Worm.Win32.Dorkbot_8c5cc6b88b
Trojan.Win32.Generic!BT (VIPRE), mzpefinder_pcap_file.YR, WormDorkbot.YR, GenericUDPFlooder.YR, GenericIRCBot.YR, GenericMSNWorm.YR, GenericSYNFlooder.YR, GenericDNSBlocker.YR, GenericAutorunWorm.YR, BackdoorIRC.YR, Rbot.YR, GenericInjector.YR, BankerGeneric.YR, GenericUSBInfector.YR, GenericProxy.YR, GenericPhysicalDrive0.YR (Lavasoft MAS)
Behaviour: Banker, Trojan, Backdoor, Flooder, Worm, WormAutorun, IRCBot, MSNWorm, DNSBlocker, UDPFlooder, SYNFlooder, Trojan-Proxy, USBInfector
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
MD5: 8c5cc6b88b98ec7f3d12f124065cc568
SHA1: 7b77b595b4ae0aeac3e85d8a8c3efa3a38eaf9dc
SHA256: f60bf1510863a531273af815f727ad3edd200733e2af14db2623cfb1a309fc60
SSDeep: 24576:nRmJkcoQricOIQxiZY1ia9e3RehqgybLWc4JdysO86:MJZoQrbTFZY1ia9e3ReYgyH
Size: 1104390 bytes
File type: EXE
Platform: WIN32
Entropy: Not Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2012-01-29 23:32:28
Summary:
Worm. A program that is primarily replicating on networks or removable drives.
Payload
| Behaviour | Description |
|---|---|
| WormAutorun | A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Worm's file once a user opens a drive's folder in Windows Explorer. |
| IRCBot | A bot can communicate with command and control servers via IRC channel. |
| MSNWorm | A worm can spread its copies through the MSN Messanger. |
| DNSBlocker | A program can block designated DNS servers for making it difficult for users to locate specific domains or web sites on the Internet. |
| UDPFlooder | This program can make a UDP flood. A UDP flood attack is a denial-of-service attack using the User Datagram Protocol (UDP). It can be initiated by sending a large number of UDP packets to random ports on a remote host. |
| SYNFlooder | This program can make a SYN flood. It is a form of denial-of-service attack in which an attacker sends a succession of SYN requests to a target's system in an attempt to consume enough server resources to make the system unresponsive to legitimate traffic. |
| Trojan-Proxy | This program can launch a proxy server (SOCKS4) on a designated TCP port. |
| USBInfector | A program can register a device notification with the help of RegisterDeviceNotification. So it is notified when a USB device is plugged and then the worm copies itself to the USB device plugged into the affected computer. |
Process activity
The Worm creates the following process(es):
nircmd.exe:852
%original file name%.exe:1972
%original file name%.exe:1728
attrib.exe:1796
WScript.exe:260
WScript.exe:1516
3.exe:1672
sys.exe:320
LVXEZ.exe:1364
LVXEZ.exe:1972
win.exe:1684
XYEOD.exe:1552
XYEOD.exe:1624
cmiinna.exe:488
reg.exe:1616
RegSvcs.exe:288
RegSvcs.exe:1704
The Worm injects its code into the following process(es):
system.exe:1772
cmiinna.exe:448
File activity
The process %original file name%.exe:1972 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%System%\cmiinna.exe (7433 bytes)
The process %original file name%.exe:1728 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\res.ico2 (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut1.tmp (1249 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\res.ico (601 bytes)
The Worm deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\aut1.tmp (0 bytes)
The process 3.exe:1672 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\PDHXK\98976.WQN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\A53015.HCG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\66052.UQN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\58570.ZXP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\94286.RAG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\11273.SXY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\30597.NSV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Z74759.ITI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\33114.GAW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\C53524.VUP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\69663.KDA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\X26000.OZH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\31623.RYI (5 bytes)
%Documents and Settings%\%current user%\PDHXK\70951.GAO (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Y32910.XBX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Z55518.RBI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I87902.PST (6 bytes)
%Documents and Settings%\%current user%\PDHXK\V46283.PON (6 bytes)
%Documents and Settings%\%current user%\PDHXK\A81405.CIP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\28811.WGX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\84552.APV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\2787.FYF (4 bytes)
%Documents and Settings%\%current user%\PDHXK\Q14241.BMV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Q83039.FCH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\6751.MBV (4 bytes)
%Documents and Settings%\%current user%\PDHXK\97584.GVB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\G15595.LMC (6 bytes)
%Documents and Settings%\%current user%\PDHXK\41115.UCP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\U74667.ZPU (6 bytes)
%Documents and Settings%\%current user%\PDHXK\U8772.BOT (5 bytes)
%Documents and Settings%\%current user%\PDHXK\50533.VFS (5 bytes)
%Documents and Settings%\%current user%\PDHXK\F82629.SSD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\X83389.YYB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\42423.GJU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\K73965.NGX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\J6344.JQV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\12812.DOI (5 bytes)
%Documents and Settings%\%current user%\PDHXK\91260.ZQG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\J65413.CER (6 bytes)
%Documents and Settings%\%current user%\PDHXK\4202.XIB (4 bytes)
%Documents and Settings%\%current user%\PDHXK\O5325.PLX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\R47143.QGN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\X23747.AOK (6 bytes)
%Documents and Settings%\%current user%\PDHXK\G2950.QSY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\8024.CSX (4 bytes)
%Documents and Settings%\%current user%\PDHXK\17971.QUC (5 bytes)
%Documents and Settings%\%current user%\PDHXK\V73898.YAA (6 bytes)
%Documents and Settings%\%current user%\PDHXK\25530.LEN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\R63852.CIR (6 bytes)
%Documents and Settings%\%current user%\PDHXK\56384.WJG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\O27771.YTT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\30956.UBA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Q63525.GVI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\50246.IMG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\R29694.COX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\J27545.EAL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H77391.ZSP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\78934.WHB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\15771.JUG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\L64772.IHZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H93522.KLO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I31246.YWL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\41046.ZWW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\79947.UBM (5 bytes)
%Documents and Settings%\%current user%\PDHXK\N9391.OEI (5 bytes)
%Documents and Settings%\%current user%\PDHXK\R30690.UAV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M4544.JVR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\52159.ACS (5 bytes)
%Documents and Settings%\%current user%\PDHXK\E84811.BDE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\37675.VUC (5 bytes)
%Documents and Settings%\%current user%\PDHXK\W2490.GWU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\T64920.HUG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\11867.OSD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\B5101.ZYB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\55551.RAV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\49374.CPZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\24838.NDZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\34257.XOJ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\8172.FCS (4 bytes)
%Documents and Settings%\%current user%\PDHXK\54187.ONL (5 bytes)
%Documents and Settings%\%current user%\PDHXK\58279.ZQW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\23652.URG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\P99489.PIM (6 bytes)
%Documents and Settings%\%current user%\PDHXK\S66136.JDO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\98938.JVU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\V88437.FSF (6 bytes)
%Documents and Settings%\%current user%\PDHXK\X69277.VZV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\24516.JFE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\D1624.HSN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\J88609.OSG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M40203.PKZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\29475.FHS (5 bytes)
%Documents and Settings%\%current user%\PDHXK\H99809.NTG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\L66933.GKR (6 bytes)
%Documents and Settings%\%current user%\PDHXK\42968.RJE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\V23336.ARD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\C23787.CUI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\X95029.ZJY (6 bytes)
%Documents and Settings%\%current user%\PDHXK\V68633.RHW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\59137.VFP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\X89527.CKV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\88099.PFB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\T91035.WMH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\O33246.QEQ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\R56975.UFF (6 bytes)
%Documents and Settings%\%current user%\PDHXK\N84051.HRX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\E95741.INZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\14963.VWA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\V14676.ESK (6 bytes)
%Documents and Settings%\%current user%\PDHXK\8621.QAO (4 bytes)
%Documents and Settings%\%current user%\PDHXK\9003.QOA (4 bytes)
%Documents and Settings%\%current user%\PDHXK\81324.SXR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\67225.NNN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Y70175.SYW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\E17176.UZK (6 bytes)
%Documents and Settings%\%current user%\PDHXK\T15509.SSK (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Z64407.WUB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M65558.TQW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\D90135.RJB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\G21109.MVZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I53335.OGR (6 bytes)
%Documents and Settings%\%current user%\PDHXK\25861.TSE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\42129.FMF (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Z28509.VUY (6 bytes)
%Documents and Settings%\%current user%\PDHXK\88122.EME (5 bytes)
%Documents and Settings%\%current user%\PDHXK\L49473.QZO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\D68161.ADV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\E23609.JZN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\96292.QTQ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\32138.TTI (5 bytes)
%Documents and Settings%\%current user%\PDHXK\21172.BRV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\T77764.LPL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\46877.QMQ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\24188.OJT (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Q15297.SRL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\43493.KEZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\N92159.HZH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\87241.OED (5 bytes)
%Documents and Settings%\%current user%\PDHXK\2764.WSV (4 bytes)
%Documents and Settings%\%current user%\PDHXK\L88596.QPU (6 bytes)
%Documents and Settings%\%current user%\PDHXK\90752.UTE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\R53376.ECM (6 bytes)
%Documents and Settings%\%current user%\PDHXK\90970.GCH (5 bytes)
%Documents and Settings%\%current user%\PDHXK\99519.LBX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\P44365.VXT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H44512.VQS (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Q46513.SKV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\4243.SBW (4 bytes)
%Documents and Settings%\%current user%\PDHXK\98628.MXY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\X23071.MUD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\J47864.VHP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H37745.LZP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\21910.XYG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\19368.HKX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\70708.BFU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\K16580.EGB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Q61955.QTC (6 bytes)
%Documents and Settings%\%current user%\PDHXK\8406.EYZ (4 bytes)
%Documents and Settings%\%current user%\PDHXK\60574.TEF (5 bytes)
%Documents and Settings%\%current user%\PDHXK\I6470.CWO (5 bytes)
%Documents and Settings%\%current user%\PDHXK\W85667.CQL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H64010.LXE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\59842.JVZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\LKFFH (1 bytes)
%Documents and Settings%\%current user%\PDHXK\94169.FKW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\B64636.HRI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Q9582.MEZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\14899.GSY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\65951.SCZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\W31856.SOY (6 bytes)
%Documents and Settings%\%current user%\PDHXK\A37320.YDD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\67970.DOI (5 bytes)
%Documents and Settings%\%current user%\PDHXK\I54673.CTW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H32716.WBO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\7282.TTQ (4 bytes)
%Documents and Settings%\%current user%\PDHXK\V52004.EER (6 bytes)
%Documents and Settings%\%current user%\PDHXK\45644.RUH (5 bytes)
%Documents and Settings%\%current user%\PDHXK\94065.BIT (5 bytes)
%Documents and Settings%\%current user%\PDHXK\91698.PYY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\19816.CEP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\1867.DNT (4 bytes)
%Documents and Settings%\%current user%\PDHXK\98117.QAV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\74959.KCA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\S21338.WRA (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H68793.YKY (6 bytes)
%Documents and Settings%\%current user%\PDHXK\C98450.AWZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\59066.WUG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\28060.NVB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\53782.YXP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\P96461.WHW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\S40871.MWE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\22859.PPW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\98908.IFT (5 bytes)
%Documents and Settings%\%current user%\PDHXK\77100.AMO (5 bytes)
%Documents and Settings%\%current user%\PDHXK\5332.CBT (4 bytes)
%Documents and Settings%\%current user%\PDHXK\5508.TMO (4 bytes)
%Documents and Settings%\%current user%\PDHXK\68834.DIK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\O64506.VWB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\14570.YAD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\X33054.WGG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\68485.SMP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\D48995.ZQY (6 bytes)
%Documents and Settings%\%current user%\PDHXK\S73760.EIE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\28914.BQR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\4974.WBG (4 bytes)
%Documents and Settings%\%current user%\PDHXK\80254.XLW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\V23483.WKB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H75257.WKU (6 bytes)
%Documents and Settings%\%current user%\PDHXK\S56575.PLE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\U18160.IIX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\51955.STE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\6325.KUS (4 bytes)
%Documents and Settings%\%current user%\PDHXK\85366.IGK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\V8309.YQN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\54178.PAT (5 bytes)
%Documents and Settings%\%current user%\PDHXK\85934.AIE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\A51645.TLF (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I76508.GQV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M82917.HKI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I52318.OES (6 bytes)
%Documents and Settings%\%current user%\PDHXK\F86790.RSH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\T1433.LYX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\I31118.IWP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\70825.AYV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\36739.ICP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\O84005.YMT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H69665.VUW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\28017.TIB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\H89480.WMP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\3732.MGB (4 bytes)
%Documents and Settings%\%current user%\PDHXK\A37911.ZZV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\19063.UIG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\F43661.ZDB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\35009.XOB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\S14141.GCE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\U77187.NLE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\13141.CEB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\W1272.XNK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\X20639.KUT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\13197.XFA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\J26437.RXF (6 bytes)
%Documents and Settings%\%current user%\PDHXK\C2221.FIZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Y79054.PNG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I1002.PDK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\C11382.AES (6 bytes)
%Documents and Settings%\%current user%\PDHXK\L93355.KSN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Y40359.EDW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\62480.AGT (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Y36078.MSO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\1022.UCX (4 bytes)
%Documents and Settings%\%current user%\PDHXK\C14318.ZZJ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\57252.EYP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\36090.PDZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\47652.BMT (5 bytes)
%Documents and Settings%\%current user%\PDHXK\F19186.JKW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\E77314.RXN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\30514.TRC (5 bytes)
%Documents and Settings%\%current user%\PDHXK\42118.HPN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\V19789.MMS (6 bytes)
%Documents and Settings%\%current user%\PDHXK\99333.LPG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\R11282.GII (6 bytes)
%Documents and Settings%\%current user%\PDHXK\P51766.GAU (6 bytes)
