Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '1' = '"<Full path to file>"'
- <Drive name for removable media>:\correct.avi
- <Drive name for removable media>:\join.avi
- <Drive name for removable media>:\split.avi
- <Drive name for removable media>:\delete.avi
- <Drive name for removable media>:\000814251_video_01.avi
- <Drive name for removable media>:\dial.bmp
- <Drive name for removable media>:\dashborder_144.bmp
- <Drive name for removable media>:\testee.cer
- <Drive name for removable media>:\contosoroot.cer
- <Drive name for removable media>:\pmd.cer
- <Drive name for removable media>:\sdszfo.docx
- <Drive name for removable media>:\thlps_keeper_mayer_1965.docx
- <SYSTEM32>\dwm.exe
- <SYSTEM32>\taskhost.exe
- C:\readme-warning.txt
- C:\far2\plugins\editcase\readme-warning.txt
- C:\far2\plugins\emenu\readme-warning.txt
- C:\far2\plugins\farcmds\readme-warning.txt
- C:\far2\plugins\filecase\readme-warning.txt
- C:\far2\plugins\ftp\lib\readme-warning.txt
- C:\far2\plugins\ftp\readme-warning.txt
- C:\far2\plugins\compare\readme-warning.txt
- C:\far2\plugins\drawline\readme-warning.txt
- C:\far2\plugins\hlfviewer\readme-warning.txt
- C:\far2\plugins\proclist\readme-warning.txt
- C:\far2\plugins\tmppanel\readme-warning.txt
- C:\far2\pluginsdk\headers.c\readme-warning.txt
- C:\far2\pluginsdk\headers.pas\readme-warning.txt
- C:\far2\readme-warning.txt
- C:\msocache\all users\{90140000-0011-0000-1000-0000000ff1ce}-c\readme-warning.txt
- C:\far2\plugins\macroview\readme-warning.txt
- C:\far2\plugins\network\readme-warning.txt
- C:\far2\plugins\brackets\readme-warning.txt
- C:\far2\plugins\autowrap\readme-warning.txt
- C:\far2\plugins\arclite\readme-warning.txt
- D:\readme-warning.txt
- C:\far2\addons\colors\custom_highlighting\readme-warning.txt
- C:\far2\addons\colors\default_highlighting\readme-warning.txt
- C:\far2\addons\colors\readme-warning.txt
- C:\far2\addons\macros\readme-warning.txt
- C:\far2\addons\setup\readme-warning.txt
- C:\far2\addons\shell\readme-warning.txt
- %HOMEPATH%\desktop\readme-warning.txt
- C:\far2\addons\xlat\russian\readme-warning.txt
- C:\far2\addons\readme-warning.txt
- C:\far2\documentation\eng\readme-warning.txt
- C:\far2\documentation\rus\readme-warning.txt
- C:\far2\encyclopedia\tap\readme-warning.txt
- C:\far2\encyclopedia\readme-warning.txt
- C:\far2\fexcept\readme-warning.txt
- C:\far2\plugins\align\readme-warning.txt
- C:\far2\addons\xlat\readme-warning.txt
- C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\readme-warning.txt
- C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\readme-warning.txt
- '<SYSTEM32>\cmd.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\sc.exe' delete "ReportServer$OPTIMA"
