VirusRescue
VirusRescue
Found:
2007-02-26
Known system changes:
Created Files
- %Desktop%\virusrescue.lnk
- %StartMenu%\virusrescue
- %ApplicationData%\microsoft\internet explorer\quick launch\virusrescue
Created Folders
- %ProgramFiles%\virusrescue
- %StartupPrograms%\virusrescue
Registry Entries
- Key: HKEY_CLASSES_ROOT\appid\{53a8703f-53bf-4c44-8daf-fa254a1e1b8c}
- Value:
- Data:
- Key: HKEY_CLASSES_ROOT\appid\{cf79dab6-0afe-4678-856d-44574d91915c}
- Value:
- Data:
- Key: HKEY_CLASSES_ROOT\clsid\{598ca4d5-6870-47f0-b513-e3efba809b22}
- Value:
- Data:
- Key: HKEY_CLASSES_ROOT\clsid\{753d7ded-2454-44a3-959d-dc3700fc6b6e}
- Value:
- Data:
- Key: HKEY_CLASSES_ROOT\clsid\{cf79dab6-0afe-4678-856d-44574d91915c}
- Value:
- Data:
- Key: HKEY_CLASSES_ROOT\interface\{598ca4d5-6870-47f0-b513-e3efba809b22}
- Value:
- Data:
- Key: HKEY_CLASSES_ROOT\interface\{679b00b5-0783-4de4-a478-7227fdd50825}
- Value:
- Data:
- Key: HKEY_CLASSES_ROOT\typelib\{2e88f662-2027-421d-9874-f3dbc2207bab}
- Value:
- Data:
- Key: HKEY_CLASSES_ROOT\typelib\{c7df0578-d732-4bfb-a65b-89c1ccea01cc}
- Value:
- Data:
- Key: HKEY_CLASSES_ROOT\*\shellex\contextmenuhandlers\vrshlext
- Value: (default)
- Data:
- Key: HKEY_CLASSES_ROOT\appid\vrext.dll
- Value: appid
- Data:
- Key: HKEY_CLASSES_ROOT\folder\shellex\contextmenuhandlers\vrshlext
- Value: (default)
- Data:
- Key: HKEY_CLASSES_ROOT\vrext.vrshlext
- Value: (default)
- Data:
- Key: HKEY_CLASSES_ROOT\vrext.vrshlext.1
- Value: (default)
- Data:
- Key: HKEY_CLASSES_ROOT\clsid\{f80db5a5-a885-7370-4983-841f62a80af2}
- Value:
- Data:
- Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\virusrescue.exe
- Value:
- Data:
- Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\virusrescue
- Value:
- Data:
- Key: HKEY_LOCAL_MACHINE\software\virusrescue
- Value:
- Data:
- Key: HKEY_LOCAL_MACHINE\system\controlset001\services\vrsvc
- Value:
- Data:
- Key: HKEY_LOCAL_MACHINE\system\currentcontrolset\services\vrsvc
- Value:
- Data:
- Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
- Value: virusrescue
- Data: