Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Onelog Notifier' = '%ProgramFiles%\ITS\Onelog\Client\LoginApplication.exe'
- %WINDIR%\Tasks\User_Feed_Synchronization-{C46B4597-5937-41A5-8F6A-83271671E360}.job
- %WINDIR%\Tasks\GoogleUpdateTaskMachineUA.job
- [<HKLM>\SYSTEM\ControlSet001\Services\ITS Onelog Client] 'ImagePath' = '"%ProgramFiles%\ITS\Onelog\Client\ClientSessionService.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\ITS Onelog Client] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\PrismXL] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\PrismXL] 'ImagePath' = '%CommonProgramFiles%\New Boundary\PrismXL\PRISMXL.SYS'
- '%CommonProgramFiles%\New Boundary\PrismXL\PRISMXL.SYS'
- %ProgramFiles%\ITS\Onelog\Client\LoginApplication.exe
- %ProgramFiles%\ITS\Onelog\Client\Logging.dll
- %ProgramFiles%\ITS\Onelog\Client\Microsoft.mshtml.dll
- %ProgramFiles%\ITS\Onelog\Client\OnelogClientHelper\Interop.SHDocVw.dll
- %ProgramFiles%\ITS\Onelog\Client\OnelogClientHelper\ForceToolbarDisplay.dll
- %ProgramFiles%\ITS\Onelog\Client\LocalDBSetup.exe
- %ProgramFiles%\ITS\Onelog\Client\ITS.Onelog.Client.BrowserClientSchema.dll
- %ProgramFiles%\ITS\Onelog\Client\ITS.LanguageResource.dll
- %ProgramFiles%\ITS\Onelog\Client\ITS.Onelog.Client.BrowserClientSchema.XmlSerializers.dll
- %ProgramFiles%\ITS\Onelog\Client\ITS.Onelog.Common.ComSchema.dll
- %ProgramFiles%\ITS\Onelog\Client\ITS.Onelog.Client.LanguageResource.dll
- %WINDIR%\Installer\fd8a7.msi
- %ProgramFiles%\Symantec\Symantec Endpoint Protection\SerState.dat.bak
- %WINDIR%\Installer\{360D82F2-ED0E-4987-81D3-A473436CE22A}\Onelog_I_0001.ico
- %WINDIR%\PICTAKER.LOG
- %ALLUSERSPROFILE%\Start Menu\Programs\Onelog\Onelog.lnk
- %ProgramFiles%\Symantec\Symantec Endpoint Protection\SerState.dat
- %ProgramFiles%\ITS\Onelog\Client\RegisterAssemblies.exe
- %ProgramFiles%\ITS\Onelog\Client\OnelogW.exe
- %ProgramFiles%\ITS\Onelog\Client\RegistrySettings.dll
- %ProgramFiles%\ITS\Onelog\Client\System.Data.SQLite.dll
- %ProgramFiles%\ITS\Onelog\Client\Request.xsd
- %ProgramFiles%\ITS\Onelog\Client\Interop.SHDocVw.dll
- %ALLUSERSPROFILE%\Application Data\ITS\Onelog\Client\X8.db
- %ALLUSERSPROFILE%\Application Data\ITS\Onelog\Client\Response.xsd
- %ProgramFiles%\Altiris\Altiris Agent\AeXAMDiscovery.txt
- %ProgramFiles%\Altiris\Altiris Agent\AeXProcessList.txt
- %ProgramFiles%\Altiris\Altiris Agent\AeXAMInventory.txt
- %ALLUSERSPROFILE%\Application Data\ITS\Onelog\Client\Languages\ITS_Languages.xml
- %CommonProgramFiles%\New Boundary\PrismXL\PRISMXL.SYS
- %TEMP%\PRISMXL.SYS
- %ALLUSERSPROFILE%\Application Data\Prism Pack\UNAPPLY\<Virus name>.PWR
- %ALLUSERSPROFILE%\Application Data\ITS\Onelog\Client\DesktopAppSchema.xsd
- %ALLUSERSPROFILE%\Application Data\Prism Pack\UNAPPLY\<Virus name> 1.PWR
- %ProgramFiles%\ITS\Onelog\Client\DBLayer.dll
- %ProgramFiles%\ITS\Onelog\Client\ComSchema.xsd
- %ProgramFiles%\ITS\Onelog\Client\DesktopApp.dll
- %ProgramFiles%\ITS\Onelog\Client\IEToolbar.dll
- %ProgramFiles%\ITS\Onelog\Client\FormTemplate.dll
- %ProgramFiles%\ITS\Onelog\Client\ClientSessionServiceDAL.dll
- %ProgramFiles%\Diskeeper Corporation\Diskeeper\PerfData{8FFED8D6-B5B8-11D9-B52D-806D6172696F}.xml
- %ProgramFiles%\Altiris\Altiris Agent\Logs\agent.log
- %ProgramFiles%\Diskeeper Corporation\Diskeeper\Volume{8FFED8D6-B5B8-11D9-B52D-806D6172696F}.dat
- %ProgramFiles%\ITS\Onelog\Client\ClientSessionService.exe
- %ProgramFiles%\ITS\Onelog\Client\BandObjectLib.dll
- %WINDIR%\Tasks\User_Feed_Synchronization-{C46B4597-5937-41A5-8F6A-83271671E360}.job
- %ALLUSERSPROFILE%\Application Data\Prism Pack\UNAPPLY\<Virus name> 1.PWR
- %ALLUSERSPROFILE%\Application Data\Prism Pack\UNAPPLY\<Virus name>.PWR
- %TEMP%\PRISMXL.SYS
- ClassName: 'Shell_TrayWnd' WindowName: ''