Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\backup.exe
- hidden files
- file extensions
- %CommonProgramFiles%\Microsoft Shared\update.exe %CommonProgramFiles%\Microsoft Shared\
- C:\Far\PlugDoc\Examples\Compare\backup.exe C:\Far\PlugDoc\Examples\Compare\
- C:\Far\Addons\Tables\backup.exe C:\Far\Addons\Tables\
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\backup.exe %ALLUSERSPROFILE%\Documents\My Music\Sample Music\
- %ALLUSERSPROFILE%\Favorites\backup.exe %ALLUSERSPROFILE%\Favorites\
- %HOMEPATH%\Start Menu\Programs\Accessories\Entertainment\backup.exe %HOMEPATH%\Start Menu\Programs\Accessories\Entertainment\
- %ALLUSERSPROFILE%\Documents\My Music\My Playlists\backup.exe %ALLUSERSPROFILE%\Documents\My Music\My Playlists\
- C:\Far\PlugDoc\Examples\backup.exe C:\Far\PlugDoc\Examples\
- %ALLUSERSPROFILE%\Documents\My Music\backup.exe %ALLUSERSPROFILE%\Documents\My Music\
- %HOMEPATH%\Start Menu\Programs\Accessories\backup.exe %HOMEPATH%\Start Menu\Programs\Accessories\
- %HOMEPATH%\Start Menu\Programs\Accessories\Accessibility\backup.exe %HOMEPATH%\Start Menu\Programs\Accessories\Accessibility\
- %CommonProgramFiles%\backup.exe %CommonProgramFiles%\
- C:\Far\Addons\Shell\data.exe C:\Far\Addons\Shell\
- C:\Far\Plugins\backup.exe C:\Far\Plugins\
- C:\Far\Plugins\ascii\backup.exe C:\Far\Plugins\ascii\
- %PROGRAM_FILES%\ComPlus Applications\backup.exe %PROGRAM_FILES%\ComPlus Applications\
- C:\Far\PlugDoc\Headers.c\backup.exe C:\Far\PlugDoc\Headers.c\
- C:\Far\Addons\XLat\backup.exe C:\Far\Addons\XLat\
- C:\Far\Addons\Tables\Cyrillic\backup.exe C:\Far\Addons\Tables\Cyrillic\
- C:\Far\PlugDoc\Examples\Editor\Align\data.exe C:\Far\PlugDoc\Examples\Editor\Align\
- %ALLUSERSPROFILE%\Documents\My Pictures\backup.exe %ALLUSERSPROFILE%\Documents\My Pictures\
- %HOMEPATH%\Start Menu\Programs\Administrative Tools\backup.exe %HOMEPATH%\Start Menu\Programs\Administrative Tools\
- C:\Far\Addons\Tables\Central European\backup.exe C:\Far\Addons\Tables\Central European\
- C:\Far\PlugDoc\Examples\Editor\backup.exe C:\Far\PlugDoc\Examples\Editor\
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\backup.exe %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\
- %ALLUSERSPROFILE%\Start Menu\backup.exe %ALLUSERSPROFILE%\Start Menu\
- %CommonProgramFiles%\Microsoft Shared\DAO\backup.exe %CommonProgramFiles%\Microsoft Shared\DAO\
- %HOMEPATH%\My Documents\backup.exe %HOMEPATH%\My Documents\
- C:\Far\Addons\backup.exe C:\Far\Addons\
- %HOMEPATH%\Favorites\Links\backup.exe %HOMEPATH%\Favorites\Links\
- C:\Far\Addons\Colors\update.exe C:\Far\Addons\Colors\
- %HOMEPATH%\My Documents\Downloads\backup.exe %HOMEPATH%\My Documents\Downloads\
- C:\Far\Addons\Archivers\backup.exe C:\Far\Addons\Archivers\
- C:\Far\backup.exe C:\Far\
- %HOMEPATH%\update.exe %HOMEPATH%\
- C:\Documents and Settings\backup.exe C:\Documents and Settings\
- C:\backup.exe \
- %HOMEPATH%\Favorites\backup.exe %HOMEPATH%\Favorites\
- %HOMEPATH%\Desktop\backup.exe %HOMEPATH%\Desktop\
- %HOMEPATH%\Cookies\System Restore.exe %HOMEPATH%\Cookies\
- %HOMEPATH%\My Documents\My Music\backup.exe %HOMEPATH%\My Documents\My Music\
- %ALLUSERSPROFILE%\Documents\backup.exe %ALLUSERSPROFILE%\Documents\
- <Auxiliary element> <Auxiliary element>
- %HOMEPATH%\Start Menu\Programs\backup.exe %HOMEPATH%\Start Menu\Programs\
- %PROGRAM_FILES%\backup.exe %PROGRAM_FILES%\
- C:\Far\Addons\SetUp\backup.exe C:\Far\Addons\SetUp\