- '<SYSTEM32>\sc.exe' delete "msftesql$SQLEXPRESS"
- '<SYSTEM32>\sc.exe' delete "postgresql-x64-9.4"
- '<SYSTEM32>\sc.exe' delete WRSVC
- '<SYSTEM32>\sc.exe' delete ekrn
- '<SYSTEM32>\sc.exe' delete klim6
- '<SYSTEM32>\sc.exe' delete "AVP18.0.0"
- '<SYSTEM32>\sc.exe' delete KLIF
- '<SYSTEM32>\sc.exe' delete klpd
- '<SYSTEM32>\sc.exe' delete klflt
- '<SYSTEM32>\sc.exe' delete klbackupdisk
- '<SYSTEM32>\sc.exe' delete klbackupflt
- '<SYSTEM32>\sc.exe' delete klkbdflt
- '<SYSTEM32>\sc.exe' delete klmouflt
- '<SYSTEM32>\sc.exe' delete klhk
- '<SYSTEM32>\sc.exe' delete "KSDE1.0.0"
- '<SYSTEM32>\sc.exe' delete kltap
- '<SYSTEM32>\sc.exe' delete TmFilter
- '<SYSTEM32>\sc.exe' delete TMLWCSService
- '<SYSTEM32>\sc.exe' delete tmusa
- '<SYSTEM32>\sc.exe' delete TmPreFilter
- '<SYSTEM32>\sc.exe' delete TMSmartRelayService
- '<SYSTEM32>\sc.exe' delete TMiCRCScanService
- '<SYSTEM32>\sc.exe' delete VSApiNt
- '<SYSTEM32>\sc.exe' delete TmCCSF
- '<SYSTEM32>\sc.exe' delete tmlisten
- '<SYSTEM32>\sc.exe' delete TmProxy
- '<SYSTEM32>\sc.exe' delete ntrtscan
- '<SYSTEM32>\sc.exe' delete ofcservice
- '<SYSTEM32>\sc.exe' delete "SQLAgent$OPTIMA"
- '<SYSTEM32>\vssvc.exe'
- '<SYSTEM32>\sc.exe' delete "MSSQL$OPTIMA"
- '<SYSTEM32>\sc.exe' delete "SQLAgent$WOLTERSKLUWER"
- '<SYSTEM32>\sc.exe' delete vmickvpexchange
- '<SYSTEM32>\sc.exe' delete vmicguestinterface
- '<SYSTEM32>\sc.exe' delete vmicshutdown
- '<SYSTEM32>\sc.exe' delete vmicheartbeat
- '<SYSTEM32>\sc.exe' delete vmicrdv
- '<SYSTEM32>\sc.exe' delete storflt
- '<SYSTEM32>\sc.exe' delete vmictimesync
- '<SYSTEM32>\sc.exe' delete vmicvss
- '<SYSTEM32>\sc.exe' delete MSSQLFDLauncher
- '<SYSTEM32>\sc.exe' delete MSSQLSERVER
- '<SYSTEM32>\sc.exe' delete SQLSERVERAGENT
- '<SYSTEM32>\sc.exe' delete SQLBrowser
- '<SYSTEM32>\sc.exe' delete SQLTELEMETRY
- '<SYSTEM32>\sc.exe' delete MsDtsServer130
- '<SYSTEM32>\sc.exe' delete SSISTELEMETRY130
- '<SYSTEM32>\sc.exe' delete SQLWriter
- '<SYSTEM32>\sc.exe' delete "MSSQL$VEEAMSQL2012"
- '<SYSTEM32>\sc.exe' delete "SQLAgent$VEEAMSQL2012"
- '<SYSTEM32>\sc.exe' delete MSSQL
- '<SYSTEM32>\sc.exe' delete SQLAgent
- '<SYSTEM32>\sc.exe' delete MSSQLServerADHelper100
- '<SYSTEM32>\sc.exe' delete MSSQLServerOLAPService
- '<SYSTEM32>\sc.exe' delete MsDtsServer100
- '<SYSTEM32>\sc.exe' delete ReportServer
- '<SYSTEM32>\sc.exe' delete "SQLTELEMETRY$HL"
- '<SYSTEM32>\sc.exe' delete TMBMServer
- '<SYSTEM32>\sc.exe' delete "MSSQL$PROGID"
- '<SYSTEM32>\sc.exe' delete "MSSQL$WOLTERSKLUWER"
- '<SYSTEM32>\sc.exe' delete "SQLAgent$PROGID"
- '<SYSTEM32>\sc.exe' delete "MSSQLFDLauncher$OPTIMA"
- '<SYSTEM32>\svchost.exe' -k swprv