Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'SecurityCenter' = '%APPDATA%\Desktop Security 2010\securitycenter.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Desktop Security 2010' = '"%APPDATA%\Desktop Security 2010\Desktop Security 2010.exe" /STARTUP'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'oqn9upuvumo0' = '<Full path to file>'
- Windows Update
- Windows Security Center
- '%APPDATA%\Desktop Security 2010\securitycenter.exe'
- '<SYSTEM32>\cmd.exe' /C dir "%APPDATA%\Desktop Security 2010"
- '<SYSTEM32>\cmd.exe' /C dir "%APPDATA%"
- '%TEMP%\_2.tmpac7d.exe' -p"21:00" -y -o"%APPDATA%\Desktop Security 2010"
- '%APPDATA%\Desktop Security 2010\Desktop Security 2010.exe'
- %TEMP%\hiphop.exe
- %TEMP%\gpupz2a.exe
- %TEMP%\dkfjd93.exe
- %TEMP%\fe.exe
- %TEMP%\timem.exe
- %TEMP%\cunifuc.exe
- %TEMP%\ddhelp.exe
- %TEMP%\hvipws9.exe
- %TEMP%\kilslmd.exex
- %TEMP%\alerfa.exe
- %TEMP%\kjdh_gf_jjdhgd.exe
- %TEMP%\hodeme.exe
- %TEMP%\lorsk.exe
- %TEMP%\snowif.exe
- %TEMP%\hhbboll_2.exe
- %TEMP%\eephilpe.exe
- %TEMP%\pswwg3c.exe
- %TEMP%\test.exe
- %TEMP%\r0life.exe
- %TEMP%\al3erfa3.exe
- %TEMP%\ddoll3342.exe
- %TEMP%\kock.exe
- %TEMP%\hardwh.exe
- %TEMP%\format.exe
- %TEMP%\safe.exe
- %TEMP%\ae0965a7157cd.exe
- %TEMP%\02c9c3c35bdx5.exe
- %TEMP%\56493.exe
- %TEMP%\wergfq.exe
- %TEMP%\qwklrvjhqlkj.exe
- %TEMP%\rtfme.exe
- %TEMP%\wqefqw7e.exe
- %TEMP%\rator.exe
- %TEMP%\jofcdks.exe
- %HOMEPATH%\Start Menu\Programs\Desktop Security 2010\Desktop Security 2010.lnk
- %HOMEPATH%\Start Menu\Programs\Desktop Security 2010\Activate Desktop Security 2010.lnk
- %APPDATA%\Desktop Security 2010\securityhelper.exe
- %HOMEPATH%\Start Menu\Programs\Desktop Security 2010.lnk
- %APPDATA%\Microsoft\Internet Explorer\Quick Launch\Desktop Security 2010.lnk
- %TEMP%\a3.tmp
- %HOMEPATH%\Start Menu\Programs\Desktop Security 2010\How to Activate Desktop Security 2010.lnk
- %HOMEPATH%\Start Menu\Programs\Desktop Security 2010\Help Desktop Security 2010.lnk
- %APPDATA%\Desktop Security 2010\taskmgr.dll
- %APPDATA%\Desktop Security 2010\Desktop Security 2010.exe
- %APPDATA%\Desktop Security 2010\securitycenter.exe
- %TEMP%\a1.tmp
- %TEMP%\_2.tmpac7d.exe
- %APPDATA%\Desktop Security 2010\msvcp71.dll
- %APPDATA%\Desktop Security 2010\msvcr71.dll
- %APPDATA%\Desktop Security 2010\mfc71.dll
- %APPDATA%\Desktop Security 2010\MFC71ENU.DLL
- %TEMP%\gedx_ae09.exe
- %TEMP%\wrcud12.exe
- %TEMP%\17dkf.exe
- %TEMP%\jdhellwo3.exe
- %TEMP%\sycre.exe
- %TEMP%\backd-efq.exe
- %TEMP%\eelnvd13.exe
- %TEMP%\ppddfcfux.exxe
- %TEMP%\dd10x10.exe
- %TEMP%\winlogoff.exe
- %TEMP%\472a10e2ebxd9.exe
- %TEMP%\a4.tmp
- %TEMP%\wrfwe_di.exe
- %TEMP%\dc_3.exe
- %TEMP%\qwedvor.exe
- %TEMP%\ds7hw.exe
- %TEMP%\lols.exe
- %TEMP%\a3.tmp
- %TEMP%\a4.tmp
- %TEMP%\a1.tmp
- %TEMP%\_2.tmpac7d.exe
- 'localhost':1041
- DNS ASK ht###work.com
- DNS ASK 14##655477
- DNS ASK 14##655447
- ClassName: '' WindowName: 'Desktop Security 2010'
- ClassName: 'Shell_TrayWnd' WindowName: ''