmt\migload.exe to <SYSTEM32>\usmt\bad136
- from <SYSTEM32>\secedit.exe to <SYSTEM32>\bad133
- from <SYSTEM32>\services.exe to <SYSTEM32>\bad146
- from <SYSTEM32>\schtasks.exe to <SYSTEM32>\bad198
- from <SYSTEM32>\sc.exe to <SYSTEM32>\bad58
- from <SYSTEM32>\scardsvr.exe to <SYSTEM32>\bad102
- from <SYSTEM32>\shadow.exe to <SYSTEM32>\bad142
- from <SYSTEM32>\share.exe to <SYSTEM32>\bad129
- from <SYSTEM32>\sfc.exe to <SYSTEM32>\bad171
- from <SYSTEM32>\sessmgr.exe to <SYSTEM32>\bad101
- from <SYSTEM32>\sethc.exe to <SYSTEM32>\bad22
- from <SYSTEM32>\rsmsink.exe to <SYSTEM32>\bad91
- from <SYSTEM32>\rsnotify.exe to <SYSTEM32>\bad69
- from <SYSTEM32>\rsh.exe to <SYSTEM32>\bad17
- from <SYSTEM32>\rexec.exe to <SYSTEM32>\bad63
- from <SYSTEM32>\routemon.exe to <SYSTEM32>\bad48
- from <SYSTEM32>\runonce.exe to <SYSTEM32>\bad74
- from <SYSTEM32>\rwinsta.exe to <SYSTEM32>\bad195
- from <SYSTEM32>\rundll32.exe to <SYSTEM32>\bad19
- from <SYSTEM32>\rsvp.exe to <SYSTEM32>\bad81
- from <SYSTEM32>\runas.exe to <SYSTEM32>\bad162
- from <SYSTEM32>\shmgrate.exe to <SYSTEM32>\bad189
- from <SYSTEM32>\systeminfo.exe to <SYSTEM32>\bad74
- from <SYSTEM32>\taskman.exe to <SYSTEM32>\bad194
- from <SYSTEM32>\sysocmgr.exe to <SYSTEM32>\bad71
- from <SYSTEM32>\subst.exe to <SYSTEM32>\bad62
- from <SYSTEM32>\sysedit.exe to <SYSTEM32>\bad116
- from <SYSTEM32>\tracert.exe to <SYSTEM32>\bad96
- from <SYSTEM32>\tskill.exe to <SYSTEM32>\bad64
- from <SYSTEM32>\tracerpt.exe to <SYSTEM32>\bad38
- from <SYSTEM32>\telnet.exe to <SYSTEM32>\bad170
- from <SYSTEM32>\tlntsess.exe to <SYSTEM32>\bad83
- from <SYSTEM32>\smss.exe to <SYSTEM32>\bad12
- from <SYSTEM32>\sort.exe to <SYSTEM32>\bad82
- from <SYSTEM32>\smlogsvc.exe to <SYSTEM32>\bad65
- from <SYSTEM32>\shutdown.exe to <SYSTEM32>\bad60
- from <SYSTEM32>\skeys.exe to <SYSTEM32>\bad70
- from <SYSTEM32>\spupdsvc.exe to <SYSTEM32>\bad2
- from <SYSTEM32>\stimon.exe to <SYSTEM32>\bad7
- from <SYSTEM32>\sprestrt.exe to <SYSTEM32>\bad130
- from <SYSTEM32>\spnpinst.exe to <SYSTEM32>\bad55
- from <SYSTEM32>\spoolsv.exe to <SYSTEM32>\bad29
- from %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\PerformanceCounterInstaller.exe to %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\bad14
- from %WINDIR%\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe to %WINDIR%\Microsoft.NET\Framework\v3.0\WPF\bad185
- from %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\WsatConfig.exe to %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\bad124
- from %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelReg.exe to %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\bad19
- from %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe to %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\bad33
- from %WINDIR%\Microsoft.NET\Framework\v3.5\AddInUtil.exe to %WINDIR%\Microsoft.NET\Framework\v3.5\bad66
- from %WINDIR%\Microsoft.NET\Framework\v3.5\csc.exe to %WINDIR%\Microsoft.NET\Framework\v3.5\bad196
- from %WINDIR%\Microsoft.NET\Framework\v3.5\AddInProcess32.exe to %WINDIR%\Microsoft.NET\Framework\v3.5\bad38
- from %WINDIR%\Microsoft.NET\Framework\v3.0\WPF\XamlViewer\XamlViewer_v0300.exe to %WINDIR%\Microsoft.NET\Framework\v3.0\WPF\XamlViewer\bad171
- from %WINDIR%\Microsoft.NET\Framework\v3.5\AddInProcess.exe to %WINDIR%\Microsoft.NET\Framework\v3.5\bad11
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad74
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ngen.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad20
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad123