%Documents and Settings%\%current user%\PDHXK\X86555.VSQ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\16378.EKV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\A72346.VWM (6 bytes)
%Documents and Settings%\%current user%\PDHXK\92768.OMN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\27966.WRH (5 bytes)
%Documents and Settings%\%current user%\PDHXK\62640.SOZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\50495.EXC (5 bytes)
%Documents and Settings%\%current user%\PDHXK\77641.WGO (5 bytes)
%Documents and Settings%\%current user%\PDHXK\C17905.MHX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\57027.ZLA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\5005.KLY (4 bytes)
%Documents and Settings%\%current user%\PDHXK\N68892.VHC (6 bytes)
%Documents and Settings%\%current user%\PDHXK\28385.ZZV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\I65393.MJL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\21236.ZXN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\H83107.GTO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\A52499.JRO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\20933.ILO (5 bytes)
%Documents and Settings%\%current user%\PDHXK\5439.ATL (4 bytes)
%Documents and Settings%\%current user%\PDHXK\Q13117.RRO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Q68098.NKU (6 bytes)
%Documents and Settings%\%current user%\PDHXK\J58280.JMD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M8435.WJA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\T51208.XTR (6 bytes)
%Documents and Settings%\%current user%\PDHXK\6380.GRO (4 bytes)
%Documents and Settings%\%current user%\PDHXK\61737.YFD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\91875.CVO (5 bytes)
%Documents and Settings%\%current user%\PDHXK\2808.CUW (4 bytes)
%Documents and Settings%\%current user%\PDHXK\25856.WSQ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\72642.RDY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\W41612.HXO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M22717.RKQ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\5718.RPQ (4 bytes)
%Documents and Settings%\%current user%\PDHXK\X46455.MLJ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\V22423.OEZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\D48725.DNI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\13284.TMB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\25319.KLE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\71285.BZJ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\90512.TVW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\79312.IDY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\25372.BSD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\2277.AQN (4 bytes)
%Documents and Settings%\%current user%\PDHXK\3629.IGH (4 bytes)
%Documents and Settings%\%current user%\PDHXK\3483.PNE (4 bytes)
%Documents and Settings%\%current user%\PDHXK\81615.RMI (5 bytes)
%Documents and Settings%\%current user%\PDHXK\C93607.EEQ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\19869.EJK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\D82706.LVX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\L42732.PFL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Q16359.CKM (6 bytes)
%Documents and Settings%\%current user%\PDHXK\1672.OSE (4 bytes)
%Documents and Settings%\%current user%\PDHXK\T50740.KOZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\T20295.YPH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M90387.TKN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\99805.INN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\G11594.JHB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\3419.ERL (4 bytes)
%Documents and Settings%\%current user%\PDHXK\L4174.HET (5 bytes)
%Documents and Settings%\%current user%\PDHXK\X96121.RZU (6 bytes)
%Documents and Settings%\%current user%\PDHXK\97331.DYB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\92132.NXW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\32535.VGL (5 bytes)
%Documents and Settings%\%current user%\PDHXK\87966.RSE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\62312.WQD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\J51457.BAI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\15719.SSR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\W60771.OOO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\X15958.ZXT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I9077.QSD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Y96865.FLM (6 bytes)
%Documents and Settings%\%current user%\PDHXK\68829.SLG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\81181.EXU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\W90779.VGN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\95704.XAH (5 bytes)
%Documents and Settings%\%current user%\PDHXK\G7240.NIL (5 bytes)
%Documents and Settings%\%current user%\PDHXK\75184.XQX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\48862.KWM (5 bytes)
%Documents and Settings%\%current user%\PDHXK\27848.EOJ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\X62570.GDN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I72264.LOS (6 bytes)
%Documents and Settings%\%current user%\PDHXK\54874.UWP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\M11494.UUG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\20636.ZMV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\E46588.UGO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Y80118.MIS (6 bytes)
%Documents and Settings%\%current user%\PDHXK\14809.WDD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\37648.MTI (5 bytes)
%Documents and Settings%\%current user%\PDHXK\2393.YOG (4 bytes)
%Documents and Settings%\%current user%\PDHXK\settings.ini (126 bytes)
%Documents and Settings%\%current user%\PDHXK\V9477.OXG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\U37276.NCN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\U79349.DAA (6 bytes)
%Documents and Settings%\%current user%\PDHXK\E38039.LOM (6 bytes)
%Documents and Settings%\%current user%\PDHXK\35475.WTU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\84396.CZW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\49177.KZF (5 bytes)
%Documents and Settings%\%current user%\PDHXK\82976.UYP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\34815.LZL (5 bytes)
%Documents and Settings%\%current user%\PDHXK\18145.BSV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Q52408.IKX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\50700.IVW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\L46066.ZPF (6 bytes)
%Documents and Settings%\%current user%\PDHXK\S82991.OFD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\G56014.NAO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\V74709.AYX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\51872.QAJ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\43069.BCK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\I90944.VJI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\44214.BPV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\I28552.LXB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\48227.SAB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\14354.KGS (5 bytes)
%Documents and Settings%\%current user%\PDHXK\45968.DMC (5 bytes)
%Documents and Settings%\%current user%\PDHXK\L23509.KGO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\87373.SXH (5 bytes)
%Documents and Settings%\%current user%\PDHXK\S22282.UUZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\9360.MVI (4 bytes)
%Documents and Settings%\%current user%\PDHXK\V39035.GAN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I73342.DIF (6 bytes)
%Documents and Settings%\%current user%\PDHXK\19634.GSA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\97756.ZEZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\N17223.DYH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H67618.YHS (6 bytes)
%Documents and Settings%\%current user%\PDHXK\90058.LBI (5 bytes)
%Documents and Settings%\%current user%\PDHXK\C36452.PTW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\B39607.LIZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M58996.XHK (6 bytes)
%Documents and Settings%\%current user%\PDHXK\18942.JUN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Y85358.SWP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\E96581.FHE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\38779.ANY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\21499.WSC (5 bytes)
%Documents and Settings%\%current user%\PDHXK\394269.NTC (15021 bytes)
%Documents and Settings%\%current user%\PDHXK\54908.JXX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\P82281.GNF (6 bytes)
%Documents and Settings%\%current user%\PDHXK\75899.GYM (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Z86165.HAG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\P36889.ZAY (6 bytes)
%Documents and Settings%\%current user%\PDHXK\98181.VOM (5 bytes)
%Documents and Settings%\%current user%\PDHXK\58749.AKY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Y93235.UBD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\40815.CWR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\18469.ZRS (5 bytes)
%Documents and Settings%\%current user%\PDHXK\13913.HXU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\G24089.PQI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\A52737.MEK (6 bytes)
%Documents and Settings%\%current user%\PDHXK\78952.HBK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\51285.QDP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\81959.ZEY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\60434.MUV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\94081.NDH (5 bytes)
%Documents and Settings%\%current user%\PDHXK\C41000.LPG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\601051.dat (601 bytes)
%Documents and Settings%\%current user%\PDHXK\27243.XJV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\88722.HOR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\73845.KSU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Q85848.OSJ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\53583.LBK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\82545.SVS (5 bytes)
%Documents and Settings%\%current user%\PDHXK\72919.XVE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\winrar.vbs (56 bytes)
%Documents and Settings%\%current user%\PDHXK\J39695.ZJL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\N61910.HNM (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Q5973.YPD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\64274.ZLU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\T28695.DDB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\V55812.BQE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\66936.KAG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\B75478.JJH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\76947.FRD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\A6247.IMZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\28449.BBV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\75376.RSK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\47145.JPL (5 bytes)
%Documents and Settings%\%current user%\PDHXK\13415.UYD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\16382.CWM (5 bytes)
%Documents and Settings%\%current user%\PDHXK\E18341.MMB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\88707.QDK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\46252.CHR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\78832.UGW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\98604.ZQP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\C14653.WND (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I79990.BLB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\57671.ZFC (5 bytes)
%Documents and Settings%\%current user%\PDHXK\M86746.ICL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M21251.JQV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\97704.DZR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\86255.WPD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Y74669.HQQ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\3684.JWJ (4 bytes)
%Documents and Settings%\%current user%\PDHXK\977916.dat (28 bytes)
%Documents and Settings%\%current user%\PDHXK\47313.CFQ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\A57318.CDA (6 bytes)
%Documents and Settings%\%current user%\PDHXK\N58880.IXT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M8084.TTN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\G41521.ZTD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\XYEOD.exe (15361 bytes)
%Documents and Settings%\%current user%\PDHXK\89549.KDD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\6030.XBW (4 bytes)
%Documents and Settings%\%current user%\PDHXK\24122.TMJ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\16719.REQ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\M95797.TAA (6 bytes)
%Documents and Settings%\%current user%\PDHXK\29231.QZP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\78540.SLX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\N67230.TUJ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\31990.BPK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\D46030.SNO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Z5841.WKY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\62161.PHQ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\29494.XAD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\T74912.SNE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Y68851.DVR (6 bytes)
%Documents and Settings%\%current user%\PDHXK\26358.RRO (5 bytes)
%Documents and Settings%\%current user%\PDHXK\61561.SOW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Q78470.BMB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\G31978.LVR (6 bytes)
%Documents and Settings%\%current user%\PDHXK\U50489.KOE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\97288.ZDA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\J30826.DIE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\L33814.CGJ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\63851.BXZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\11863.ZAU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\82485.YSO (5 bytes)
%Documents and Settings%\%current user%\PDHXK\92840.BEN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\O3314.LQJ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\53861.OPG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\38447.AVZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\V82816.FIT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\14949.SWL (5 bytes)
%Documents and Settings%\%current user%\PDHXK\C22210.CFV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\67994.BNJ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\A35937.DBD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\17304.TCR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\B66514.KYE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\O41661.MVB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\O23014.HRH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\R33381.YYF (6 bytes)
%Documents and Settings%\%current user%\PDHXK\75807.BOB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\X83258.ZPT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\W66860.GRJ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\84407.AWB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\49118.KVD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\60866.LKP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\U95015.ILG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\G54176.BRP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\17022.EWH (5 bytes)
%Documents and Settings%\%current user%\PDHXK\W21005.WWT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Z87557.VXU (6 bytes)
%Documents and Settings%\%current user%\PDHXK\10647.RNM (5 bytes)
%Documents and Settings%\%current user%\PDHXK\M16705.HAI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\X17263.GLE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\39772.JTG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\83799.KDX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\84067.PJF (5 bytes)
%Documents and Settings%\%current user%\PDHXK\T62867.WXV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Q6020.KFJ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\57816.BFQ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\8150.JEQ (4 bytes)
%Documents and Settings%\%current user%\PDHXK\T54088.UXS (6 bytes)
%Documents and Settings%\%current user%\PDHXK\54692.GXY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\3933.ZPL (4 bytes)
%Documents and Settings%\%current user%\PDHXK\S40567.HYM (6 bytes)
%Documents and Settings%\%current user%\PDHXK\N77918.JXX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\G29462.ZQO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\E44424.VSW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\9338.TEW (4 bytes)
%Documents and Settings%\%current user%\PDHXK\68561.DHC (5 bytes)
%Documents and Settings%\%current user%\PDHXK\P29813.NKC (6 bytes)
%Documents and Settings%\%current user%\PDHXK\18328.SJK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\4294.UAG (4 bytes)
%Documents and Settings%\%current user%\PDHXK\Z77078.JMT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\44622.AHA (5 bytes)
The Worm deletes the following file(s):
%Documents and Settings%\%current user%\PDHXK\__tmp_rar_sfx_access_check_603796 (0 bytes)
The process sys.exe:320 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\XYSVU\35767.BAK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\24162.RDZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Z27627.OIN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\8300.ZXI (4 bytes)
%Documents and Settings%\%current user%\XYSVU\H2605.CZD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\64615.JVD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\11242.QTW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\R71160.ABG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\N37594.PBY (6 bytes)
%Documents and Settings%\%current user%\XYSVU\96792.GYO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\92487.FVO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\26813.HFL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\25139.FOV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Q35111.HHC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M32325.IXS (6 bytes)
%Documents and Settings%\%current user%\XYSVU\X16482.IHR (6 bytes)
%Documents and Settings%\%current user%\XYSVU\S30160.MVQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\T42734.KVM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\N33965.NPB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\52384.VWN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X87737.JYC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\23418.YWA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\24696.XAD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X91661.BAQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\E20424.FFS (6 bytes)
%Documents and Settings%\%current user%\XYSVU\A82388.MWW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\66450.GFO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Q31115.GXK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\V92810.ZNX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\320074.dat (28 bytes)
%Documents and Settings%\%current user%\XYSVU\E51187.AIW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\G72590.EYG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\R88319.KQA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\12219.ZTE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A35922.GDG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\K58782.WHN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\31561.DQF (5 bytes)
%Documents and Settings%\%current user%\XYSVU\96772.OIG (5 bytes)
