Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'WindowsUpdateCheck' = '<Full path to file>'
- <Drive name for removable media>:\how to back your files.exe
- <Drive name for removable media>:\cveuropeo.doc
- <Drive name for removable media>:\applicantform_en.doc
- <Drive name for removable media>:\february_catalogue__2015.doc
- <Drive name for removable media>:\contoso.cer
- <Drive name for removable media>:\pmd.cer
- <Drive name for removable media>:\contosoroot.cer
- <Drive name for removable media>:\contosoroot_1.cer
- <Drive name for removable media>:\contoso_1.cer
- <Drive name for removable media>:\sdkfailsafeemulator.cer
- <Drive name for removable media>:\dashborder_192.bmp
- <Drive name for removable media>:\dashborder_144.bmp
- <Drive name for removable media>:\dashborder_96.bmp
- <Drive name for removable media>:\tileimage.bmp
- <Drive name for removable media>:\coffee.bmp
- <Drive name for removable media>:\toolbar.bmp
- <Drive name for removable media>:\default.bmp
- <Drive name for removable media>:\dialmap.bmp
- <Drive name for removable media>:\archer.avi
- <Drive name for removable media>:\000814251_video_01.avi
- <Drive name for removable media>:\delete.avi
- <Drive name for removable media>:\correct.avi
- <Drive name for removable media>:\508softwareandos.doc
- <Drive name for removable media>:\fi51.doc
- %PROGRAMDATA%\how to back your files.exe
- %ProgramFiles%\bdsurvey\how to back your files.exe
- %ProgramFiles%\bdswitch\how to back your files.exe
- %ProgramFiles%\bdwizreg\how to back your files.exe
- %ProgramFiles%\blackd\how to back your files.exe
- %ProgramFiles%\blackice\how to back your files.exe
- %ProgramFiles%\blindman\how to back your files.exe
- %ProgramFiles%\btini\how to back your files.exe
- %ProgramFiles%\bdsubmit\how to back your files.exe
- %ProgramFiles%\bdsubmitwiz\how to back your files.exe
- %ProgramFiles%\btinint\how to back your files.exe
- %ProgramFiles%\cavapp\how to back your files.exe
- %ProgramFiles%\cavasm\how to back your files.exe
- %ProgramFiles%\cavaud\how to back your files.exe
- %ProgramFiles%\cavemsrv\how to back your files.exe
- %ProgramFiles%\cavmr\how to back your files.exe
- %ProgramFiles%\cavmud\how to back your files.exe
- %ProgramFiles%\cavoar\how to back your files.exe
- %ProgramFiles%\cabalmain\how to back your files.exe
- %ProgramFiles%\cafix\how to back your files.exe
- %ProgramFiles%\bdss\how to back your files.exe
- %ProgramFiles%\bdoesrv\how to back your files.exe
- %ProgramFiles%\bdnews\how to back your files.exe
- %ProgramFiles%\avgupden\how to back your files.exe
- %ProgramFiles%\avgupsvc\how to back your files.exe
- %ProgramFiles%\avgvv\how to back your files.exe
- %ProgramFiles%\avgw\how to back your files.exe
- %ProgramFiles%\avgwizfw\how to back your files.exe
- %ProgramFiles%\avinitnt\how to back your files.exe
- %ProgramFiles%\avkserv\how to back your files.exe
- %ProgramFiles%\avkservice\how to back your files.exe
- %ProgramFiles%\avgscan\how to back your files.exe
- %ProgramFiles%\avkwctl\how to back your files.exe
- %ProgramFiles%\avpcc\how to back your files.exe
- %ProgramFiles%\avpm\how to back your files.exe
- %ProgramFiles%\avscan\how to back your files.exe
- %ProgramFiles%\avsynmgr\how to back your files.exe
- %ProgramFiles%\b2\how to back your files.exe
- %ProgramFiles%\backweb-4476822\how to back your files.exe
- %ProgramFiles%\bdagent\how to back your files.exe
- %ProgramFiles%\bdmcon\how to back your files.exe
- %ProgramFiles%\avnotify\how to back your files.exe
- %ProgramFiles%\cavq\how to back your files.exe
- %ProgramFiles%\cavse\how to back your files.exe
- %ProgramFiles%\dnf\how to back your files.exe