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ilasm.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad102
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad31
- from %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ComSvcConfig.exe to %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\bad63
- from %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe to %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\bad53
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad69
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad12
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad129
- from %WINDIR%\Microsoft.NET\Framework\v3.5\DataSvcUtil.exe to %WINDIR%\Microsoft.NET\Framework\v3.5\bad71
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_wp.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad190
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\CasPol.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad65
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad23
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_regbrowsers.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad182
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_regsql.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad170
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\DataSvcUtil.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad122
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\EdmGen.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad21
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\cvtres.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad171
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ComSvcConfig.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad76
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\csc.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad37
- from %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\DeleteTemp.exe to %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\bad93
- from %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe to %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\bad182
- from %WINDIR%\Microsoft.NET\Framework\v3.5\WFServicesReg.exe to %WINDIR%\Microsoft.NET\Framework\v3.5\bad151
- from %WINDIR%\Microsoft.NET\Framework\v3.5\EdmGen.exe to %WINDIR%\Microsoft.NET\Framework\v3.5\bad2
- from %WINDIR%\Microsoft.NET\Framework\v3.5\vbc.exe to %WINDIR%\Microsoft.NET\Framework\v3.5\bad17
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad98
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad91
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\AddInUtil.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad165
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\AddInProcess.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad73
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad178
- from %WINDIR%\Microsoft.NET\Framework\NETFXSBS10.exe to %WINDIR%\Microsoft.NET\Framework\bad45
- from %WINDIR%\Microsoft.NET\Framework\v1.1.4322\aspnet_regiis.exe to %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad111
- from %WINDIR%\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5\Microsoft.Workflow.Compiler.exe to %WINDIR%\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5\bad60
- from %WINDIR%\Help\Tours\mmTour\tour.exe to %WINDIR%\Help\Tours\mmTour\bad115
- from %WINDIR%\Microsoft.NET\NETFXRepair.exe to %WINDIR%\Microsoft.NET\bad120
- from %WINDIR%\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe to %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad107