%Documents and Settings%\%current user%\XYSVU\92328.BXT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\settings.ini (133 bytes)
%Documents and Settings%\%current user%\XYSVU\668282.AQI (23407 bytes)
%Documents and Settings%\%current user%\XYSVU\87795.DNV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\92918.NVW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\84926.SHK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\82066.TPK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\67165.TPS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\39633.VUU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Z3879.EEV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\N1218.JZY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\37138.AJY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\25493.KCU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\95761.BCA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A45157.IVF (6 bytes)
%Documents and Settings%\%current user%\XYSVU\P50221.EES (6 bytes)
%Documents and Settings%\%current user%\XYSVU\4585.SFZ (4 bytes)
%Documents and Settings%\%current user%\XYSVU\1867.BFW (4 bytes)
%Documents and Settings%\%current user%\XYSVU\96416.QUP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\J99234.JSX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\53221.ULK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\U82488.ZPJ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\3916.SND (4 bytes)
%Documents and Settings%\%current user%\XYSVU\E87215.EWG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\C6349.EMM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\J84605.AAO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M17634.TRP (6 bytes)
%Documents and Settings%\%current user%\XYSVU\66426.ZIS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\T4367.NTI (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Z44597.XEW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Y79701.PFW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\D89659.BBM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\95793.UGT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\42789.VSB (5 bytes)
%Documents and Settings%\%current user%\XYSVU\65942.XKP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\P17637.GRX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\98027.FOZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\S68918.CGZ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\61707.IUR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\69000.HMU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\C82051.SVH (6 bytes)
%Documents and Settings%\%current user%\XYSVU\65530.JNJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\52850.VRY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\86154.JQM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\52807.VTM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\T33967.KDW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\6642.ZZH (4 bytes)
%Documents and Settings%\%current user%\XYSVU\F12423.LLC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\82838.JRP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\V36420.QTF (6 bytes)
%Documents and Settings%\%current user%\XYSVU\65766.ODK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\99565.LNW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\F31234.RUC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\A27226.GQZ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\D73582.TSZ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\45183.UZA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\4974.LAZ (4 bytes)
%Documents and Settings%\%current user%\XYSVU\69060.RTV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\S50465.BIM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\58861.FEQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\14817.TRL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\M4731.EME (5 bytes)
%Documents and Settings%\%current user%\XYSVU\O93685.FXX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Y60001.JHI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\X24504.VLH (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Z83737.CEO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F25654.YHD (6 bytes)
%Documents and Settings%\%current user%\XYSVU\73621.VNT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\M33246.NAN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\99600.WSV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\87257.ZJY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\13773.LBN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\37919.NRN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\V96293.GGA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\A47238.LBP (6 bytes)
%Documents and Settings%\%current user%\XYSVU\L69473.VTG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\R6883.NWO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\K30598.AGB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\57729.JRU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\P65569.SNI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\P72171.QTA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\82611.QBH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\H65306.RWH (6 bytes)
%Documents and Settings%\%current user%\XYSVU\U57207.NGO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\79372.LKE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\U66107.ZYX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\29864.YNZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\H14008.CMO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\35755.GAJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\96470.HOG (5 bytes)
%Documents and Settings%\%current user%\XYSVU\14896.RJZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\U3659.PTU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\46515.VHK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\D42082.UEN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\48569.MQH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\O92517.EBG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M83933.JRB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\87575.MXF (5 bytes)
%Documents and Settings%\%current user%\XYSVU\89081.NPQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\L94184.VEN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\P41072.WMK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\81879.GDN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Q33880.NXF (6 bytes)
%Documents and Settings%\%current user%\XYSVU\47499.ORW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Q93348.UFT (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Q60940.AFC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\LVXEZ.exe (15361 bytes)
%Documents and Settings%\%current user%\XYSVU\X4549.IRQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\36820.AFQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\22514.WYK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\3883.OBP (4 bytes)
%Documents and Settings%\%current user%\XYSVU\N31217.LNJ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\28747.QXZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\78236.FUC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A26636.CKW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\20653.OIA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\68837.CGN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\76520.SNE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\19690.TTJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Q86304.XHY (6 bytes)
%Documents and Settings%\%current user%\XYSVU\X8705.YJW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\S60842.BXX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\O36513.DVF (6 bytes)
%Documents and Settings%\%current user%\XYSVU\99137.MBO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\81664.XHK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\34086.CSR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\15599.PSS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\58968.SET (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A47228.QPQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\18678.FWF (5 bytes)
%Documents and Settings%\%current user%\XYSVU\85659.CNP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\68891.SHY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\32072.DYQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\T64116.PEI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\49059.HGV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\D4482.XVG (5 bytes)
%Documents and Settings%\%current user%\XYSVU\63655.FTY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\91232.OAQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X30621.IWB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\T57277.OAQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F16410.LWK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\I97658.CBN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Y17138.MMA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\R90321.HXA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\18315.SMV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\N26624.JXC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\28307.ZYS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\65611.ESO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\70416.AFY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\I15836.OQA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\69430.HNF (5 bytes)
%Documents and Settings%\%current user%\XYSVU\51770.JDS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X58543.LJW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\88083.QRW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X79532.SBO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\95650.LEO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\11287.TXE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\99654.KHD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\B10918.ZFO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\12332.RBB (5 bytes)
%Documents and Settings%\%current user%\XYSVU\W28470.OYA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\O93461.IQM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\45566.MDW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\V78910.KOL (6 bytes)
%Documents and Settings%\%current user%\XYSVU\X39074.ZRU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\73669.MIK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\74110.FZP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\99058.UUT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\S20857.ZSM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\B40895.GFB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\61851.QTI (5 bytes)
%Documents and Settings%\%current user%\XYSVU\93387.DZT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\N48385.RWR (6 bytes)
%Documents and Settings%\%current user%\XYSVU\W47829.VZW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\64099.HNO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\51023.YMZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\52958.BTA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\M9627.NXR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\T62505.DKV (6 bytes)
%Documents and Settings%\%current user%\XYSVU\91677.YVB (5 bytes)
%Documents and Settings%\%current user%\XYSVU\96097.OKP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\19255.SFZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Q59586.EUH (6 bytes)
%Documents and Settings%\%current user%\XYSVU\14744.QLT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A25914.FCG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\V57007.USG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\42921.ZXL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\J71593.LZG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\24145.FAK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\I65893.LAX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\89730.QYJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\51992.OJU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\S24727.TAM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\65549.TAU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\S56484.NYL (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M35164.GWR (6 bytes)
%Documents and Settings%\%current user%\XYSVU\94337.YAH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\56927.XYY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A53135.AZZ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\U26117.YHX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\T90819.RDT (6 bytes)
%Documents and Settings%\%current user%\XYSVU\81539.NLA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\99649.OXI (5 bytes)
%Documents and Settings%\%current user%\XYSVU\N25267.BBX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\59885.XVX (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Y31967.GVE (6 bytes)
%Documents and Settings%\%current user%\XYSVU\35274.WFU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\M73201.QQQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\62660.ANX (5 bytes)
%Documents and Settings%\%current user%\XYSVU\20981.XRN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\W23113.XLA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\A70027.WFI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M85148.EGR (6 bytes)
%Documents and Settings%\%current user%\XYSVU\X69146.ZAV (6 bytes)
%Documents and Settings%\%current user%\XYSVU\42478.CZZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\76769.EKJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A64796.KRL (6 bytes)
%Documents and Settings%\%current user%\XYSVU\56133.MCD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\96631.QIM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\83297.DPH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\94848.LPM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\C85149.SXY (6 bytes)
%Documents and Settings%\%current user%\XYSVU\U8902.EOV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\84859.PGP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Q46828.QTA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\L59752.VOC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\A57787.UML (6 bytes)
%Documents and Settings%\%current user%\XYSVU\winrar.vbs (56 bytes)
%Documents and Settings%\%current user%\XYSVU\42121.IRW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\51054.NHF (5 bytes)
%Documents and Settings%\%current user%\XYSVU\63278.CEX (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A27799.UAC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\P10151.ZJA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Z33606.JXD (6 bytes)
%Documents and Settings%\%current user%\XYSVU\95511.HEJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\78377.JRC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\37938.NLV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\J24051.XQO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\10217.IPA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\J89956.PHJ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\59889.NGT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\71982.ELM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\50172.NLR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\3957.OKR (4 bytes)
%Documents and Settings%\%current user%\XYSVU\E48202.DJK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\27106.JKL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\L80033.ZWH (6 bytes)
%Documents and Settings%\%current user%\XYSVU\J6183.ILA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\22055.NKD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\W8197.EHE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\64859.MUT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X78964.KON (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Q88420.JQV (6 bytes)
%Documents and Settings%\%current user%\XYSVU\88314.EPU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\18840.XYM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\B57874.VGA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\66443.DVE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\F52606.BTG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\R49879.SRE (6 bytes)
%Documents and Settings%\%current user%\XYSVU\53502.JUO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X44163.AZF (6 bytes)
%Documents and Settings%\%current user%\XYSVU\I69393.LTG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\A66449.RVZ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F4868.STW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Z4214.ENL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\46884.FVP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\12963.XVP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\73682.MRV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\73078.CKM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\D7182.IJQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\M82628.IWN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\32125.UNJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\66844.YMY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\16443.KWW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\61583.QGD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\34007.KWN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\49896.TAE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\90332.UZR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\62896.DUS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\P20212.CCP (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F57544.FNO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Z46568.CCB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Y81127.RRX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\C99145.LJB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\90525.KPF (5 bytes)
%Documents and Settings%\%current user%\XYSVU\V34647.MZR (6 bytes)
%Documents and Settings%\%current user%\XYSVU\43686.IAJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\93209.VZD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\H33838.KLS (6 bytes)
%Documents and Settings%\%current user%\XYSVU\74927.SEA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\I59144.EBU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\K73378.ZNB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\35737.BJY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\N8514.XAC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\R41333.YAU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\V35789.FEF (6 bytes)
%Documents and Settings%\%current user%\XYSVU\31932.OEL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A30687.SAB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\47454.ULP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\99963.FHJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\47060.IMC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\C73395.SII (6 bytes)
%Documents and Settings%\%current user%\XYSVU\E26092.VYK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\J88584.SAU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Z40191.JAX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\B14866.OUL (6 bytes)
%Documents and Settings%\%current user%\XYSVU\69546.XQH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\9726.YCN (4 bytes)
%Documents and Settings%\%current user%\XYSVU\PAFMJ (1 bytes)
%Documents and Settings%\%current user%\XYSVU\89971.ATK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\R8327.YOU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\31415.GAP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\82502.LTI (5 bytes)
%Documents and Settings%\%current user%\XYSVU\1038.MNY (4 bytes)
%Documents and Settings%\%current user%\XYSVU\H64947.MSL (6 bytes)
