Technical Information
- Command Prompt (CMD)
- Windows Task Manager (Taskmgr)
- Registry Editor (RegEdit)
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoRun' = '00000001'
- %HOMEPATH%\desktop\000814251_video_01.avi
- %HOMEPATH%\desktop\weeklysheet1215.doc
- %HOMEPATH%\desktop\toolbar.bmp
- %HOMEPATH%\desktop\tileimage.bmp
- %HOMEPATH%\desktop\testee.cer
- %HOMEPATH%\desktop\join.avi
- %HOMEPATH%\desktop\ituneshelpunavailable.htm
- %HOMEPATH%\desktop\iisstart.html
- %HOMEPATH%\desktop\iisstart.htm
- %HOMEPATH%\desktop\howto-index.html
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %HOMEPATH%\desktop\hanni_umami_chapter.doc
- %HOMEPATH%\desktop\fi51.doc
- %HOMEPATH%\desktop\dialmap.bmp
- %HOMEPATH%\desktop\delete.avi
- %HOMEPATH%\desktop\correct.avi
- %HOMEPATH%\desktop\browse.htm
- %HOMEPATH%\desktop\aoc_saq_d_v3_merchant.docx
- %HOMEPATH%\desktop\adadsi.html
- %HOMEPATH%\desktop\about.html
- %HOMEPATH%\desktop\about.htm
- %HOMEPATH%\desktop\file_p_00000000_1371597592.docx
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %HOMEPATH%\desktop\check_this_before_you_do_anything1.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything74.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything73.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything72.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything71.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything70.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything69.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything68.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything67.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything66.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything65.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything64.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything63.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything62.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything61.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything60.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything59.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything58.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything57.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything56.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything55.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything54.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything52.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything53.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything75.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything76.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything98.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything97.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything96.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything95.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything94.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything93.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything92.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything91.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything90.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything89.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything87.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything37.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything86.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything85.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything84.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything83.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything82.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything81.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything80.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything79.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything78.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything77.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything51.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything50.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything49.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything21.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything20.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything19.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything18.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything17.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything16.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything15.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything14.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything13.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything12.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything11.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything10.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything9.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything8.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything7.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything6.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything5.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything4.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything3.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything2.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything23.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything24.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything22.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything25.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything48.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything26.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything47.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything46.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything45.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything44.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything43.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything42.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything41.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything40.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything39.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything88.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything99.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything36.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything35.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything34.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything33.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything32.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything31.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything30.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything29.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything28.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything27.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything38.txt
- %HOMEPATH%\desktop\check_this_before_you_do_anything100.txt
- %HOMEPATH%\desktop\000814251_video_01.avi
- %LOCALAPPDATA%\adobe\acrobat\dc\adobesysfnt15.lst
- %LOCALAPPDATA%\adobe\acrobat\dc\adobecmapfnt15.lst
- C:\users\public\recorded tv\sample media\win7_scenic-demoshort_raw.wtv
- C:\users\public\music\sample music\sleep away.mp3
- C:\users\public\music\sample music\maid with the flaxen hair.mp3
- C:\users\public\music\sample music\kalimba.mp3
- C:\users\public\libraries\recordedtv.library-ms
- C:\users\public\desktop\winamp.lnk
- C:\users\public\desktop\steam.lnk
- C:\users\public\desktop\opera.lnk
- C:\users\public\desktop\mozilla thunderbird.lnk
- C:\users\public\desktop\mozilla firefox.lnk
- C:\users\public\desktop\mirc.lnk
- C:\users\public\desktop\google chrome.lnk
- C:\users\public\desktop\acrobat reader dc.lnk
- %HOMEPATH%\desktop\total commander 64 bit.lnk
- %HOMEPATH%\desktop\telegram.lnk
- %HOMEPATH%\desktop\qip 2012.lnk
- %HOMEPATH%\desktop\mail.ru agent.lnk
- %HOMEPATH%\desktop\icq.lnk
- %HOMEPATH%\desktop\delete.avi
- %HOMEPATH%\desktop\correct.avi
- %HOMEPATH%\desktop\browse.htm
- %HOMEPATH%\desktop\aoc_saq_d_v3_merchant.docx
- %HOMEPATH%\desktop\adadsi.html
- %HOMEPATH%\desktop\about.html
- %HOMEPATH%\desktop\about.htm
- %LOCALAPPDATA%\adobe\acrobat\dc\cache\acrofnt15.lst
- %LOCALAPPDATA%\adobe\acrobat\dc\shareddataevents
- 'di##ord.com':443
- 'di##ord.com':443
- DNS ASK di##ord.com