- from %WINDIR%\Microsoft.NET\Framework\v1.1.4322\csc.exe to %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad37
- from %WINDIR%\Microsoft.NET\Framework\v1.1.4322\CasPol.exe to %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad97
- from %WINDIR%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe to %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad84
- from %WINDIR%\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe to %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad64
- from %WINDIR%\sfk.exe to %WINDIR%\bad35
- from %WINDIR%\sleep.exe to %WINDIR%\bad197
- from %WINDIR%\regedit.exe to %WINDIR%\bad78
- from %WINDIR%\hh.exe to %WINDIR%\bad121
- from %WINDIR%\NOTEPAD.EXE to %WINDIR%\bad30
- from %WINDIR%\winhelp.exe to %WINDIR%\bad7
- from %WINDIR%\winhlp32.exe to %WINDIR%\bad8
- from %WINDIR%\twunk_32.exe to %WINDIR%\bad49
- from %WINDIR%\TASKMAN.EXE to %WINDIR%\bad105
- from %WINDIR%\twunk_16.exe to %WINDIR%\bad119
- from %WINDIR%\Microsoft.NET\Framework\v1.1.4322\cvtres.exe to %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad135
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad173
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad29
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad149
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad24
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad131
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad104
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\IEExec.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad11
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\cvtres.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad59
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad19
- from %WINDIR%\Microsoft.NET\Framework\v2.0.50727\CasPol.exe to %WINDIR%\Microsoft.NET\Framework\v2.0.50727\bad51
- from %WINDIR%\Microsoft.NET\Framework\v1.1.4322\jsc.exe to %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad62
- from %WINDIR%\Microsoft.NET\Framework\v1.1.4322\MigPol.exe to %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad52
- from %WINDIR%\Microsoft.NET\Framework\v1.1.4322\InstallUtil.exe to %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad46
- from %WINDIR%\Microsoft.NET\Framework\v1.1.4322\IEExec.exe to %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad22
- from %WINDIR%\Microsoft.NET\Framework\v1.1.4322\ilasm.exe to %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad32
- from %WINDIR%\Microsoft.NET\Framework\v1.1.4322\RegSvcs.exe to %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad9
- from %WINDIR%\Microsoft.NET\Framework\v1.1.4322\vbc.exe to %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad20
- from %WINDIR%\Microsoft.NET\Framework\v1.1.4322\RegAsm.exe to %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad44
- from %WINDIR%\Microsoft.NET\Framework\v1.1.4322\MigPolWin.exe to %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad139
- from %WINDIR%\Microsoft.NET\Framework\v1.1.4322\ngen.exe to %WINDIR%\Microsoft.NET\Framework\v1.1.4322\bad128
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ilasm.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad125
- from <SYSTEM32>\clipbrd.exe to <SYSTEM32>\bad135
- from <SYSTEM32>\cmd.exe to <SYSTEM32>\bad36
- from <SYSTEM32>\cliconfg.exe to <SYSTEM32>\bad75
- from <SYSTEM32>\ckcnv.exe to <SYSTEM32>\bad116
- from <SYSTEM32>\cleanmgr.exe to <SYSTEM32>\bad134
- from <SYSTEM32>\conime.exe to <SYSTEM32>\bad97
- from <SYSTEM32>\control.exe to <SYSTEM32>\bad144
- from <SYSTEM32>\compact.exe to <SYSTEM32>\bad176