%Documents and Settings%\%current user%\XYSVU\S38741.TGI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\D46334.FHE (6 bytes)
%Documents and Settings%\%current user%\XYSVU\I49357.FHP (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Y94588.ODM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\U24992.LPK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\30558.ULP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\60071.PNY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\80419.FCY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\K87075.GPF (6 bytes)
%Documents and Settings%\%current user%\XYSVU\U63919.GHO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\C62019.GLO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\73457.ZLC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Y39303.BGP (6 bytes)
%Documents and Settings%\%current user%\XYSVU\W7328.TPO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\V89680.WXA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\L86252.FGK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\41842.WQU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\47517.IIY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\78980.RVG (5 bytes)
%Documents and Settings%\%current user%\XYSVU\B34334.TAX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\20093.APQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\55811.LGL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\G24281.OAI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\60272.VWE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\42617.EXO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\26825.EZT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\19818.IQQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A34832.BRL (6 bytes)
%Documents and Settings%\%current user%\XYSVU\N11800.CSS (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F63564.QNA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\U70284.QMS (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M23971.DIR (6 bytes)
%Documents and Settings%\%current user%\XYSVU\90618.EGS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\N92224.BGP (6 bytes)
%Documents and Settings%\%current user%\XYSVU\61137.XGX (5 bytes)
%Documents and Settings%\%current user%\XYSVU\42711.HAC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\93712.BPN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\W35173.VRA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\T73187.BFF (6 bytes)
%Documents and Settings%\%current user%\XYSVU\K77554.ZRU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\57530.TTR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\P11039.HYA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F90416.LJN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\21840.BUV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\66294.EJQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\29768.DDA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\384661.dat (601 bytes)
%Documents and Settings%\%current user%\XYSVU\17074.ZEE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\94587.EGC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\98708.GIU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\84709.ODS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\B69129.ISM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\U77313.QIM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\U89793.QKB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\K22373.NIA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\T52313.NDB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\12230.ZYU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\3424.MMO (4 bytes)
%Documents and Settings%\%current user%\XYSVU\R37998.XHL (6 bytes)
%Documents and Settings%\%current user%\XYSVU\63167.NLI (5 bytes)
%Documents and Settings%\%current user%\XYSVU\C21597.SAD (6 bytes)
%Documents and Settings%\%current user%\XYSVU\P13633.ASX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\D62578.UIB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\38885.JPM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\N23489.QCU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\98242.JWZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\9601.CPZ (4 bytes)
%Documents and Settings%\%current user%\XYSVU\B61490.UOH (6 bytes)
%Documents and Settings%\%current user%\XYSVU\83940.IZR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\P54980.EYG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\V61064.AQI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\S37990.YXU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\I89705.HOT (6 bytes)
%Documents and Settings%\%current user%\XYSVU\C65790.XLE (6 bytes)
%Documents and Settings%\%current user%\XYSVU\N87282.BUH (6 bytes)
%Documents and Settings%\%current user%\XYSVU\93497.CVD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\26363.FKU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\59058.UBL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\41395.IZY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\31710.CPS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\14351.MMN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X88731.LCU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F41814.XTP (6 bytes)
%Documents and Settings%\%current user%\XYSVU\90276.PHH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\T99737.XLQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\K87700.GRQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\72285.VPW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\J17949.IJN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\78613.DSE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\84138.HPH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\3305.MMO (4 bytes)
%Documents and Settings%\%current user%\XYSVU\27109.PUL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\J99067.NNI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F20374.NCB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\G60246.RVK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M26206.KPA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\95585.MLK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\43165.MRK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\97338.MTI (5 bytes)
%Documents and Settings%\%current user%\XYSVU\47603.RZS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X91286.NMV (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F67975.BFS (6 bytes)
%Documents and Settings%\%current user%\XYSVU\51617.VWQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\2979.PEX (4 bytes)
%Documents and Settings%\%current user%\XYSVU\80757.JSH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\C54064.TMJ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\21737.VFH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\D25436.ODQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\R48432.JGC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\A84449.IGO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M72564.KKW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\91897.KJO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\80274.WXY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\12366.QPA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\G30624.UMY (6 bytes)
%Documents and Settings%\%current user%\XYSVU\N22690.ODS (6 bytes)
%Documents and Settings%\%current user%\XYSVU\23378.NNS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\22649.ESS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\51644.FZT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\R15638.SCM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\24603.MKQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Y55598.RDB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\76118.IIK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\H31972.QDV (6 bytes)
%Documents and Settings%\%current user%\XYSVU\L83658.KXD (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Y89903.JAQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\D21820.EGL (6 bytes)
%Documents and Settings%\%current user%\XYSVU\G55796.XPA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\W80847.MSW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\65815.EJM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\94368.WES (5 bytes)
%Documents and Settings%\%current user%\XYSVU\77574.LIR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\12213.YOZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\H69172.PBN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\W91117.JMB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\N95666.PWQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\65031.WRN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\50853.TEB (5 bytes)
%Documents and Settings%\%current user%\XYSVU\R91328.YZI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\10394.VYL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\82595.CEK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\98162.BLN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\T3331.UKH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\54543.ZSC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X62334.GKU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\L86703.EJE (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Z33503.VEK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\B60215.MUQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\25844.COV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\57467.YDB (5 bytes)
%Documents and Settings%\%current user%\XYSVU\59293.QMC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\1346.MUZ (4 bytes)
%Documents and Settings%\%current user%\XYSVU\F38906.CYK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M40995.SPD (6 bytes)
%Documents and Settings%\%current user%\XYSVU\S64124.CKG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\K39791.CBI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\35990.MJG (5 bytes)
%Documents and Settings%\%current user%\XYSVU\P96448.PST (6 bytes)
%Documents and Settings%\%current user%\XYSVU\45907.CSR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\B62992.VIB (6 bytes)
The Worm deletes the following file(s):
%Documents and Settings%\%current user%\XYSVU\__tmp_rar_sfx_access_check_562812 (0 bytes)
The process LVXEZ.exe:1364 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\XYSVU\PBFSUGDH.dat (28 bytes)
The Worm deletes the following file(s):
%Documents and Settings%\%current user%\XYSVU\PBFSUGDH.dat (0 bytes)
The process LVXEZ.exe:1972 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\RegSvcs.exe (1216 bytes)
The process win.exe:1684 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%WinDir%\syso\critical\libcurl-4.dll (1673 bytes)
%WinDir%\syso\critical\system.exe (1289 bytes)
%WinDir%\syso\critical\pthreadGC2.dll (2017 bytes)
%WinDir%\syso\critical\antivirus.bat (108 bytes)
%WinDir%\syso\critical\sys.bat (337 bytes)
%WinDir%\syso\critical\zlib1.dll (601 bytes)
%WinDir%\syso\critical\libcurl.dll (1345 bytes)
%WinDir%\syso\critical\nircmd.exe (43 bytes)
The Worm deletes the following file(s):
%WinDir%\syso\__tmp_rar_sfx_access_check_562937 (0 bytes)
The process XYEOD.exe:1552 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\RegSvcs.exe (1216 bytes)
The process XYEOD.exe:1624 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\PDHXK\CIBJVSBF.dat (28 bytes)
The Worm deletes the following file(s):
%Documents and Settings%\%current user%\PDHXK\CIBJVSBF.dat (0 bytes)
The process cmiinna.exe:448 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\517798780.ng[1] (657976 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\1090589642.sym[1].exe (574472 bytes)
C:\win.exe (575270 bytes)
C:\sys.exe (658816 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@directxex[1].txt (225 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (1928 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@directxex[2].txt (225 bytes)
The Worm deletes the following file(s):
%Documents and Settings%\%current user%\Cookies\Current_User@directxex[1].txt (0 bytes)
The process cmiinna.exe:488 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\res.ico2 (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\res.ico (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut2.tmp (1249 bytes)
The Worm deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\res.ico2 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut2.tmp (0 bytes)
The process RegSvcs.exe:1704 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%WinDir%\csrss.exe (33 bytes)
Registry activity
The process nircmd.exe:852 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "6B 9B 94 A3 28 1A 2B 98 BB 04 27 C4 7F 2F 4D B6"
The process %original file name%.exe:1972 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B1 E0 5F 38 04 2B F5 DE FF 0D 52 57 5A 9D F7 29"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
The process %original file name%.exe:1728 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "C8 58 F7 50 3E 1F BD D6 DC 57 29 FF 52 0C 83 A8"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process attrib.exe:1796 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B5 38 47 90 EC EC 37 30 87 23 FB 86 DB BC 06 C8"
The process WScript.exe:260 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "99 F5 5C 38 A3 8D 73 19 53 14 BB E3 99 F7 81 07"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Documents and Settings%\%current user%\PDHXK]
"XYEOD.exe" = "AutoIt v3 Script"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
The Worm modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
The Worm modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Worm modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
The process WScript.exe:1516 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "76 72 58 18 C1 0F FF 22 90 99 AC AF 2D 62 69 75"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Documents and Settings%\%current user%\XYSVU]
"LVXEZ.exe" = "AutoIt v3 Script"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
The Worm modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
The Worm modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Worm modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
The process 3.exe:1672 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "2A 64 5E DB E3 D4 A6 27 1F F0 B8 C4 AF 76 43 B0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The Worm modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Worm modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Worm modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The process sys.exe:320 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "40 B4 EB 67 08 4A 4A 1A 53 D0 8A 3F 06 FD 92 54"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%WinDir%\System32]
"WScript.exe" = "Microsoft (R) Windows Based Script Host"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The Worm modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Worm modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Worm modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The process system.exe:1772 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "62 C0 B9 78 71 69 15 8E 87 68 1F 13 EB 81 56 F8"
The process LVXEZ.exe:1364 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "BD 00 64 59 91 3F A5 13 32 EE 16 02 7A B5 8F BA"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process LVXEZ.exe:1972 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "78 F6 35 D6 65 70 3F 92 66 4F 20 AE C3 7B D2 CC"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process win.exe:1684 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D3 E0 B5 35 28 E3 92 32 6B A1 52 A8 90 1D 15 4F"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Windows\syso\critical]
"sys.bat" = "sys"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The Worm modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Worm modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Worm modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The process XYEOD.exe:1552 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B9 D2 AC C0 F7 79 FC AA 1C B6 28 C3 EF 2D AB 62"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process XYEOD.exe:1624 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "48 F0 BC BE A7 AF 07 4A 58 6C BF 57 DF 56 98 3D"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process cmiinna.exe:448 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKCU\Software\Microsoft\yOLE]
"Supports RAS Connections" = "cmiinna.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:]
"win.exe" = "win"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:]
"sys.exe" = "sys"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\SYSTEM\CurrentControlSet\Control\Lsa]
"Supports RAS Connections" = "cmiinna.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\yOLE]
"Supports RAS Connections" = "cmiinna.exe"
[HKLM\System\CurrentControlSet\Control\Lsa]
"Supports RAS Connections" = "cmiinna.exe"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "C1 68 63 6B E4 7B 53 C3 05 94 9C D6 5B 32 7C 48"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Worm modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
To automatically run itself each time Windows is booted, the Worm adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices]
"Supports RAS Connections" = "cmiinna.exe"
The Worm modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
To automatically run itself each time Windows is booted, the Worm adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Supports RAS Connections" = "cmiinna.exe"
The Worm modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
To automatically run itself each time Windows is booted, the Worm adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Supports RAS Connections" = "cmiinna.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Supports RAS Connections" = "cmiinna.exe"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Worm deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process cmiinna.exe:488 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "C3 DF 17 A2 EF 5C 98 9C CF 59 7A 8A 07 41 DB 98"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process reg.exe:1616 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "43 20 BA B0 25 F3 54 50 87 A6 2E 3B 9D 5F 0F 73"
To automatically run itself each time Windows is booted, the Worm adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Update" = "C:\Windows\syso\critical\antivirus.bat"
The process RegSvcs.exe:288 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "82 28 3C 45 EB 58 EF 18 47 96 DF AE 75 90 EC CD"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
The process RegSvcs.exe:1704 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "AE CF AB C6 9F 5A F5 F4 A0 EA CC 75 E7 43 7D 94"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
To automatically run itself each time Windows is booted, the Worm adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Remote Registry Service" = "csrss.exe"
Network activity (URLs)
| URL | IP |
|---|---|
| hxxp://api.wipmania.com/ (ET POLICY External IP Lookup Attempt To Wipmania ) | |
| hxxp://108.162.199.96/uploads/327660259.mz.exe?dl=1 | |
| n.sw-ho.info |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
The Worm installs the following user-mode hooks in WININET.dll:
HttpSendRequestW
InternetWriteFile
HttpSendRequestA
The Worm installs the following user-mode hooks in dnsapi.dll:
DnsQuery_A
DnsQuery_W
The Worm installs the following user-mode hooks in WS2_32.dll:
send
GetAddrInfoW
The Worm installs the following user-mode hooks in kernel32.dll:
MoveFileA
CopyFileW
CopyFileA
MoveFileW
CreateFileW
CreateFileA
The Worm installs the following user-mode hooks in ntdll.dll:
LdrLoadDll
NtResumeThread
NtQueryDirectoryFile
NtEnumerateValueKey
Propagation
A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the Worm's file once a user opens a drive's folder in Windows Explorer.
