Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'zsevice-455' = '%APPDATA%\vkgnuhe45.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'zsevice-34' = '%APPDATA%\vkgnuhe45.exe'
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Startup\help_recover_instructions+qlf.txt
- '%APPDATA%\vkgnuhe45.exe'
- '<SYSTEM32>\cmd.exe' /c DEL <Full path to virus>
- <SYSTEM32>\cmd.exe
- ecmd.exe
- C:\Documents and Settings\Default User\Local Settings\History\History.IE5\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Local Settings\History\History.IE5\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Local Settings\History\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Local Settings\History\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Local Settings\Temp\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Local Settings\Temp\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Application Data\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Cookies\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Cookies\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Application Data\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Favorites\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\9.0\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Windows Media\9.0\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Favorites\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Media Player\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Media Player\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Recent\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\SendTo\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\SendTo\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Start Menu\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Start Menu\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Start Menu\Programs\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Start Menu\Programs\Startup\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Start Menu\Programs\Startup\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Local Settings\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Local Settings\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\PrintHood\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\PrintHood\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Recent\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\NetHood\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\My Documents\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\My Documents\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\NetHood\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Documents\My Videos\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Documents\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Documents\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Documents\My Videos\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Documents\My Pictures\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Documents\My Pictures\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\DRM\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\DRM\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Favorites\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Favorites\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Documents\My Music\My Playlists\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Documents\My Music\My Playlists\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\help_recover_instructions+qlf.txt
- <Current directory>\help_recover_instructions+qlf.html
- %APPDATA%\vkgnuhe45.exe
- %HOMEPATH%\My Documents\recover_file_aixsbjsvn.txt
- <Current directory>\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Documents\My Music\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Documents\My Music\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\0338E140\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\0338E140\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\Media Player\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\Media Player\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs\help_recover_instructions+qlf.txt
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs\help_recover_instructions+qlf.html
- C:\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Start Menu\Programs\Games\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Start Menu\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Templates\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Templates\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Start Menu\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\Games\help_recover_instructions+qlf.html
- %ALLUSERSPROFILE%\Start Menu\Programs\help_recover_instructions+qlf.txt
- %ALLUSERSPROFILE%\Start Menu\Programs\help_recover_instructions+qlf.html
- 'tr###hung.net':80
- 'fl#####epublishing.com':80
- 'bi###arice.net':80
- 'su####-group.com':80
- 'ip.#yk.nu':80
- 'to######heneedyandaid.org':80
- 'th##at.org':80
- http://ip.#yk.nu/
- http://tr###hung.net/banhang/shop/upload/image/cache/catalog/demo/mssys.php
- http://fl#####epublishing.com/administrator/components/com_sef/libs/seostats/src/ext/mssys.php
- http://bi###arice.net/mssys.php
- http://to######heneedyandaid.org/administrator/components/com_users/views/notes/tmpl/mssys.php
- http://th##at.org/mssys.php
- http://su####-group.com/administrator/components/com_admin/views/help/tmpl/mssys.php
- DNS ASK tr###hung.net
- DNS ASK fl#####epublishing.com
- DNS ASK bi###arice.net
- DNS ASK su####-group.com
- DNS ASK ip.#yk.nu
- DNS ASK to######heneedyandaid.org
- DNS ASK th##at.org
- ClassName: 'Indicator' WindowName: ''