- %ProgramFiles%\cavsn\how to back your files.exe
- %ProgramFiles%\copyx64\how to back your files.exe
- %ProgramFiles%\courier\how to back your files.exe
- %ProgramFiles%\cpd\how to back your files.exe
- %ProgramFiles%\csendto\how to back your files.exe
- %ProgramFiles%\cssexc\how to back your files.exe
- %ProgramFiles%\custinstall\how to back your files.exe
- %ProgramFiles%\custsetup\how to back your files.exe
- %ProgramFiles%\cmgrdian\how to back your files.exe
- %CommonProgramFiles%\how to back your files.exe
- %ProgramFiles%\cuteftp\how to back your files.exe
- %ProgramFiles%\defensewall\how to back your files.exe
- %ProgramFiles%\defwatch\how to back your files.exe
- %ProgramFiles%\dekaron\how to back your files.exe
- %ProgramFiles%\digsby\how to back your files.exe
- %ProgramFiles%\digsby-app\how to back your files.exe
- %ProgramFiles%\directftp\how to back your files.exe
- %ProgramFiles%\dislite\how to back your files.exe
- %ProgramFiles%\dbconvert\how to back your files.exe
- %ProgramFiles%\dbtool\how to back your files.exe
- %ProgramFiles%\cmain\how to back your files.exe
- %ProgramFiles%\clrcche\how to back your files.exe
- %ProgramFiles%\clisvc\how to back your files.exe
- %ProgramFiles%\cavsubmit\how to back your files.exe
- %ProgramFiles%\cavumas\how to back your files.exe
- %ProgramFiles%\cavuserupd\how to back your files.exe
- %ProgramFiles%\cavvl\how to back your files.exe
- %ProgramFiles%\ccapp\how to back your files.exe
- %ProgramFiles%\ccevtmgr\how to back your files.exe
- %ProgramFiles%\ccleaner\how to back your files.exe
- %ProgramFiles%\ccproxy\how to back your files.exe
- %ProgramFiles%\cavsub\how to back your files.exe
- %ProgramFiles%\ccsetmgr\how to back your files.exe
- %ProgramFiles%\chrome\how to back your files.exe
- %ProgramFiles%\clamscan\how to back your files.exe
- %ProgramFiles%\clamtray\how to back your files.exe
- %ProgramFiles%\clamwin\how to back your files.exe
- %ProgramFiles%\claw95\how to back your files.exe
- %ProgramFiles%\claw95cf\how to back your files.exe
- %ProgramFiles%\cleaner\how to back your files.exe
- %ProgramFiles%\cleaner3\how to back your files.exe
- %ProgramFiles%\cemrep\how to back your files.exe
- %ProgramFiles%\avgrssvc\how to back your files.exe
- %ProgramFiles%\cavscons\how to back your files.exe
- %ProgramFiles%\avgnpsvc\how to back your files.exe
- %ProgramFiles%\almon\how to back your files.exe
- %ProgramFiles%\a2cmd\how to back your files.exe
- %ProgramFiles%\a2guard\how to back your files.exe
- %ProgramFiles%\a2hijackfree\how to back your files.exe
- %ProgramFiles%\a2scan\how to back your files.exe
- %ProgramFiles%\a2service\how to back your files.exe
- %ProgramFiles%\a2start\how to back your files.exe
- %ProgramFiles%\a2upd\how to back your files.exe
- C:\msocache\all users\how to back your files.exe
- %ProgramFiles%\360tray\how to back your files.exe
- %ProgramFiles%\a2wizard\how to back your files.exe
- %ProgramFiles%\ackwin32\how to back your files.exe
- %ProgramFiles%\admunch\how to back your files.exe
- %ProgramFiles%\agb5\how to back your files.exe
- %ProgramFiles%\ageofconan\how to back your files.exe
- %ProgramFiles%\ahnsd\how to back your files.exe
- %ProgramFiles%\aim6\how to back your files.exe
- %ProgramFiles%\aimpro\how to back your files.exe
- %ProgramFiles%\aavshield\how to back your files.exe
- %ProgramFiles%\about\how to back your files.exe
- C:\far2\pluginsdk\how to back your files.exe
- C:\far2\plugins\how to back your files.exe
- C:\far2\fexcept\how to back your files.exe
- D:\how to back your files.exe
- C:\how to back your files.exe
- <Current directory>\how to back your files.exe
- C:\documents and settings\how to back your files.exe
