Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'verif-8746' = '%APPDATA%\amcxdfi.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'verif-8746' = '%APPDATA%\amcxdfi.exe'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\HELP_RECOVER_instructions+prs.png
- '%APPDATA%\amcxdfi.exe'
- '<SYSTEM32>\cmd.exe' /c DEL <Full path to virus>
- <SYSTEM32>\cmd.exe
- ecmd.exe
- C:\Documents and Settings\Default User\Local Settings\History\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Local Settings\History\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Local Settings\History\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Local Settings\Temp\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Local Settings\Temp\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Local Settings\History\History.IE5\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Local Settings\Application Data\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Local Settings\History\History.IE5\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Local Settings\History\History.IE5\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Local Settings\Temp\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Cookies\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Cookies\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Favorites\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Favorites\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Favorites\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Cookies\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Application Data\Microsoft\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Application Data\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Application Data\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Application Data\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Media Player\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Media Player\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Media Player\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\9.0\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\9.0\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\9.0\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\SendTo\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\SendTo\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Startup\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Start Menu\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Start Menu\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Templates\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Templates\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Templates\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Start Menu\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Start Menu\Programs\Startup\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Startup\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Start Menu\Programs\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Start Menu\Programs\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Local Settings\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Local Settings\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\My Documents\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Local Settings\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\My Documents\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Recent\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\PrintHood\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Recent\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\SendTo\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Recent\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\PrintHood\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\NetHood\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\My Documents\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\NetHood\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\PrintHood\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\NetHood\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Documents\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Documents\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Documents\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\DRM\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\DRM\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Documents\My Videos\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Documents\My Pictures\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Documents\My Pictures\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Documents\My Pictures\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Documents\My Videos\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Documents\My Videos\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\DRM\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Favorites\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Favorites\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Favorites\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Documents\My Music\My Playlists\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Documents\My Music\My Playlists\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Documents\My Music\My Playlists\HELP_RECOVER_instructions+prs.png
- %HOMEPATH%\My Documents\recover_file_jgjwganus.txt
- %APPDATA%\amcxdfi.exe
- <Current directory>\HELP_RECOVER_instructions+prs.png
- <Current directory>\HELP_RECOVER_instructions+prs.html
- <Current directory>\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\0338E140\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Documents\My Music\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Documents\My Music\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Documents\My Music\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\0338E140\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\0338E140\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\Media Player\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\Media Player\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\Media Player\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs\HELP_RECOVER_instructions+prs.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs\HELP_RECOVER_instructions+prs.png
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs\HELP_RECOVER_instructions+prs.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Games\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Games\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Templates\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Start Menu\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Templates\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Templates\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Start Menu\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Start Menu\Programs\Games\HELP_RECOVER_instructions+prs.html
- %ALLUSERSPROFILE%\Start Menu\Programs\HELP_RECOVER_instructions+prs.txt
- %ALLUSERSPROFILE%\Start Menu\HELP_RECOVER_instructions+prs.png
- %ALLUSERSPROFILE%\Start Menu\Programs\HELP_RECOVER_instructions+prs.html
- 'du#####zelerimuzesi.com':80
- 'ed###rpetas.com':80
- 'so####nstrument.org':80
- 'bd#####n.desjardins.fr':80
- 'gr###-pro.com':80
- 'ii##drd.com':80
- http://du#####zelerimuzesi.com/templates/yoo_bigeasy/styles/turquoise/mzsys.php
- http://ed###rpetas.com/modules/mod_fxprev/libraries/mzsys.php
- http://so####nstrument.org/templates/protostar/less/mzsys.php
- http://bd#####n.desjardins.fr/js/openlayers/theme/default/img/mzsys.php
- http://gr###-pro.com/templates/beez3/html/com_newsfeeds/categories/mzsys.php
- http://ii##drd.com/tmp/mzsys.php
- DNS ASK du#####zelerimuzesi.com
- DNS ASK ed###rpetas.com
- DNS ASK so####nstrument.org
- DNS ASK bd#####n.desjardins.fr
- DNS ASK gr###-pro.com
- DNS ASK ii##drd.com
- ClassName: 'Indicator' WindowName: ''