SystemSecurity
SystemSecurity
Found:
2008-12-23
Known system changes:
Created Files
- %Desktop%System Security.lnk
- %Desktop%System Security.lnk
- %Temp%izohore.bmp
- %Desktop%System Security..lnk
- %CommonDesktop%System Security..lnk
Created Folders
- %StartMenu%Programs\System Security
- %StartMenu%Program\System Security
- %StartMenu%Programs\System Security
- %ApplicationData%13645134
- %ApplicationData%13645734
Registry Entries
- Key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\vmscsi\Type
- Value:
- Data:
- Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Value: SystemSecurity
- Data: "C:\Documents and Settings\%userprofile%\Desktop\SystemSecurity.exe"
- Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Value: 314277577
- Data: "C:\Documents and Settings\All Users\Application Data\120573386\314277577.exe"
- Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Value: 359F5809-00B8-4455-A73A-9EA62A51101B
- Data: "C:\Documents and Settings\All Users\Application Data\477274F.exe"
- Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Value: 359F5809-00B8-4455-A73A-9EA62A51101B
- Data: "C:\Documents and Settings\All Users\Application Data\3A76A1EF.exe"
- Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Value: 433591806
- Data: "C:\Documents and Settings\All Users\Application Data\1361987034\433591806.exe"
- Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Value: 1409743529
- Data: "C:\Documents and Settings\All Users\Application Data\1558838974\1409743529.exe"
- Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Value: 1146867637
- Data: "C:\Documents and Settings\All Users\Application Data\18507711\1146867637.exe"
- Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Value: 359F5809-00B8-4455-A73A-9EA62A51101B
- Data: "C:\Documents and Settings\All Users\Application Data\3BE74167.exe"
- Key: HKEY_LOCAL_MACHINE\SOFTWARE\11161974
- Value:
- Data:
- Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Value: 11161974
- Data: C:\Documents and Settings\All Users\Application Data\11161974\11161974.exe
- Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Value: 61181969
- Data: C:\Documents and Settings\All Users\Application Data\61181969\61181969.exe
- Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Value: 91171966
- Data: C:\Documents and Settings\All Users\Application Data\91171966\91171966.exe
- Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SystemSecurity2009
- Value:
- Data:
- Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Value: 13461474
- Data: C:\Documents and Settings\All Users\Application Data\13461474\13461474.exe
- Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Value: 13645134
- Data: C:\Documents and Settings\All Users\Application Data\13645134\13645134.exe
- Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Value: 13645734
- Data: C:\Documents and Settings\All Users\Application Data\13645734\13645734.exe