This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
WildFire Analysis Report
Table of Contents
1. File Information ................................................................... 22. Dynamic Analysis ................................................................. 2
2.1.1. Behavioral Summary This sample was found to be malware on this virtual machine.
Behavior Created a file in the Windows folder Used the POST method in HTTP Created an executable file in the Windows system folder Created an executable file in a user document folder Started a process from a user document folder Spawned new processes Deleted itself Injected code into another process Started or stopped a system service Registered a file as auto-start from a local directory Modified registries or system configuration to enable auto start capablity Modified Windows registries Changed security settings of Internet Explorer Changed the proxy settings for Internet Explorer Modified the network connections setting for Internet Explorer Created or modified files Attempted to sleep for a long period Disabled Safe Mode by modifying safe boot registries
2.1.2. Network Activity
DNS Queries
Domain Name Query Type DNS Responsemolinaderrec.com A 185.11.80.74google.nl NS ns3.google.comgoogle.com NS ns1.google.comgoogle.com A 173.194.113.7www.google.nl A 173.194.44.23molinaderrec.com NS ns3.andreia.rugoogle.com A 173.194.113.4ssl.gstatic.com A 173.194.113.23molinaderrec.com NS ns4.impis.rugoogle.com A 173.194.113.5molinaderrec.com A 31.8.219.66www.google.nl A 173.194.44.24google.com A 173.194.113.2google.nl NS ns2.google.commolinaderrec.com A 71.197.189.135
molinaderrec.com NS ns4.andreia.rugoogle.com NS ns4.google.commolinaderrec.com A 78.137.47.140google.com A 173.194.113.3www.google.nl A 173.194.44.31clients1.google.nl A 173.194.113.31google.com A 173.194.113.0google.com NS ns2.google.comgoogle.com A 173.194.113.1molinaderrec.com NS ns1.andreia.rugstatic.com NS ns2.google.commolinaderrec.com NS ns2.impis.russl.gstatic.com A 173.194.113.31clients1.google.nl A 173.194.113.23gstatic.com NS ns3.google.commolinaderrec.com A 46.118.77.80molinaderrec.com A 194.44.119.181molinaderrec.com NS ns3.impis.rumolinaderrec.com A 31.28.251.147molinaderrec.com A 95.67.81.31molinaderrec.com A 68.174.185.19molinaderrec.com NS ns1.impis.rumolinaderrec.com NS ns2.andreia.russl.gstatic.com A 173.194.113.24google.nl NS ns4.google.comgoogle.com A 173.194.113.8molinaderrec.com A 46.211.67.170gstatic.com NS ns1.google.commolinaderrec.com A 94.41.83.192google.com A 173.194.113.9google.com NS ns3.google.comclients1.google.nl A 173.194.113.24google.com A 173.194.113.14gstatic.com NS ns4.google.comgoogle.com A 173.194.113.6ssl.gstatic.com A 173.194.113.15google.nl NS ns1.google.com
HTTP Requests
HTTP Method URL User-AgentGET google.com/ Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;
POST molinaderrec.com/b/opt/44DFB48F29646D0D6B8E9192 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;SV1; .NET CLR 2.0.50727; .NET CLR3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C;.NET4.0E)
POST molinaderrec.com/b/opt/C3B267273F1D9D547DF761CB Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;SV1; .NET CLR 2.0.50727; .NET CLR3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C;.NET4.0E)
POST molinaderrec.com/b/opt/74AE238F49A32A870B49D618 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;SV1; .NET CLR 2.0.50727; .NET CLR3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C;.NET4.0E)
GET molinaderrec.com/b/eve/d2ba060f9050fa90f0326845 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;SV1; .NET CLR 2.0.50727; .NET CLR3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C;.NET4.0E)
POST molinaderrec.com/b/opt/AF508E8EF8599C6DBAB360F2 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;SV1; .NET CLR 2.0.50727; .NET CLR3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C;.NET4.0E)
GET google.com/ Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;SV1; .NET CLR 2.0.50727; .NET CLR3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C;.NET4.0E)
GET www.google.nl/?gws_rd=cr&ei=X6NsU-7MHcPuOvqDgfgP Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;SV1; .NET CLR 2.0.50727; .NET CLR3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C;.NET4.0E)
GET google.com/ Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;SV1; .NET CLR 2.0.50727; .NET CLR3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C;.NET4.0E)
POST molinaderrec.com/b/opt/FD514D30402872AB02C28E34 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;SV1; .NET CLR 2.0.50727; .NET CLR3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C;.NET4.0E)
POST molinaderrec.com/b/opt/A72E0EC28DBE8707CF547B98 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;SV1; .NET CLR 2.0.50727; .NET CLR3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C;.NET4.0E)
GET www.google.nl/?gws_rd=cr&ei=A6NsU7vuJIrEPKHJgPgC Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;SV1; .NET CLR 2.0.50727; .NET CLR3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C;.NET4.0E)
GET www.google.nl/?gws_rd=cr&ei=3qJsU77yDsfiOtKLgJAE Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;SV1; .NET CLR 2.0.50727; .NET CLR3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C;.NET4.0E)
POST molinaderrec.com/b/opt/0E02CB9E9605AA93D4EF560C Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;SV1; .NET CLR 2.0.50727; .NET CLR3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C;.NET4.0E)
GET google.com/ Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;SV1; .NET CLR 2.0.50727; .NET CLR3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C;.NET4.0E)
Connections
Host Port Protocol Country173.194.113.24 80 TCP US173.194.113.31 80 TCP US
5 / 32
173.194.113.8 80 TCP US46.118.77.80 80 TCP UA173.194.44.23 80 TCP US
2.1.3. Host ActivityProcess Name - "C:\Documents and Settings\Administrator\ApplicationData\Myysry\enyzolq.exe" -child(command: "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe" -child)