- from <SYSTEM32>\cmmon32.exe to <SYSTEM32>\bad68
- from <SYSTEM32>\cmstp.exe to <SYSTEM32>\bad20
- from <SYSTEM32>\calc.exe to <SYSTEM32>\bad3
- from <SYSTEM32>\charmap.exe to <SYSTEM32>\bad139
- from <SYSTEM32>\cacls.exe to <SYSTEM32>\bad69
- from <SYSTEM32>\autolfn.exe to <SYSTEM32>\bad33
- from <SYSTEM32>\blastcln.exe to <SYSTEM32>\bad99
- from <SYSTEM32>\cipher.exe to <SYSTEM32>\bad108
- from <SYSTEM32>\cisvc.exe to <SYSTEM32>\bad138
- from <SYSTEM32>\cidaemon.exe to <SYSTEM32>\bad119
- from <SYSTEM32>\chkdsk.exe to <SYSTEM32>\bad185
- from <SYSTEM32>\chkntfs.exe to <SYSTEM32>\bad152
- from <SYSTEM32>\convert.exe to <SYSTEM32>\bad170
- from <SYSTEM32>\dpnsvr.exe to <SYSTEM32>\bad150
- from <SYSTEM32>\drwatson.exe to <SYSTEM32>\bad116
- from <SYSTEM32>\dplaysvr.exe to <SYSTEM32>\bad102
- from <SYSTEM32>\dmremote.exe to <SYSTEM32>\bad0
- from <SYSTEM32>\dosx.exe to <SYSTEM32>\bad175
- from <SYSTEM32>\dvdupgrd.exe to <SYSTEM32>\bad41
- from <SYSTEM32>\dwwin.exe to <SYSTEM32>\bad35
- from <SYSTEM32>\dvdplay.exe to <SYSTEM32>\bad199
- from <SYSTEM32>\drwtsn32.exe to <SYSTEM32>\bad31
- from <SYSTEM32>\dumprep.exe to <SYSTEM32>\bad115
- from <SYSTEM32>\dfrgfat.exe to <SYSTEM32>\bad67
- from <SYSTEM32>\dfrgntfs.exe to <SYSTEM32>\bad124
- from <SYSTEM32>\defrag.exe to <SYSTEM32>\bad138
- from <SYSTEM32>\csrss.exe to <SYSTEM32>\bad54
- from <SYSTEM32>\dcomcnfg.exe to <SYSTEM32>\bad132
- from <SYSTEM32>\dllhst3g.exe to <SYSTEM32>\bad197
- from <SYSTEM32>\dmadmin.exe to <SYSTEM32>\bad104
- from <SYSTEM32>\diskperf.exe to <SYSTEM32>\bad21
- from <SYSTEM32>\diantz.exe to <SYSTEM32>\bad8
- from <SYSTEM32>\diskpart.exe to <SYSTEM32>\bad187
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\Setup.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\bad21
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\SetupUtility.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\bad70
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\SetupUtility.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\bad8
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\WsatConfig.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad192
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\bad111
- from %WINDIR%\pchealth\helpctr\binaries\HelpCtr.exe to %WINDIR%\pchealth\helpctr\binaries\bad41
- from %WINDIR%\pchealth\helpctr\binaries\HelpHost.exe to %WINDIR%\pchealth\helpctr\binaries\bad132
- from %WINDIR%\mui\muisetup.exe to %WINDIR%\mui\bad10
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\WPF\bad157
- from %WINDIR%\msagent\agentsvr.exe to %WINDIR%\msagent\bad12
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad174
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad4
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\Microsoft.Workflow.Compiler.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad26
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad83
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\jsc.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad127
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ServiceModelReg.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad94
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad72
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\regtlibv12.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad24
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ngen.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad162
- from %WINDIR%\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe to %WINDIR%\Microsoft.NET\Framework\v4.0.30319\bad0