A program can register a device notification with the help of RegisterDeviceNotification. So it is notified when a USB device is plugged and then the worm copies itself to the USB device plugged into the affected computer.
A worm can spread its copies through the MSN Messanger.
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Scan a system with an anti-rootkit tool.
- Terminate malicious process(es) (How to End a Process With the Task Manager):
nircmd.exe:852
%original file name%.exe:1972
%original file name%.exe:1728
attrib.exe:1796
WScript.exe:260
WScript.exe:1516
3.exe:1672
sys.exe:320
LVXEZ.exe:1364
LVXEZ.exe:1972
win.exe:1684
XYEOD.exe:1552
XYEOD.exe:1624
cmiinna.exe:488
reg.exe:1616
RegSvcs.exe:288
RegSvcs.exe:1704 - Delete the original Worm file.
- Delete or disinfect the following files created/modified by the Worm:
%System%\cmiinna.exe (7433 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\res.ico2 (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut1.tmp (1249 bytes)
%Documents and Settings%\%current user%\PDHXK\98976.WQN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\A53015.HCG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\66052.UQN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\58570.ZXP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\94286.RAG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\11273.SXY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\30597.NSV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Z74759.ITI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\33114.GAW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\C53524.VUP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\69663.KDA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\X26000.OZH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\31623.RYI (5 bytes)
%Documents and Settings%\%current user%\PDHXK\70951.GAO (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Y32910.XBX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Z55518.RBI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I87902.PST (6 bytes)
%Documents and Settings%\%current user%\PDHXK\V46283.PON (6 bytes)
%Documents and Settings%\%current user%\PDHXK\A81405.CIP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\28811.WGX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\84552.APV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\2787.FYF (4 bytes)
%Documents and Settings%\%current user%\PDHXK\Q14241.BMV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Q83039.FCH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\6751.MBV (4 bytes)
%Documents and Settings%\%current user%\PDHXK\97584.GVB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\G15595.LMC (6 bytes)
%Documents and Settings%\%current user%\PDHXK\41115.UCP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\U74667.ZPU (6 bytes)
%Documents and Settings%\%current user%\PDHXK\U8772.BOT (5 bytes)
%Documents and Settings%\%current user%\PDHXK\50533.VFS (5 bytes)
%Documents and Settings%\%current user%\PDHXK\F82629.SSD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\X83389.YYB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\42423.GJU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\K73965.NGX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\J6344.JQV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\12812.DOI (5 bytes)
%Documents and Settings%\%current user%\PDHXK\91260.ZQG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\J65413.CER (6 bytes)
%Documents and Settings%\%current user%\PDHXK\4202.XIB (4 bytes)
%Documents and Settings%\%current user%\PDHXK\O5325.PLX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\R47143.QGN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\X23747.AOK (6 bytes)
%Documents and Settings%\%current user%\PDHXK\G2950.QSY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\8024.CSX (4 bytes)
%Documents and Settings%\%current user%\PDHXK\17971.QUC (5 bytes)
%Documents and Settings%\%current user%\PDHXK\V73898.YAA (6 bytes)
%Documents and Settings%\%current user%\PDHXK\25530.LEN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\R63852.CIR (6 bytes)
%Documents and Settings%\%current user%\PDHXK\56384.WJG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\O27771.YTT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\30956.UBA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Q63525.GVI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\50246.IMG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\R29694.COX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\J27545.EAL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H77391.ZSP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\78934.WHB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\15771.JUG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\L64772.IHZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H93522.KLO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I31246.YWL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\41046.ZWW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\79947.UBM (5 bytes)
%Documents and Settings%\%current user%\PDHXK\N9391.OEI (5 bytes)
%Documents and Settings%\%current user%\PDHXK\R30690.UAV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M4544.JVR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\52159.ACS (5 bytes)
%Documents and Settings%\%current user%\PDHXK\E84811.BDE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\37675.VUC (5 bytes)
%Documents and Settings%\%current user%\PDHXK\W2490.GWU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\T64920.HUG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\11867.OSD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\B5101.ZYB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\55551.RAV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\49374.CPZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\24838.NDZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\34257.XOJ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\8172.FCS (4 bytes)
%Documents and Settings%\%current user%\PDHXK\54187.ONL (5 bytes)
%Documents and Settings%\%current user%\PDHXK\58279.ZQW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\23652.URG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\P99489.PIM (6 bytes)
%Documents and Settings%\%current user%\PDHXK\S66136.JDO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\98938.JVU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\V88437.FSF (6 bytes)
%Documents and Settings%\%current user%\PDHXK\X69277.VZV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\24516.JFE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\D1624.HSN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\J88609.OSG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M40203.PKZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\29475.FHS (5 bytes)
%Documents and Settings%\%current user%\PDHXK\H99809.NTG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\L66933.GKR (6 bytes)
%Documents and Settings%\%current user%\PDHXK\42968.RJE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\V23336.ARD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\C23787.CUI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\X95029.ZJY (6 bytes)
%Documents and Settings%\%current user%\PDHXK\V68633.RHW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\59137.VFP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\X89527.CKV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\88099.PFB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\T91035.WMH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\O33246.QEQ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\R56975.UFF (6 bytes)
%Documents and Settings%\%current user%\PDHXK\N84051.HRX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\E95741.INZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\14963.VWA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\V14676.ESK (6 bytes)
%Documents and Settings%\%current user%\PDHXK\8621.QAO (4 bytes)
%Documents and Settings%\%current user%\PDHXK\9003.QOA (4 bytes)
%Documents and Settings%\%current user%\PDHXK\81324.SXR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\67225.NNN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Y70175.SYW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\E17176.UZK (6 bytes)
%Documents and Settings%\%current user%\PDHXK\T15509.SSK (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Z64407.WUB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M65558.TQW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\D90135.RJB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\G21109.MVZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I53335.OGR (6 bytes)
%Documents and Settings%\%current user%\PDHXK\25861.TSE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\42129.FMF (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Z28509.VUY (6 bytes)
%Documents and Settings%\%current user%\PDHXK\88122.EME (5 bytes)
%Documents and Settings%\%current user%\PDHXK\L49473.QZO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\D68161.ADV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\E23609.JZN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\96292.QTQ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\32138.TTI (5 bytes)
%Documents and Settings%\%current user%\PDHXK\21172.BRV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\T77764.LPL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\46877.QMQ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\24188.OJT (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Q15297.SRL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\43493.KEZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\N92159.HZH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\87241.OED (5 bytes)
%Documents and Settings%\%current user%\PDHXK\2764.WSV (4 bytes)
%Documents and Settings%\%current user%\PDHXK\L88596.QPU (6 bytes)
%Documents and Settings%\%current user%\PDHXK\90752.UTE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\R53376.ECM (6 bytes)
%Documents and Settings%\%current user%\PDHXK\90970.GCH (5 bytes)
%Documents and Settings%\%current user%\PDHXK\99519.LBX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\P44365.VXT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H44512.VQS (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Q46513.SKV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\4243.SBW (4 bytes)
%Documents and Settings%\%current user%\PDHXK\98628.MXY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\X23071.MUD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\J47864.VHP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H37745.LZP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\21910.XYG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\19368.HKX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\70708.BFU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\K16580.EGB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Q61955.QTC (6 bytes)
%Documents and Settings%\%current user%\PDHXK\8406.EYZ (4 bytes)
%Documents and Settings%\%current user%\PDHXK\60574.TEF (5 bytes)
%Documents and Settings%\%current user%\PDHXK\I6470.CWO (5 bytes)
%Documents and Settings%\%current user%\PDHXK\W85667.CQL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H64010.LXE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\59842.JVZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\LKFFH (1 bytes)
%Documents and Settings%\%current user%\PDHXK\94169.FKW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\B64636.HRI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Q9582.MEZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\14899.GSY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\65951.SCZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\W31856.SOY (6 bytes)
%Documents and Settings%\%current user%\PDHXK\A37320.YDD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\67970.DOI (5 bytes)
%Documents and Settings%\%current user%\PDHXK\I54673.CTW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H32716.WBO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\7282.TTQ (4 bytes)
%Documents and Settings%\%current user%\PDHXK\V52004.EER (6 bytes)
%Documents and Settings%\%current user%\PDHXK\45644.RUH (5 bytes)
%Documents and Settings%\%current user%\PDHXK\94065.BIT (5 bytes)
%Documents and Settings%\%current user%\PDHXK\91698.PYY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\19816.CEP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\1867.DNT (4 bytes)
%Documents and Settings%\%current user%\PDHXK\98117.QAV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\74959.KCA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\S21338.WRA (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H68793.YKY (6 bytes)
%Documents and Settings%\%current user%\PDHXK\C98450.AWZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\59066.WUG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\28060.NVB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\53782.YXP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\P96461.WHW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\S40871.MWE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\22859.PPW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\98908.IFT (5 bytes)
%Documents and Settings%\%current user%\PDHXK\77100.AMO (5 bytes)
%Documents and Settings%\%current user%\PDHXK\5332.CBT (4 bytes)
%Documents and Settings%\%current user%\PDHXK\5508.TMO (4 bytes)
%Documents and Settings%\%current user%\PDHXK\68834.DIK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\O64506.VWB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\14570.YAD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\X33054.WGG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\68485.SMP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\D48995.ZQY (6 bytes)
%Documents and Settings%\%current user%\PDHXK\S73760.EIE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\28914.BQR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\4974.WBG (4 bytes)
%Documents and Settings%\%current user%\PDHXK\80254.XLW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\V23483.WKB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H75257.WKU (6 bytes)
%Documents and Settings%\%current user%\PDHXK\S56575.PLE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\U18160.IIX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\51955.STE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\6325.KUS (4 bytes)
%Documents and Settings%\%current user%\PDHXK\85366.IGK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\V8309.YQN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\54178.PAT (5 bytes)
%Documents and Settings%\%current user%\PDHXK\85934.AIE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\A51645.TLF (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I76508.GQV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M82917.HKI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I52318.OES (6 bytes)
%Documents and Settings%\%current user%\PDHXK\F86790.RSH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\T1433.LYX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\I31118.IWP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\70825.AYV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\36739.ICP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\O84005.YMT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H69665.VUW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\28017.TIB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\H89480.WMP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\3732.MGB (4 bytes)
%Documents and Settings%\%current user%\PDHXK\A37911.ZZV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\19063.UIG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\F43661.ZDB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\35009.XOB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\S14141.GCE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\U77187.NLE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\13141.CEB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\W1272.XNK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\X20639.KUT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\13197.XFA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\J26437.RXF (6 bytes)
%Documents and Settings%\%current user%\PDHXK\C2221.FIZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Y79054.PNG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I1002.PDK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\C11382.AES (6 bytes)
%Documents and Settings%\%current user%\PDHXK\L93355.KSN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Y40359.EDW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\62480.AGT (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Y36078.MSO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\1022.UCX (4 bytes)
%Documents and Settings%\%current user%\PDHXK\C14318.ZZJ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\57252.EYP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\36090.PDZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\47652.BMT (5 bytes)
%Documents and Settings%\%current user%\PDHXK\F19186.JKW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\E77314.RXN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\30514.TRC (5 bytes)
%Documents and Settings%\%current user%\PDHXK\42118.HPN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\V19789.MMS (6 bytes)