- C:\Far\PlugDoc\backup.exe C:\Far\PlugDoc\
- C:\Far\Addons\Macros\backup.exe C:\Far\Addons\Macros\
- %ALLUSERSPROFILE%\backup.exe %ALLUSERSPROFILE%\
- %HOMEPATH%\My Documents\My Pictures\backup.exe %HOMEPATH%\My Documents\My Pictures\
- C:\Far\Addons\Colors\Custom Highlighting\backup.exe C:\Far\Addons\Colors\Custom Highlighting\
- %ALLUSERSPROFILE%\Desktop\backup.exe %ALLUSERSPROFILE%\Desktop\
- %HOMEPATH%\Start Menu\backup.exe %HOMEPATH%\Start Menu\
- C:\Far\Addons\Colors\Default Highlighting\backup.exe C:\Far\Addons\Colors\Default Highlighting\
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer] 'NoFolderOptions' = '00000001'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '00000001'
- C:\Far\Addons\Tables\backup.exe
- C:\Far\PlugDoc\Examples\Compare\backup.exe
- %ALLUSERSPROFILE%\Documents\My Music\My Playlists\backup.exe
- %CommonProgramFiles%\Microsoft Shared\update.exe
- %ALLUSERSPROFILE%\Favorites\backup.exe
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\backup.exe
- %HOMEPATH%\Start Menu\Programs\Accessories\Entertainment\backup.exe
- %HOMEPATH%\Start Menu\Programs\Accessories\Accessibility\backup.exe
- %HOMEPATH%\Start Menu\Programs\Accessories\backup.exe
- %PROGRAM_FILES%\backup.exe
- C:\Far\Addons\SetUp\backup.exe
- %ALLUSERSPROFILE%\Documents\My Music\backup.exe
- %CommonProgramFiles%\backup.exe
- C:\Far\Addons\Shell\data.exe
- C:\Far\PlugDoc\Examples\backup.exe
- C:\Far\PlugDoc\Headers.c\backup.exe
- %ALLUSERSPROFILE%\Documents\My Pictures\backup.exe
- C:\Far\PlugDoc\Examples\Editor\Align\data.exe
- %PROGRAM_FILES%\ComPlus Applications\backup.exe
- %CommonProgramFiles%\MSSoap\backup.exe
- C:\Far\Addons\XLat\backup.exe
- C:\Far\Addons\Tables\Cyrillic\backup.exe
- C:\Far\Plugins\ascii\backup.exe
- C:\Far\Plugins\backup.exe
- C:\Far\Addons\Tables\Central European\backup.exe
- C:\Far\PlugDoc\Examples\Editor\backup.exe
- %CommonProgramFiles%\Microsoft Shared\DAO\backup.exe
- %ALLUSERSPROFILE%\Start Menu\backup.exe
- %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\backup.exe
- %HOMEPATH%\Start Menu\Programs\Administrative Tools\backup.exe
- %HOMEPATH%\Favorites\backup.exe
- %HOMEPATH%\Desktop\backup.exe
- %HOMEPATH%\Cookies\System Restore.exe
- C:\Far\backup.exe
- %HOMEPATH%\My Documents\backup.exe
- C:\Far\Addons\backup.exe
- %HOMEPATH%\Favorites\Links\backup.exe
- <Current directory>\%USERNAME%.zip
- <Current directory>\H1a02792
- <Current directory>\temp.zip
- <Current directory>\backup.exe
- <Current directory>\<Virus name>.dat
- %HOMEPATH%\update.exe
- C:\Documents and Settings\backup.exe
- C:\backup.exe
- C:\Far\Addons\Macros\backup.exe
- %ALLUSERSPROFILE%\Desktop\backup.exe
- %HOMEPATH%\Start Menu\backup.exe
- %HOMEPATH%\Start Menu\Programs\backup.exe
- C:\Far\PlugDoc\backup.exe
- %ALLUSERSPROFILE%\Documents\backup.exe
- <Auxiliary element>
- C:\Far\Addons\Colors\Default Highlighting\backup.exe
- C:\Far\Addons\Colors\update.exe
- %HOMEPATH%\My Documents\Downloads\backup.exe
- C:\Far\Addons\Archivers\backup.exe
- %HOMEPATH%\My Documents\My Music\backup.exe
- %ALLUSERSPROFILE%\backup.exe
- %HOMEPATH%\My Documents\My Pictures\backup.exe
- C:\Far\Addons\Colors\Custom Highlighting\backup.exe
- <Current directory>\%USERNAME%.zip
- <Current directory>\temp.zip
- <Current directory>\<Virus name>.dat
- <Current directory>\temp.zip
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'ExploreWClass' WindowName: ''
- ClassName: 'CabinetWClass' WindowName: ''