- from %WINDIR%\pchealth\helpctr\binaries\HelpSvc.exe to %WINDIR%\pchealth\helpctr\binaries\bad22
- from <SYSTEM32>\at.exe to <SYSTEM32>\bad34
- from <SYSTEM32>\atmadm.exe to <SYSTEM32>\bad53
- from <SYSTEM32>\asr_pfu.exe to <SYSTEM32>\bad153
- from <SYSTEM32>\asr_fmt.exe to <SYSTEM32>\bad194
- from <SYSTEM32>\asr_ldm.exe to <SYSTEM32>\bad178
- from <SYSTEM32>\autoconv.exe to <SYSTEM32>\bad57
- from <SYSTEM32>\autofmt.exe to <SYSTEM32>\bad89
- from <SYSTEM32>\autochk.exe to <SYSTEM32>\bad196
- from <SYSTEM32>\attrib.exe to <SYSTEM32>\bad136
- from <SYSTEM32>\auditusr.exe to <SYSTEM32>\bad182
- from %WINDIR%\pchealth\UploadLB\Binaries\UploadM.exe to %WINDIR%\pchealth\UploadLB\Binaries\bad194
- from <SYSTEM32>\accwiz.exe to <SYSTEM32>\bad140
- from %WINDIR%\pchealth\helpctr\binaries\notiflag.exe to %WINDIR%\pchealth\helpctr\binaries\bad2
- from %WINDIR%\pchealth\helpctr\binaries\HscUpd.exe to %WINDIR%\pchealth\helpctr\binaries\bad9
- from %WINDIR%\pchealth\helpctr\binaries\msconfig.exe to %WINDIR%\pchealth\helpctr\binaries\bad112
- from <SYSTEM32>\append.exe to <SYSTEM32>\bad6
- from <SYSTEM32>\arp.exe to <SYSTEM32>\bad17
- from <SYSTEM32>\alg.exe to <SYSTEM32>\bad183
- from <SYSTEM32>\actmovie.exe to <SYSTEM32>\bad78
- from <SYSTEM32>\ahui.exe to <SYSTEM32>\bad158
- from %PROGRAM_FILES%\Movie Maker\moviemk.exe to %PROGRAM_FILES%\Movie Maker\bad3
- from %PROGRAM_FILES%\MSN Gaming Zone\Windows\bckgzm.exe to %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad41
- from %PROGRAM_FILES%\MSN Gaming Zone\Windows\chkrzm.exe to %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad153
- from <SYSTEM32>\dllcache\helpsvc.exe.new to <SYSTEM32>\dllcache\helpsvc.exe
- from %PROGRAM_FILES%\Internet Explorer\Connection Wizard\inetwiz.exe to %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad91
- from %PROGRAM_FILES%\Internet Explorer\Connection Wizard\isignup.exe to %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad44
- from %PROGRAM_FILES%\MSN Gaming Zone\Windows\zclientm.exe to %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad125
- from %PROGRAM_FILES%\NetMeeting\cb32.exe to %PROGRAM_FILES%\NetMeeting\bad137
- from <SYSTEM32>\dllcache\hscupd.exe.new to <SYSTEM32>\dllcache\hscupd.exe
- from %PROGRAM_FILES%\MSN Gaming Zone\Windows\hrtzzm.exe to %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad118
- from %PROGRAM_FILES%\MSN Gaming Zone\Windows\rvsezm.exe to %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad174
- from %PROGRAM_FILES%\MSN Gaming Zone\Windows\shvlzm.exe to %PROGRAM_FILES%\MSN Gaming Zone\Windows\bad129
- from %CommonProgramFiles%\Microsoft Shared\Speech\sapisvr.exe to %CommonProgramFiles%\Microsoft Shared\Speech\bad38
- from <SYSTEM32>\dllcache\helpctr.exe.new to <SYSTEM32>\dllcache\helpctr.exe
- from <SYSTEM32>\dllcache\helphost.exe.new to <SYSTEM32>\dllcache\helphost.exe
- from <SYSTEM32>\dllcache\notepad.exe.new to <SYSTEM32>\dllcache\notepad.exe
- from <SYSTEM32>\dllcache\taskman.exe.new to <SYSTEM32>\dllcache\taskman.exe
- from %CommonProgramFiles%\Microsoft Shared\MSInfo\msinfo32.exe to %CommonProgramFiles%\Microsoft Shared\MSInfo\bad43
- from %PROGRAM_FILES%\Internet Explorer\Connection Wizard\icwconn2.exe to %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad144
- from %PROGRAM_FILES%\Internet Explorer\Connection Wizard\icwrmind.exe to %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad123
- from %PROGRAM_FILES%\Internet Explorer\Connection Wizard\icwtutor.exe to %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad177