%Documents and Settings%\%current user%\PDHXK\99333.LPG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\R11282.GII (6 bytes)
%Documents and Settings%\%current user%\PDHXK\P51766.GAU (6 bytes)
%Documents and Settings%\%current user%\PDHXK\X86555.VSQ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\16378.EKV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\A72346.VWM (6 bytes)
%Documents and Settings%\%current user%\PDHXK\92768.OMN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\27966.WRH (5 bytes)
%Documents and Settings%\%current user%\PDHXK\62640.SOZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\50495.EXC (5 bytes)
%Documents and Settings%\%current user%\PDHXK\77641.WGO (5 bytes)
%Documents and Settings%\%current user%\PDHXK\C17905.MHX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\57027.ZLA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\5005.KLY (4 bytes)
%Documents and Settings%\%current user%\PDHXK\N68892.VHC (6 bytes)
%Documents and Settings%\%current user%\PDHXK\28385.ZZV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\I65393.MJL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\21236.ZXN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\H83107.GTO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\A52499.JRO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\20933.ILO (5 bytes)
%Documents and Settings%\%current user%\PDHXK\5439.ATL (4 bytes)
%Documents and Settings%\%current user%\PDHXK\Q13117.RRO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Q68098.NKU (6 bytes)
%Documents and Settings%\%current user%\PDHXK\J58280.JMD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M8435.WJA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\T51208.XTR (6 bytes)
%Documents and Settings%\%current user%\PDHXK\6380.GRO (4 bytes)
%Documents and Settings%\%current user%\PDHXK\61737.YFD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\91875.CVO (5 bytes)
%Documents and Settings%\%current user%\PDHXK\2808.CUW (4 bytes)
%Documents and Settings%\%current user%\PDHXK\25856.WSQ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\72642.RDY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\W41612.HXO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M22717.RKQ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\5718.RPQ (4 bytes)
%Documents and Settings%\%current user%\PDHXK\X46455.MLJ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\V22423.OEZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\D48725.DNI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\13284.TMB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\25319.KLE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\71285.BZJ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\90512.TVW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\79312.IDY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\25372.BSD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\2277.AQN (4 bytes)
%Documents and Settings%\%current user%\PDHXK\3629.IGH (4 bytes)
%Documents and Settings%\%current user%\PDHXK\3483.PNE (4 bytes)
%Documents and Settings%\%current user%\PDHXK\81615.RMI (5 bytes)
%Documents and Settings%\%current user%\PDHXK\C93607.EEQ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\19869.EJK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\D82706.LVX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\L42732.PFL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Q16359.CKM (6 bytes)
%Documents and Settings%\%current user%\PDHXK\1672.OSE (4 bytes)
%Documents and Settings%\%current user%\PDHXK\T50740.KOZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\T20295.YPH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M90387.TKN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\99805.INN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\G11594.JHB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\3419.ERL (4 bytes)
%Documents and Settings%\%current user%\PDHXK\L4174.HET (5 bytes)
%Documents and Settings%\%current user%\PDHXK\X96121.RZU (6 bytes)
%Documents and Settings%\%current user%\PDHXK\97331.DYB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\92132.NXW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\32535.VGL (5 bytes)
%Documents and Settings%\%current user%\PDHXK\87966.RSE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\62312.WQD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\J51457.BAI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\15719.SSR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\W60771.OOO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\X15958.ZXT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I9077.QSD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Y96865.FLM (6 bytes)
%Documents and Settings%\%current user%\PDHXK\68829.SLG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\81181.EXU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\W90779.VGN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\95704.XAH (5 bytes)
%Documents and Settings%\%current user%\PDHXK\G7240.NIL (5 bytes)
%Documents and Settings%\%current user%\PDHXK\75184.XQX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\48862.KWM (5 bytes)
%Documents and Settings%\%current user%\PDHXK\27848.EOJ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\X62570.GDN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I72264.LOS (6 bytes)
%Documents and Settings%\%current user%\PDHXK\54874.UWP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\M11494.UUG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\20636.ZMV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\E46588.UGO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Y80118.MIS (6 bytes)
%Documents and Settings%\%current user%\PDHXK\14809.WDD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\37648.MTI (5 bytes)
%Documents and Settings%\%current user%\PDHXK\2393.YOG (4 bytes)
%Documents and Settings%\%current user%\PDHXK\settings.ini (126 bytes)
%Documents and Settings%\%current user%\PDHXK\V9477.OXG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\U37276.NCN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\U79349.DAA (6 bytes)
%Documents and Settings%\%current user%\PDHXK\E38039.LOM (6 bytes)
%Documents and Settings%\%current user%\PDHXK\35475.WTU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\84396.CZW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\49177.KZF (5 bytes)
%Documents and Settings%\%current user%\PDHXK\82976.UYP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\34815.LZL (5 bytes)
%Documents and Settings%\%current user%\PDHXK\18145.BSV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Q52408.IKX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\50700.IVW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\L46066.ZPF (6 bytes)
%Documents and Settings%\%current user%\PDHXK\S82991.OFD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\G56014.NAO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\V74709.AYX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\51872.QAJ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\43069.BCK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\I90944.VJI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\44214.BPV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\I28552.LXB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\48227.SAB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\14354.KGS (5 bytes)
%Documents and Settings%\%current user%\PDHXK\45968.DMC (5 bytes)
%Documents and Settings%\%current user%\PDHXK\L23509.KGO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\87373.SXH (5 bytes)
%Documents and Settings%\%current user%\PDHXK\S22282.UUZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\9360.MVI (4 bytes)
%Documents and Settings%\%current user%\PDHXK\V39035.GAN (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I73342.DIF (6 bytes)
%Documents and Settings%\%current user%\PDHXK\19634.GSA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\97756.ZEZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\N17223.DYH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\H67618.YHS (6 bytes)
%Documents and Settings%\%current user%\PDHXK\90058.LBI (5 bytes)
%Documents and Settings%\%current user%\PDHXK\C36452.PTW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\B39607.LIZ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M58996.XHK (6 bytes)
%Documents and Settings%\%current user%\PDHXK\18942.JUN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Y85358.SWP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\E96581.FHE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\38779.ANY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\21499.WSC (5 bytes)
%Documents and Settings%\%current user%\PDHXK\394269.NTC (15021 bytes)
%Documents and Settings%\%current user%\PDHXK\54908.JXX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\P82281.GNF (6 bytes)
%Documents and Settings%\%current user%\PDHXK\75899.GYM (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Z86165.HAG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\P36889.ZAY (6 bytes)
%Documents and Settings%\%current user%\PDHXK\98181.VOM (5 bytes)
%Documents and Settings%\%current user%\PDHXK\58749.AKY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Y93235.UBD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\40815.CWR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\18469.ZRS (5 bytes)
%Documents and Settings%\%current user%\PDHXK\13913.HXU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\G24089.PQI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\A52737.MEK (6 bytes)
%Documents and Settings%\%current user%\PDHXK\78952.HBK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\51285.QDP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\81959.ZEY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\60434.MUV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\94081.NDH (5 bytes)
%Documents and Settings%\%current user%\PDHXK\C41000.LPG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\601051.dat (601 bytes)
%Documents and Settings%\%current user%\PDHXK\27243.XJV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\88722.HOR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\73845.KSU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Q85848.OSJ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\53583.LBK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\82545.SVS (5 bytes)
%Documents and Settings%\%current user%\PDHXK\72919.XVE (5 bytes)
%Documents and Settings%\%current user%\PDHXK\winrar.vbs (56 bytes)
%Documents and Settings%\%current user%\PDHXK\J39695.ZJL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\N61910.HNM (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Q5973.YPD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\64274.ZLU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\T28695.DDB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\V55812.BQE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\66936.KAG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\B75478.JJH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\76947.FRD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\A6247.IMZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\28449.BBV (5 bytes)
%Documents and Settings%\%current user%\PDHXK\75376.RSK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\47145.JPL (5 bytes)
%Documents and Settings%\%current user%\PDHXK\13415.UYD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\16382.CWM (5 bytes)
%Documents and Settings%\%current user%\PDHXK\E18341.MMB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\88707.QDK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\46252.CHR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\78832.UGW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\98604.ZQP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\C14653.WND (6 bytes)
%Documents and Settings%\%current user%\PDHXK\I79990.BLB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\57671.ZFC (5 bytes)
%Documents and Settings%\%current user%\PDHXK\M86746.ICL (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M21251.JQV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\97704.DZR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\86255.WPD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Y74669.HQQ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\3684.JWJ (4 bytes)
%Documents and Settings%\%current user%\PDHXK\977916.dat (28 bytes)
%Documents and Settings%\%current user%\PDHXK\47313.CFQ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\A57318.CDA (6 bytes)
%Documents and Settings%\%current user%\PDHXK\N58880.IXT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\M8084.TTN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\G41521.ZTD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\XYEOD.exe (15361 bytes)
%Documents and Settings%\%current user%\PDHXK\89549.KDD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\6030.XBW (4 bytes)
%Documents and Settings%\%current user%\PDHXK\24122.TMJ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\16719.REQ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\M95797.TAA (6 bytes)
%Documents and Settings%\%current user%\PDHXK\29231.QZP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\78540.SLX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\N67230.TUJ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\31990.BPK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\D46030.SNO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Z5841.WKY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\62161.PHQ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\29494.XAD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\T74912.SNE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Y68851.DVR (6 bytes)
%Documents and Settings%\%current user%\PDHXK\26358.RRO (5 bytes)
%Documents and Settings%\%current user%\PDHXK\61561.SOW (5 bytes)
%Documents and Settings%\%current user%\PDHXK\Q78470.BMB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\G31978.LVR (6 bytes)
%Documents and Settings%\%current user%\PDHXK\U50489.KOE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\97288.ZDA (5 bytes)
%Documents and Settings%\%current user%\PDHXK\J30826.DIE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\L33814.CGJ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\63851.BXZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\11863.ZAU (5 bytes)
%Documents and Settings%\%current user%\PDHXK\82485.YSO (5 bytes)
%Documents and Settings%\%current user%\PDHXK\92840.BEN (5 bytes)
%Documents and Settings%\%current user%\PDHXK\O3314.LQJ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\53861.OPG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\38447.AVZ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\V82816.FIT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\14949.SWL (5 bytes)
%Documents and Settings%\%current user%\PDHXK\C22210.CFV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\67994.BNJ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\A35937.DBD (6 bytes)
%Documents and Settings%\%current user%\PDHXK\17304.TCR (5 bytes)
%Documents and Settings%\%current user%\PDHXK\B66514.KYE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\O41661.MVB (6 bytes)
%Documents and Settings%\%current user%\PDHXK\O23014.HRH (6 bytes)
%Documents and Settings%\%current user%\PDHXK\R33381.YYF (6 bytes)
%Documents and Settings%\%current user%\PDHXK\75807.BOB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\X83258.ZPT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\W66860.GRJ (6 bytes)
%Documents and Settings%\%current user%\PDHXK\84407.AWB (5 bytes)
%Documents and Settings%\%current user%\PDHXK\49118.KVD (5 bytes)
%Documents and Settings%\%current user%\PDHXK\60866.LKP (5 bytes)
%Documents and Settings%\%current user%\PDHXK\U95015.ILG (6 bytes)
%Documents and Settings%\%current user%\PDHXK\G54176.BRP (6 bytes)
%Documents and Settings%\%current user%\PDHXK\17022.EWH (5 bytes)
%Documents and Settings%\%current user%\PDHXK\W21005.WWT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Z87557.VXU (6 bytes)
%Documents and Settings%\%current user%\PDHXK\10647.RNM (5 bytes)
%Documents and Settings%\%current user%\PDHXK\M16705.HAI (6 bytes)
%Documents and Settings%\%current user%\PDHXK\X17263.GLE (6 bytes)
%Documents and Settings%\%current user%\PDHXK\39772.JTG (5 bytes)
%Documents and Settings%\%current user%\PDHXK\83799.KDX (5 bytes)
%Documents and Settings%\%current user%\PDHXK\84067.PJF (5 bytes)
%Documents and Settings%\%current user%\PDHXK\T62867.WXV (6 bytes)
%Documents and Settings%\%current user%\PDHXK\Q6020.KFJ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\57816.BFQ (5 bytes)
%Documents and Settings%\%current user%\PDHXK\8150.JEQ (4 bytes)
%Documents and Settings%\%current user%\PDHXK\T54088.UXS (6 bytes)
%Documents and Settings%\%current user%\PDHXK\54692.GXY (5 bytes)
%Documents and Settings%\%current user%\PDHXK\3933.ZPL (4 bytes)
%Documents and Settings%\%current user%\PDHXK\S40567.HYM (6 bytes)
%Documents and Settings%\%current user%\PDHXK\N77918.JXX (6 bytes)
%Documents and Settings%\%current user%\PDHXK\G29462.ZQO (6 bytes)
%Documents and Settings%\%current user%\PDHXK\E44424.VSW (6 bytes)
%Documents and Settings%\%current user%\PDHXK\9338.TEW (4 bytes)
%Documents and Settings%\%current user%\PDHXK\68561.DHC (5 bytes)
