Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'FxHrkpLpWn' = '<Full path to file>'
- <Drive name for removable media>:\t79h0gj-readme.txt
- firefox.exe
- %HOMEPATH%\desktop\000814251_video_01.avi
- %HOMEPATH%\desktop\64bit_notes.htm
- %HOMEPATH%\desktop\advice_process.htm
- %HOMEPATH%\desktop\browse.htm
- %HOMEPATH%\desktop\coffee.bmp
- %HOMEPATH%\desktop\dashborder_192.bmp
- %HOMEPATH%\desktop\delete.avi
- %HOMEPATH%\desktop\hanni_umami_chapter.doc
- %HOMEPATH%\desktop\iisstart.htm
- %HOMEPATH%\desktop\ituneshelpunavailable.htm
- %HOMEPATH%\desktop\join.avi
- %HOMEPATH%\desktop\testcertificate.cer
- %HOMEPATH%\desktop\tree_view.htm
- %HOMEPATH%\desktop\tree_view.html
- <Current directory>\dbg_log.txt
- %HOMEPATH%\contacts\t79h0gj-readme.txt
- C:\users\public\videos\t79h0gj-readme.txt
- C:\users\public\recorded tv\t79h0gj-readme.txt
- C:\users\public\pictures\t79h0gj-readme.txt
- C:\users\public\music\t79h0gj-readme.txt
- C:\users\public\libraries\t79h0gj-readme.txt
- C:\users\public\favorites\t79h0gj-readme.txt
- C:\users\public\downloads\t79h0gj-readme.txt
- C:\users\public\documents\t79h0gj-readme.txt
- C:\users\public\desktop\t79h0gj-readme.txt
- C:\users\default\videos\t79h0gj-readme.txt
- C:\users\default\saved games\t79h0gj-readme.txt
- C:\users\default\pictures\t79h0gj-readme.txt
- C:\users\default\music\t79h0gj-readme.txt
- C:\users\default\links\t79h0gj-readme.txt
- C:\users\default\favorites\t79h0gj-readme.txt
- C:\users\default\downloads\t79h0gj-readme.txt
- C:\users\default\documents\t79h0gj-readme.txt
- C:\users\default\desktop\t79h0gj-readme.txt
- %HOMEPATH%\desktop\t79h0gj-readme.txt
- %HOMEPATH%\documents\t79h0gj-readme.txt
- %HOMEPATH%\downloads\t79h0gj-readme.txt
- %HOMEPATH%\favorites\t79h0gj-readme.txt
- %HOMEPATH%\favorites\msn websites\t79h0gj-readme.txt
- %HOMEPATH%\favorites\microsoft websites\t79h0gj-readme.txt
- %HOMEPATH%\favorites\links for united states\t79h0gj-readme.txt
- %HOMEPATH%\favorites\links\t79h0gj-readme.txt
- C:\users\public\videos\sample videos\t79h0gj-readme.txt
- C:\users\public\recorded tv\sample media\t79h0gj-readme.txt
- C:\users\public\pictures\sample pictures\t79h0gj-readme.txt
- C:\users\public\music\sample music\t79h0gj-readme.txt
- %ProgramFiles%\microsoft sql server compact edition\v3.5\desktop\t79h0gj-readme.txt
- C:\far2\addons\xlat\russian\t79h0gj-readme.txt
- C:\far2\plugins\ftp\lib\t79h0gj-readme.txt
- C:\far2\addons\colors\default_highlighting\t79h0gj-readme.txt
- C:\far2\addons\colors\custom_highlighting\t79h0gj-readme.txt
- %HOMEPATH%\voip\t79h0gj-readme.txt
- %HOMEPATH%\videos\t79h0gj-readme.txt
- %HOMEPATH%\searches\t79h0gj-readme.txt
- %HOMEPATH%\saved games\t79h0gj-readme.txt
- %HOMEPATH%\pictures\t79h0gj-readme.txt
- %HOMEPATH%\music\t79h0gj-readme.txt
- %HOMEPATH%\links\t79h0gj-readme.txt
- %HOMEPATH%\favorites\windows live\t79h0gj-readme.txt
- %ProgramFiles%\microsoft sql server compact edition\v3.5\t79h0gj-readme.txt
- C:\far2\pluginsdk\headers.pas\t79h0gj-readme.txt
- C:\far2\pluginsdk\headers.c\t79h0gj-readme.txt
- C:\users\public\t79h0gj-readme.txt
- C:\users\default\t79h0gj-readme.txt
- C:\totalcmd\language\t79h0gj-readme.txt
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\t79h0gj-readme.txt
- %ProgramFiles%\microsoft sql server compact edition\t79h0gj-readme.txt
- C:\far2\pluginsdk\t79h0gj-readme.txt
- C:\far2\plugins\t79h0gj-readme.txt
- C:\far2\fexcept\t79h0gj-readme.txt
- C:\far2\encyclopedia\t79h0gj-readme.txt
- C:\far2\documentation\t79h0gj-readme.txt
- C:\far2\addons\t79h0gj-readme.txt
- C:\users\t79h0gj-readme.txt
- C:\totalcmd\t79h0gj-readme.txt
- <Current directory>\t79h0gj-readme.txt
- C:\recovery\t79h0gj-readme.txt
- %ProgramFiles(x86)%\t79h0gj-readme.txt
- %ProgramFiles%\t79h0gj-readme.txt
- C:\far2\t79h0gj-readme.txt
- C:\t79h0gj-readme.txt
- %HOMEPATH%\t79h0gj-readme.txt
- C:\far2\addons\colors\t79h0gj-readme.txt
- C:\far2\addons\macros\t79h0gj-readme.txt
- C:\far2\addons\setup\t79h0gj-readme.txt
- C:\far2\plugins\proclist\t79h0gj-readme.txt
- C:\far2\plugins\network\t79h0gj-readme.txt
- C:\far2\plugins\macroview\t79h0gj-readme.txt
- C:\far2\plugins\hlfviewer\t79h0gj-readme.txt
- C:\far2\plugins\ftp\t79h0gj-readme.txt
- C:\far2\plugins\filecase\t79h0gj-readme.txt
- C:\far2\plugins\farcmds\t79h0gj-readme.txt
- C:\far2\plugins\emenu\t79h0gj-readme.txt
- C:\far2\plugins\editcase\t79h0gj-readme.txt
- C:\far2\plugins\compare\t79h0gj-readme.txt
- C:\far2\plugins\drawline\t79h0gj-readme.txt
- C:\far2\plugins\brackets\t79h0gj-readme.txt
- C:\far2\plugins\autowrap\t79h0gj-readme.txt
- C:\far2\plugins\arclite\t79h0gj-readme.txt
- C:\far2\plugins\align\t79h0gj-readme.txt
- C:\far2\encyclopedia\tap\t79h0gj-readme.txt
- C:\far2\documentation\rus\t79h0gj-readme.txt
- C:\far2\documentation\eng\t79h0gj-readme.txt
- C:\far2\addons\xlat\t79h0gj-readme.txt
- C:\far2\addons\shell\t79h0gj-readme.txt
- C:\far2\plugins\tmppanel\t79h0gj-readme.txt
- D:\t79h0gj-readme.txt
- '<SYSTEM32>\vssvc.exe'
- '<SYSTEM32>\svchost.exe' -k swprv