- z:\how to back your files.exe
- C:\far2\how to back your files.exe
- C:\msocache\how to back your files.exe
- %ProgramFiles%\how to back your files.exe
- <Current directory>\ids.txt
- %ProgramFiles(x86)%\how to back your files.exe
- C:\totalcmd\how to back your files.exe
- C:\documents and settings\default\how to back your files.exe
- C:\documents and settings\desktop.ini.globeimposter-delta865qqz
- C:\documents and settings\public\how to back your files.exe
- C:\documents and settings\user\how to back your files.exe
- C:\far2\addons\how to back your files.exe
- C:\far2\documentation\how to back your files.exe
- C:\far2\encyclopedia\how to back your files.exe
- C:\recovery\how to back your files.exe
- %ProgramFiles%\airdefense\how to back your files.exe
- %ProgramFiles%\alsvc\how to back your files.exe
- %ProgramFiles%\avginet\how to back your files.exe
- %ProgramFiles%\amon\how to back your files.exe
- %ProgramFiles%\ash_updatemediator\how to back your files.exe
- %ProgramFiles%\aswregsvr\how to back your files.exe
- %ProgramFiles%\aswupdsv\how to back your files.exe
- %ProgramFiles%\autodown\how to back your files.exe
- %ProgramFiles%\autostartexplorer\how to back your files.exe
- %ProgramFiles%\autotrace\how to back your files.exe
- %ProgramFiles%\avadmin\how to back your files.exe
- %ProgramFiles%\ashupd\how to back your files.exe
- %ProgramFiles%\ashwebsv\how to back your files.exe
- %ProgramFiles%\avcenter\how to back your files.exe
- %ProgramFiles%\avconfig\how to back your files.exe
- %ProgramFiles%\avconsol\how to back your files.exe
- %ProgramFiles%\avgamsvr\how to back your files.exe
- %ProgramFiles%\avgcc\how to back your files.exe
- %ProgramFiles%\avgdiag\how to back your files.exe
- %ProgramFiles%\avgemc\how to back your files.exe
- %ProgramFiles%\avgfwsrv\how to back your files.exe
- %ProgramFiles%\avciman\how to back your files.exe
- %ProgramFiles%\avcmd\how to back your files.exe
- %ProgramFiles%\ashskpck\how to back your files.exe
- %ProgramFiles%\ashskpcc\how to back your files.exe
- %ProgramFiles%\ashsimpl\how to back your files.exe
- %ProgramFiles%\anti-trojan\how to back your files.exe
- %ProgramFiles%\antivirus\how to back your files.exe
- %ProgramFiles%\aoltbserver\how to back your files.exe
- %ProgramFiles%\armor2net\how to back your files.exe
- %ProgramFiles%\armorsurf\how to back your files.exe
- %ProgramFiles%\ash\how to back your files.exe
- %ProgramFiles%\ashavast\how to back your files.exe
- %ProgramFiles%\ashavsrv\how to back your files.exe
- %ProgramFiles%\amsn\how to back your files.exe
- %ProgramFiles%\ashchest\how to back your files.exe
- %ProgramFiles%\ashdug\how to back your files.exe
- %ProgramFiles%\ashenhcd\how to back your files.exe
- %ProgramFiles%\ashlogv\how to back your files.exe
- %ProgramFiles%\ashmaisv\how to back your files.exe
- %ProgramFiles%\ashpopwz\how to back your files.exe
- %ProgramFiles%\ashquick\how to back your files.exe
- %ProgramFiles%\ashserv\how to back your files.exe
- %ProgramFiles%\ashsimp2\how to back your files.exe
- %ProgramFiles%\ashdisp\how to back your files.exe
- %ProgramFiles%\avgnpdln\how to back your files.exe
- %ProgramFiles%\dpatrolq\how to back your files.exe
- from %ProgramFiles%\desktop.ini to %ProgramFiles%\desktop.ini.globeimposter-delta865qqz
- from %ProgramFiles(x86)%\desktop.ini to %ProgramFiles(x86)%\desktop.ini.globeimposter-delta865qqz
- '%WINDIR%\syswow64\werfault.exe' -u -p 2884 -s 268' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c @echo off vssadmin delete shadows /all /quiet sc config browser sc config browser start=enabled sc stop vss sc config vss start=disabled sc stop MongoDB sc config MongoDB start=disabl...