- from %PROGRAM_FILES%\Internet Explorer\iedw.exe to %PROGRAM_FILES%\Internet Explorer\bad179
- from %PROGRAM_FILES%\Internet Explorer\iexplore.exe to %PROGRAM_FILES%\Internet Explorer\bad17
- from %PROGRAM_FILES%\Internet Explorer\Connection Wizard\icwconn1.exe to %PROGRAM_FILES%\Internet Explorer\Connection Wizard\bad128
- from %WINDIR%\hh.exe to %WINDIR%\bad75
- from %WINDIR%\notepad.exe to %WINDIR%\bad145
- from %WINDIR%\regedit.exe to %WINDIR%\bad146
- from %PROGRAM_FILES%\Windows NT\Accessories\wordpad.exe to %PROGRAM_FILES%\Windows NT\Accessories\bad27
- from %PROGRAM_FILES%\Windows NT\Pinball\pinball.exe to %PROGRAM_FILES%\Windows NT\Pinball\bad166
- from <SYSTEM32>\dllcache\uploadm.exe.new to <SYSTEM32>\dllcache\uploadm.exe
- from %WINDIR%\winhelp.exe to %WINDIR%\bad89
- from %WINDIR%\winhlp32.exe to %WINDIR%\bad65
- from %WINDIR%\Help\Tours\mmTour\tour.exe to %WINDIR%\Help\Tours\mmTour\bad131
- from %WINDIR%\taskman.exe to %WINDIR%\bad114
- from %WINDIR%\twunk_16.exe to %WINDIR%\bad4
- from %WINDIR%\twunk_32.exe to %WINDIR%\bad182
- from %PROGRAM_FILES%\Outlook Express\oemig50.exe to %PROGRAM_FILES%\Outlook Express\bad10
- from %PROGRAM_FILES%\Outlook Express\setup50.exe to %PROGRAM_FILES%\Outlook Express\bad154
- from %PROGRAM_FILES%\Outlook Express\wab.exe to %PROGRAM_FILES%\Outlook Express\bad26
- from %PROGRAM_FILES%\NetMeeting\conf.exe to %PROGRAM_FILES%\NetMeeting\bad39
- from %PROGRAM_FILES%\NetMeeting\wb32.exe to %PROGRAM_FILES%\NetMeeting\bad133
- from %PROGRAM_FILES%\Outlook Express\msimn.exe to %PROGRAM_FILES%\Outlook Express\bad52
- from %PROGRAM_FILES%\Windows Media Player\setup_wm.exe to %PROGRAM_FILES%\Windows Media Player\bad51
- from %PROGRAM_FILES%\Windows Media Player\wmplayer.exe to %PROGRAM_FILES%\Windows Media Player\bad180
- from %PROGRAM_FILES%\Windows NT\dialer.exe to %PROGRAM_FILES%\Windows NT\bad124
- from %PROGRAM_FILES%\Outlook Express\wabmig.exe to %PROGRAM_FILES%\Outlook Express\bad187
- from %PROGRAM_FILES%\Windows Media Player\migrate.exe to %PROGRAM_FILES%\Windows Media Player\bad163
- from %PROGRAM_FILES%\Windows Media Player\mplayer2.exe to %PROGRAM_FILES%\Windows Media Player\bad142
- from <SYSTEM32>\dllcache\pinball.exe.new to <SYSTEM32>\dllcache\pinball.exe
- from <SYSTEM32>\dllcache\iexplore.exe.new to <SYSTEM32>\dllcache\iexplore.exe
- from %PROGRAM_FILES%\MSN Gaming Zone\Windows\chkrzm.exe.new to %PROGRAM_FILES%\MSN Gaming Zone\Windows\chkrzm.exe
- from %PROGRAM_FILES%\MSN Gaming Zone\Windows\hrtzzm.exe.new to %PROGRAM_FILES%\MSN Gaming Zone\Windows\hrtzzm.exe
- from <SYSTEM32>\dllcache\msinfo32.exe.new to <SYSTEM32>\dllcache\msinfo32.exe
- from <SYSTEM32>\dllcache\iedw.exe.new to <SYSTEM32>\dllcache\iedw.exe
- from %PROGRAM_FILES%\MSN Gaming Zone\Windows\bckgzm.exe.new to %PROGRAM_FILES%\MSN Gaming Zone\Windows\bckgzm.exe
- from %PROGRAM_FILES%\MSN Gaming Zone\Windows\zclientm.exe.new to %PROGRAM_FILES%\MSN Gaming Zone\Windows\zclientm.exe
- from %PROGRAM_FILES%\NetMeeting\cb32.exe.new to %PROGRAM_FILES%\NetMeeting\cb32.exe
- from <SYSTEM32>\dllcache\icwconn2.exe.new to <SYSTEM32>\dllcache\icwconn2.exe
- from %PROGRAM_FILES%\MSN Gaming Zone\Windows\rvsezm.exe.new to %PROGRAM_FILES%\MSN Gaming Zone\Windows\rvsezm.exe
- from <SYSTEM32>\dllcache\icwconn1.exe.new to <SYSTEM32>\dllcache\icwconn1.exe
- from %PROGRAM_FILES%\MSN Gaming Zone\Windows\shvlzm.exe.new to %PROGRAM_FILES%\MSN Gaming Zone\Windows\shvlzm.exe
- from %PROGRAM_FILES%\Internet Explorer\iedw.exe.new to %PROGRAM_FILES%\Internet Explorer\iedw.exe
- from %PROGRAM_FILES%\Internet Explorer\iexplore.exe.new to %PROGRAM_FILES%\Internet Explorer\iexplore.exe