%Documents and Settings%\%current user%\PDHXK\P29813.NKC (6 bytes)
%Documents and Settings%\%current user%\PDHXK\18328.SJK (5 bytes)
%Documents and Settings%\%current user%\PDHXK\4294.UAG (4 bytes)
%Documents and Settings%\%current user%\PDHXK\Z77078.JMT (6 bytes)
%Documents and Settings%\%current user%\PDHXK\44622.AHA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\35767.BAK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\24162.RDZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Z27627.OIN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\8300.ZXI (4 bytes)
%Documents and Settings%\%current user%\XYSVU\H2605.CZD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\64615.JVD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\11242.QTW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\R71160.ABG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\N37594.PBY (6 bytes)
%Documents and Settings%\%current user%\XYSVU\96792.GYO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\92487.FVO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\26813.HFL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\25139.FOV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Q35111.HHC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M32325.IXS (6 bytes)
%Documents and Settings%\%current user%\XYSVU\X16482.IHR (6 bytes)
%Documents and Settings%\%current user%\XYSVU\S30160.MVQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\T42734.KVM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\N33965.NPB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\52384.VWN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X87737.JYC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\23418.YWA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\24696.XAD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X91661.BAQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\E20424.FFS (6 bytes)
%Documents and Settings%\%current user%\XYSVU\A82388.MWW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\66450.GFO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Q31115.GXK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\V92810.ZNX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\320074.dat (28 bytes)
%Documents and Settings%\%current user%\XYSVU\E51187.AIW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\G72590.EYG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\R88319.KQA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\12219.ZTE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A35922.GDG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\K58782.WHN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\31561.DQF (5 bytes)
%Documents and Settings%\%current user%\XYSVU\96772.OIG (5 bytes)
%Documents and Settings%\%current user%\XYSVU\92328.BXT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\settings.ini (133 bytes)
%Documents and Settings%\%current user%\XYSVU\668282.AQI (23407 bytes)
%Documents and Settings%\%current user%\XYSVU\87795.DNV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\92918.NVW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\84926.SHK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\82066.TPK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\67165.TPS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\39633.VUU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Z3879.EEV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\N1218.JZY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\37138.AJY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\25493.KCU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\95761.BCA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A45157.IVF (6 bytes)
%Documents and Settings%\%current user%\XYSVU\P50221.EES (6 bytes)
%Documents and Settings%\%current user%\XYSVU\4585.SFZ (4 bytes)
%Documents and Settings%\%current user%\XYSVU\1867.BFW (4 bytes)
%Documents and Settings%\%current user%\XYSVU\96416.QUP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\J99234.JSX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\53221.ULK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\U82488.ZPJ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\3916.SND (4 bytes)
%Documents and Settings%\%current user%\XYSVU\E87215.EWG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\C6349.EMM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\J84605.AAO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M17634.TRP (6 bytes)
%Documents and Settings%\%current user%\XYSVU\66426.ZIS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\T4367.NTI (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Z44597.XEW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Y79701.PFW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\D89659.BBM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\95793.UGT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\42789.VSB (5 bytes)
%Documents and Settings%\%current user%\XYSVU\65942.XKP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\P17637.GRX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\98027.FOZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\S68918.CGZ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\61707.IUR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\69000.HMU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\C82051.SVH (6 bytes)
%Documents and Settings%\%current user%\XYSVU\65530.JNJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\52850.VRY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\86154.JQM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\52807.VTM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\T33967.KDW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\6642.ZZH (4 bytes)
%Documents and Settings%\%current user%\XYSVU\F12423.LLC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\82838.JRP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\V36420.QTF (6 bytes)
%Documents and Settings%\%current user%\XYSVU\65766.ODK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\99565.LNW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\F31234.RUC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\A27226.GQZ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\D73582.TSZ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\45183.UZA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\4974.LAZ (4 bytes)
%Documents and Settings%\%current user%\XYSVU\69060.RTV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\S50465.BIM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\58861.FEQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\14817.TRL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\M4731.EME (5 bytes)
%Documents and Settings%\%current user%\XYSVU\O93685.FXX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Y60001.JHI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\X24504.VLH (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Z83737.CEO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F25654.YHD (6 bytes)
%Documents and Settings%\%current user%\XYSVU\73621.VNT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\M33246.NAN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\99600.WSV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\87257.ZJY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\13773.LBN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\37919.NRN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\V96293.GGA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\A47238.LBP (6 bytes)
%Documents and Settings%\%current user%\XYSVU\L69473.VTG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\R6883.NWO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\K30598.AGB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\57729.JRU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\P65569.SNI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\P72171.QTA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\82611.QBH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\H65306.RWH (6 bytes)
%Documents and Settings%\%current user%\XYSVU\U57207.NGO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\79372.LKE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\U66107.ZYX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\29864.YNZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\H14008.CMO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\35755.GAJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\96470.HOG (5 bytes)
%Documents and Settings%\%current user%\XYSVU\14896.RJZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\U3659.PTU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\46515.VHK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\D42082.UEN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\48569.MQH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\O92517.EBG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M83933.JRB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\87575.MXF (5 bytes)
%Documents and Settings%\%current user%\XYSVU\89081.NPQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\L94184.VEN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\P41072.WMK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\81879.GDN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Q33880.NXF (6 bytes)
%Documents and Settings%\%current user%\XYSVU\47499.ORW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Q93348.UFT (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Q60940.AFC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\LVXEZ.exe (15361 bytes)
%Documents and Settings%\%current user%\XYSVU\X4549.IRQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\36820.AFQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\22514.WYK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\3883.OBP (4 bytes)
%Documents and Settings%\%current user%\XYSVU\N31217.LNJ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\28747.QXZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\78236.FUC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A26636.CKW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\20653.OIA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\68837.CGN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\76520.SNE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\19690.TTJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Q86304.XHY (6 bytes)
%Documents and Settings%\%current user%\XYSVU\X8705.YJW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\S60842.BXX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\O36513.DVF (6 bytes)
%Documents and Settings%\%current user%\XYSVU\99137.MBO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\81664.XHK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\34086.CSR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\15599.PSS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\58968.SET (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A47228.QPQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\18678.FWF (5 bytes)
%Documents and Settings%\%current user%\XYSVU\85659.CNP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\68891.SHY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\32072.DYQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\T64116.PEI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\49059.HGV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\D4482.XVG (5 bytes)
%Documents and Settings%\%current user%\XYSVU\63655.FTY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\91232.OAQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X30621.IWB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\T57277.OAQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F16410.LWK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\I97658.CBN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Y17138.MMA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\R90321.HXA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\18315.SMV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\N26624.JXC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\28307.ZYS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\65611.ESO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\70416.AFY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\I15836.OQA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\69430.HNF (5 bytes)
%Documents and Settings%\%current user%\XYSVU\51770.JDS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X58543.LJW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\88083.QRW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X79532.SBO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\95650.LEO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\11287.TXE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\99654.KHD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\B10918.ZFO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\12332.RBB (5 bytes)
%Documents and Settings%\%current user%\XYSVU\W28470.OYA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\O93461.IQM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\45566.MDW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\V78910.KOL (6 bytes)
%Documents and Settings%\%current user%\XYSVU\X39074.ZRU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\73669.MIK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\74110.FZP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\99058.UUT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\S20857.ZSM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\B40895.GFB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\61851.QTI (5 bytes)
%Documents and Settings%\%current user%\XYSVU\93387.DZT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\N48385.RWR (6 bytes)
%Documents and Settings%\%current user%\XYSVU\W47829.VZW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\64099.HNO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\51023.YMZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\52958.BTA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\M9627.NXR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\T62505.DKV (6 bytes)
%Documents and Settings%\%current user%\XYSVU\91677.YVB (5 bytes)
%Documents and Settings%\%current user%\XYSVU\96097.OKP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\19255.SFZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Q59586.EUH (6 bytes)
%Documents and Settings%\%current user%\XYSVU\14744.QLT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A25914.FCG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\V57007.USG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\42921.ZXL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\J71593.LZG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\24145.FAK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\I65893.LAX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\89730.QYJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\51992.OJU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\S24727.TAM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\65549.TAU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\S56484.NYL (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M35164.GWR (6 bytes)
%Documents and Settings%\%current user%\XYSVU\94337.YAH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\56927.XYY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A53135.AZZ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\U26117.YHX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\T90819.RDT (6 bytes)
%Documents and Settings%\%current user%\XYSVU\81539.NLA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\99649.OXI (5 bytes)
%Documents and Settings%\%current user%\XYSVU\N25267.BBX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\59885.XVX (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Y31967.GVE (6 bytes)
%Documents and Settings%\%current user%\XYSVU\35274.WFU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\M73201.QQQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\62660.ANX (5 bytes)
%Documents and Settings%\%current user%\XYSVU\20981.XRN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\W23113.XLA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\A70027.WFI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M85148.EGR (6 bytes)
%Documents and Settings%\%current user%\XYSVU\X69146.ZAV (6 bytes)
%Documents and Settings%\%current user%\XYSVU\42478.CZZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\76769.EKJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A64796.KRL (6 bytes)
%Documents and Settings%\%current user%\XYSVU\56133.MCD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\96631.QIM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\83297.DPH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\94848.LPM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\C85149.SXY (6 bytes)
%Documents and Settings%\%current user%\XYSVU\U8902.EOV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\84859.PGP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Q46828.QTA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\L59752.VOC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\A57787.UML (6 bytes)
%Documents and Settings%\%current user%\XYSVU\winrar.vbs (56 bytes)
%Documents and Settings%\%current user%\XYSVU\42121.IRW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\51054.NHF (5 bytes)