- from %PROGRAM_FILES%\Internet Explorer\Connection Wizard\icwconn1.exe.new to %PROGRAM_FILES%\Internet Explorer\Connection Wizard\icwconn1.exe
- from <Full path to virus>.exe to <Current directory>\bad36
- from %CommonProgramFiles%\Microsoft Shared\MSInfo\msinfo32.exe.new to %CommonProgramFiles%\Microsoft Shared\MSInfo\msinfo32.exe
- from %CommonProgramFiles%\Microsoft Shared\Speech\sapisvr.exe.new to %CommonProgramFiles%\Microsoft Shared\Speech\sapisvr.exe
- from %PROGRAM_FILES%\Internet Explorer\Connection Wizard\inetwiz.exe.new to %PROGRAM_FILES%\Internet Explorer\Connection Wizard\inetwiz.exe
- from %PROGRAM_FILES%\Internet Explorer\Connection Wizard\isignup.exe.new to %PROGRAM_FILES%\Internet Explorer\Connection Wizard\isignup.exe
- from %PROGRAM_FILES%\Movie Maker\moviemk.exe.new to %PROGRAM_FILES%\Movie Maker\moviemk.exe
- from %PROGRAM_FILES%\Internet Explorer\Connection Wizard\icwconn2.exe.new to %PROGRAM_FILES%\Internet Explorer\Connection Wizard\icwconn2.exe
- from %PROGRAM_FILES%\Internet Explorer\Connection Wizard\icwrmind.exe.new to %PROGRAM_FILES%\Internet Explorer\Connection Wizard\icwrmind.exe
- from %PROGRAM_FILES%\Internet Explorer\Connection Wizard\icwtutor.exe.new to %PROGRAM_FILES%\Internet Explorer\Connection Wizard\icwtutor.exe
- from %PROGRAM_FILES%\Windows NT\dialer.exe.new to %PROGRAM_FILES%\Windows NT\dialer.exe
- from <SYSTEM32>\dllcache\moviemk.exe.new to <SYSTEM32>\dllcache\moviemk.exe
- from %PROGRAM_FILES%\Windows NT\Accessories\wordpad.exe.new to %PROGRAM_FILES%\Windows NT\Accessories\wordpad.exe
- from %PROGRAM_FILES%\Windows Media Player\mplayer2.exe.new to %PROGRAM_FILES%\Windows Media Player\mplayer2.exe
- from %PROGRAM_FILES%\Windows Media Player\setup_wm.exe.new to %PROGRAM_FILES%\Windows Media Player\setup_wm.exe
- from %PROGRAM_FILES%\Windows Media Player\wmplayer.exe.new to %PROGRAM_FILES%\Windows Media Player\wmplayer.exe
- from <SYSTEM32>\dllcache\hrtzzm.exe.new to <SYSTEM32>\dllcache\hrtzzm.exe
- from <SYSTEM32>\dllcache\rvsezm.exe.new to <SYSTEM32>\dllcache\rvsezm.exe
- from <SYSTEM32>\dllcache\zclientm.exe.new to <SYSTEM32>\dllcache\zclientm.exe
- from %PROGRAM_FILES%\Windows NT\Pinball\pinball.exe.new to %PROGRAM_FILES%\Windows NT\Pinball\pinball.exe
- from <SYSTEM32>\dllcache\bckgzm.exe.new to <SYSTEM32>\dllcache\bckgzm.exe
- from <SYSTEM32>\dllcache\chkrzm.exe.new to <SYSTEM32>\dllcache\chkrzm.exe
- from <SYSTEM32>\dllcache\inetwiz.exe.new to <SYSTEM32>\dllcache\inetwiz.exe
- from %PROGRAM_FILES%\NetMeeting\wb32.exe.new to %PROGRAM_FILES%\NetMeeting\wb32.exe
- from <SYSTEM32>\dllcache\isignup.exe.new to <SYSTEM32>\dllcache\isignup.exe
- from <SYSTEM32>\dllcache\icwrmind.exe.new to <SYSTEM32>\dllcache\icwrmind.exe
- from <SYSTEM32>\dllcache\icwtutor.exe.new to <SYSTEM32>\dllcache\icwtutor.exe
- from %PROGRAM_FILES%\NetMeeting\conf.exe.new to %PROGRAM_FILES%\NetMeeting\conf.exe
- from %PROGRAM_FILES%\Outlook Express\wab.exe.new to %PROGRAM_FILES%\Outlook Express\wab.exe
- from %PROGRAM_FILES%\Outlook Express\wabmig.exe.new to %PROGRAM_FILES%\Outlook Express\wabmig.exe
- from %PROGRAM_FILES%\Windows Media Player\migrate.exe.new to %PROGRAM_FILES%\Windows Media Player\migrate.exe
- from %PROGRAM_FILES%\Outlook Express\msimn.exe.new to %PROGRAM_FILES%\Outlook Express\msimn.exe
- from %PROGRAM_FILES%\Outlook Express\oemig50.exe.new to %PROGRAM_FILES%\Outlook Express\oemig50.exe
- from %PROGRAM_FILES%\Outlook Express\setup50.exe.new to %PROGRAM_FILES%\Outlook Express\setup50.exe
- 'www.vi###192.h18.ru':80
- www.vi###192.h18.ru/1.exe
- DNS ASK www.vi###192.h18.ru