%Documents and Settings%\%current user%\XYSVU\63278.CEX (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A27799.UAC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\P10151.ZJA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Z33606.JXD (6 bytes)
%Documents and Settings%\%current user%\XYSVU\95511.HEJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\78377.JRC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\37938.NLV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\J24051.XQO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\10217.IPA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\J89956.PHJ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\59889.NGT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\71982.ELM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\50172.NLR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\3957.OKR (4 bytes)
%Documents and Settings%\%current user%\XYSVU\E48202.DJK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\27106.JKL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\L80033.ZWH (6 bytes)
%Documents and Settings%\%current user%\XYSVU\J6183.ILA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\22055.NKD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\W8197.EHE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\64859.MUT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X78964.KON (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Q88420.JQV (6 bytes)
%Documents and Settings%\%current user%\XYSVU\88314.EPU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\18840.XYM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\B57874.VGA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\66443.DVE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\F52606.BTG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\R49879.SRE (6 bytes)
%Documents and Settings%\%current user%\XYSVU\53502.JUO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X44163.AZF (6 bytes)
%Documents and Settings%\%current user%\XYSVU\I69393.LTG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\A66449.RVZ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F4868.STW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Z4214.ENL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\46884.FVP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\12963.XVP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\73682.MRV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\73078.CKM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\D7182.IJQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\M82628.IWN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\32125.UNJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\66844.YMY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\16443.KWW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\61583.QGD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\34007.KWN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\49896.TAE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\90332.UZR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\62896.DUS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\P20212.CCP (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F57544.FNO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Z46568.CCB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Y81127.RRX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\C99145.LJB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\90525.KPF (5 bytes)
%Documents and Settings%\%current user%\XYSVU\V34647.MZR (6 bytes)
%Documents and Settings%\%current user%\XYSVU\43686.IAJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\93209.VZD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\H33838.KLS (6 bytes)
%Documents and Settings%\%current user%\XYSVU\74927.SEA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\I59144.EBU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\K73378.ZNB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\35737.BJY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\N8514.XAC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\R41333.YAU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\V35789.FEF (6 bytes)
%Documents and Settings%\%current user%\XYSVU\31932.OEL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A30687.SAB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\47454.ULP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\99963.FHJ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\47060.IMC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\C73395.SII (6 bytes)
%Documents and Settings%\%current user%\XYSVU\E26092.VYK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\J88584.SAU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Z40191.JAX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\B14866.OUL (6 bytes)
%Documents and Settings%\%current user%\XYSVU\69546.XQH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\9726.YCN (4 bytes)
%Documents and Settings%\%current user%\XYSVU\PAFMJ (1 bytes)
%Documents and Settings%\%current user%\XYSVU\89971.ATK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\R8327.YOU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\31415.GAP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\82502.LTI (5 bytes)
%Documents and Settings%\%current user%\XYSVU\1038.MNY (4 bytes)
%Documents and Settings%\%current user%\XYSVU\H64947.MSL (6 bytes)
%Documents and Settings%\%current user%\XYSVU\S38741.TGI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\D46334.FHE (6 bytes)
%Documents and Settings%\%current user%\XYSVU\I49357.FHP (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Y94588.ODM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\U24992.LPK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\30558.ULP (5 bytes)
%Documents and Settings%\%current user%\XYSVU\60071.PNY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\80419.FCY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\K87075.GPF (6 bytes)
%Documents and Settings%\%current user%\XYSVU\U63919.GHO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\C62019.GLO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\73457.ZLC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Y39303.BGP (6 bytes)
%Documents and Settings%\%current user%\XYSVU\W7328.TPO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\V89680.WXA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\L86252.FGK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\41842.WQU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\47517.IIY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\78980.RVG (5 bytes)
%Documents and Settings%\%current user%\XYSVU\B34334.TAX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\20093.APQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\55811.LGL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\G24281.OAI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\60272.VWE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\42617.EXO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\26825.EZT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\19818.IQQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\A34832.BRL (6 bytes)
%Documents and Settings%\%current user%\XYSVU\N11800.CSS (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F63564.QNA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\U70284.QMS (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M23971.DIR (6 bytes)
%Documents and Settings%\%current user%\XYSVU\90618.EGS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\N92224.BGP (6 bytes)
%Documents and Settings%\%current user%\XYSVU\61137.XGX (5 bytes)
%Documents and Settings%\%current user%\XYSVU\42711.HAC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\93712.BPN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\W35173.VRA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\T73187.BFF (6 bytes)
%Documents and Settings%\%current user%\XYSVU\K77554.ZRU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\57530.TTR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\P11039.HYA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F90416.LJN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\21840.BUV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\66294.EJQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\29768.DDA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\384661.dat (601 bytes)
%Documents and Settings%\%current user%\XYSVU\17074.ZEE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\94587.EGC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\98708.GIU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\84709.ODS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\B69129.ISM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\U77313.QIM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\U89793.QKB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\K22373.NIA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\T52313.NDB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\12230.ZYU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\3424.MMO (4 bytes)
%Documents and Settings%\%current user%\XYSVU\R37998.XHL (6 bytes)
%Documents and Settings%\%current user%\XYSVU\63167.NLI (5 bytes)
%Documents and Settings%\%current user%\XYSVU\C21597.SAD (6 bytes)
%Documents and Settings%\%current user%\XYSVU\P13633.ASX (6 bytes)
%Documents and Settings%\%current user%\XYSVU\D62578.UIB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\38885.JPM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\N23489.QCU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\98242.JWZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\9601.CPZ (4 bytes)
%Documents and Settings%\%current user%\XYSVU\B61490.UOH (6 bytes)
%Documents and Settings%\%current user%\XYSVU\83940.IZR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\P54980.EYG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\V61064.AQI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\S37990.YXU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\I89705.HOT (6 bytes)
%Documents and Settings%\%current user%\XYSVU\C65790.XLE (6 bytes)
%Documents and Settings%\%current user%\XYSVU\N87282.BUH (6 bytes)
%Documents and Settings%\%current user%\XYSVU\93497.CVD (5 bytes)
%Documents and Settings%\%current user%\XYSVU\26363.FKU (5 bytes)
%Documents and Settings%\%current user%\XYSVU\59058.UBL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\41395.IZY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\31710.CPS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\14351.MMN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X88731.LCU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F41814.XTP (6 bytes)
%Documents and Settings%\%current user%\XYSVU\90276.PHH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\T99737.XLQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\K87700.GRQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\72285.VPW (5 bytes)
%Documents and Settings%\%current user%\XYSVU\J17949.IJN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\78613.DSE (5 bytes)
%Documents and Settings%\%current user%\XYSVU\84138.HPH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\3305.MMO (4 bytes)
%Documents and Settings%\%current user%\XYSVU\27109.PUL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\J99067.NNI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F20374.NCB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\G60246.RVK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M26206.KPA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\95585.MLK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\43165.MRK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\97338.MTI (5 bytes)
%Documents and Settings%\%current user%\XYSVU\47603.RZS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X91286.NMV (6 bytes)
%Documents and Settings%\%current user%\XYSVU\F67975.BFS (6 bytes)
%Documents and Settings%\%current user%\XYSVU\51617.VWQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\2979.PEX (4 bytes)
%Documents and Settings%\%current user%\XYSVU\80757.JSH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\C54064.TMJ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\21737.VFH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\D25436.ODQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\R48432.JGC (6 bytes)
%Documents and Settings%\%current user%\XYSVU\A84449.IGO (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M72564.KKW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\91897.KJO (5 bytes)
%Documents and Settings%\%current user%\XYSVU\80274.WXY (5 bytes)
%Documents and Settings%\%current user%\XYSVU\12366.QPA (5 bytes)
%Documents and Settings%\%current user%\XYSVU\G30624.UMY (6 bytes)
%Documents and Settings%\%current user%\XYSVU\N22690.ODS (6 bytes)
%Documents and Settings%\%current user%\XYSVU\23378.NNS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\22649.ESS (5 bytes)
%Documents and Settings%\%current user%\XYSVU\51644.FZT (5 bytes)
%Documents and Settings%\%current user%\XYSVU\R15638.SCM (6 bytes)
%Documents and Settings%\%current user%\XYSVU\24603.MKQ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\Y55598.RDB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\76118.IIK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\H31972.QDV (6 bytes)
%Documents and Settings%\%current user%\XYSVU\L83658.KXD (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Y89903.JAQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\D21820.EGL (6 bytes)
%Documents and Settings%\%current user%\XYSVU\G55796.XPA (6 bytes)
%Documents and Settings%\%current user%\XYSVU\W80847.MSW (6 bytes)
%Documents and Settings%\%current user%\XYSVU\65815.EJM (5 bytes)
%Documents and Settings%\%current user%\XYSVU\94368.WES (5 bytes)
%Documents and Settings%\%current user%\XYSVU\77574.LIR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\12213.YOZ (5 bytes)
%Documents and Settings%\%current user%\XYSVU\H69172.PBN (6 bytes)
%Documents and Settings%\%current user%\XYSVU\W91117.JMB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\N95666.PWQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\65031.WRN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\50853.TEB (5 bytes)
%Documents and Settings%\%current user%\XYSVU\R91328.YZI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\10394.VYL (5 bytes)
%Documents and Settings%\%current user%\XYSVU\82595.CEK (5 bytes)
%Documents and Settings%\%current user%\XYSVU\98162.BLN (5 bytes)
%Documents and Settings%\%current user%\XYSVU\T3331.UKH (5 bytes)
%Documents and Settings%\%current user%\XYSVU\54543.ZSC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\X62334.GKU (6 bytes)
%Documents and Settings%\%current user%\XYSVU\L86703.EJE (6 bytes)
%Documents and Settings%\%current user%\XYSVU\Z33503.VEK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\B60215.MUQ (6 bytes)
%Documents and Settings%\%current user%\XYSVU\25844.COV (5 bytes)
%Documents and Settings%\%current user%\XYSVU\57467.YDB (5 bytes)
%Documents and Settings%\%current user%\XYSVU\59293.QMC (5 bytes)
%Documents and Settings%\%current user%\XYSVU\1346.MUZ (4 bytes)
%Documents and Settings%\%current user%\XYSVU\F38906.CYK (6 bytes)
%Documents and Settings%\%current user%\XYSVU\M40995.SPD (6 bytes)
%Documents and Settings%\%current user%\XYSVU\S64124.CKG (6 bytes)
%Documents and Settings%\%current user%\XYSVU\K39791.CBI (6 bytes)
%Documents and Settings%\%current user%\XYSVU\35990.MJG (5 bytes)
%Documents and Settings%\%current user%\XYSVU\P96448.PST (6 bytes)
%Documents and Settings%\%current user%\XYSVU\45907.CSR (5 bytes)
%Documents and Settings%\%current user%\XYSVU\B62992.VIB (6 bytes)
%Documents and Settings%\%current user%\XYSVU\PBFSUGDH.dat (28 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\RegSvcs.exe (1216 bytes)
%WinDir%\syso\critical\libcurl-4.dll (1673 bytes)
%WinDir%\syso\critical\system.exe (1289 bytes)
%WinDir%\syso\critical\pthreadGC2.dll (2017 bytes)
%WinDir%\syso\critical\antivirus.bat (108 bytes)
%WinDir%\syso\critical\sys.bat (337 bytes)
%WinDir%\syso\critical\zlib1.dll (601 bytes)
%WinDir%\syso\critical\libcurl.dll (1345 bytes)
%WinDir%\syso\critical\nircmd.exe (43 bytes)
%Documents and Settings%\%current user%\PDHXK\CIBJVSBF.dat (28 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\517798780.ng[1] (657976 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\1090589642.sym[1].exe (574472 bytes)
C:\win.exe (575270 bytes)
C:\sys.exe (658816 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@directxex[1].txt (225 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (1928 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@directxex[2].txt (225 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut2.tmp (1249 bytes)
%WinDir%\csrss.exe (33 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices]
"Supports RAS Connections" = "cmiinna.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Supports RAS Connections" = "cmiinna.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Supports RAS Connections" = "cmiinna.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Supports RAS Connections" = "cmiinna.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Update" = "C:\Windows\syso\critical\antivirus.bat"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Remote Registry Service" = "csrss.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Find and delete all copies of the worm's file together with "autorun.inf" scripts on removable drives.
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.