File Activity
File ActionC:\Documents and Settings\Administrator\Cookies\administrator@google[1].txt CreateC:\Documents and Settings\Administrator\Cookies\administrator@google[2].txt CreateC:\Documents and Settings\Administrator\Cookies\administrator@google[3].txt CreateC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\DF1LSW9G\google[1] CreateC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\DF1LSW9G\google[1].htm CreateC:\Documents and Settings\Administrator\Local Settings\Temporary InternetFiles\Content.IE5\K1XHOOEA\chrome-48[2].png
Create
C:\Documents and Settings\Administrator\Local Settings\Temporary InternetFiles\Content.IE5\LDKH2A5D\nav_logo80[2].png
Create
C:\Documents and Settings\Administrator\Local Settings\Temporary InternetFiles\Content.IE5\VPKKM73P\rs=AItRSTPqPxPQq9apHYeYn61I89z9NOuesQ[1]
Create
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\VPKKM73P\logo9w[1].png CreateC:\Documents and Settings\Administrator\Local Settings\Temporary InternetFiles\Content.IE5\K1XHOOEA\scm_2b9edb365d122da01f5cf2b5a536cae8[1].js
Create
C:\Documents and Settings\Administrator\Cookies\administrator@google[1].txt Delete
Registry Activity
Registry Key Value ActionHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Process Name - "C:\WINDOWS\system32\cmd.exe" /c"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp781f8c98.bat"(command: "C:\WINDOWS\system32\cmd.exe" /c "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp781f8c98.bat")
File Activity
File Actionc:\documents and settings\administrator\sample.exe DeleteC:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp781f8c98.bat Delete
Process Name - "C:\Documents and Settings\Administrator\ApplicationData\Myysry\enyzolq.exe"(command: "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe")
Process Activity
Child Process Action"C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe" -child Create
File Activity
File ActionC:\Documents and Settings\Administrator\Cookies\administrator@google[1].txt CreateC:\Documents and Settings\Administrator\Cookies\administrator@google[2].txt CreateC:\Documents and Settings\Administrator\Cookies\administrator@google[3].txt CreateC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LDKH2A5D\google[1].htm CreateC:\Documents and Settings\Administrator\Cookies\administrator@google[2].txt DeleteC:\Documents and Settings\Administrator\Cookies\administrator@google[1].txt DeleteC:\Documents and Settings\Administrator\Cookies\administrator@google[3].txt DeleteC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LDKH2A5D\google[1].htm Delete
Registry Activity
Registry Key Value ActionHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Mutex NameLocal\{A3C4EA23-1B1A-AD61-B859-15889600F576}Local\{88628F11-7E28-86C7-B859-15889600F576}Global\{A4BBAF3C-5E05-AA1E-FCAE-E722D2F707DC}Global\{E9843906-C83F-E721-B859-15889600F576}c:!documents and settings!administrator!local settings!temporary internet files!content.ie5!c:!documents and settings!administrator!cookies!c:!documents and settings!administrator!local settings!history!history.ie5!WininetConnectionMutex<NULL>Global\{A4BBAF3C-5E05-AA1E-8CAC-E722A2F507DC}
Process Name - sample.exe(command: c:\documents and settings\administrator\sample.exe)
Process Activity
Child Process Action"C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe" Create"C:\WINDOWS\system32\cmd.exe" /c "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp781f8c98.bat" Create
File Activity
File ActionC:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe CreateC:\WINDOWS\Tasks\Security Center Update - 4194332589.job CreateC:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp781f8c98.bat Create
Registry Activity
Registry Key Value ActionHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
1 Created Process c:\documents and settings\administrator\sample.exe2 Set key
\REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellFolders\AppData to value C:\Documents and Settings\Administrator\Application Data
3 Created mutex Global\{19DDCF68-3E51-1778-B859-15889600F576}4 Created file C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe5 Created file C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe6 Created file C:\WINDOWS\Tasks\Security Center Update - 4194332589.job7 Created service SecurityCenterServer4194332589 from "C:\WINDOWS\system32\viebfomibu.exe" -service "C:\Documents and
Settings\Administrator\Application Data\Myysry\enyzolq.exe"8 Set key \REGISTRY\MACHINE\SOFTWARE\Mrdfiiithk\License to value 4449 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Mrdfiiithk\License to value 44410 Created Process "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"11 Set key
\REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellFolders\AppData to value C:\Documents and Settings\Administrator\Application Data
12 Created mutex Local\{A3C4EA23-1B1A-AD61-B859-15889600F576}13 Created file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp781f8c98.bat14 Created mutex Local\{88628F11-7E28-86C7-B859-15889600F576}15 Created mutex Global\{A4BBAF3C-5E05-AA1E-FCAE-E722D2F707DC}16 Created mutex Global\{E9843906-C83F-E721-B859-15889600F576}17 Created file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp781f8c98.bat18 Set key \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Session Manager\SubSystems\Windows to value NULL19 Set key
\REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellFolders\Cache to value C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
20 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
21 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
22 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
23 Created Process "C:\WINDOWS\system32\cmd.exe" /c "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp781f8c98.bat"24 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Directory to value
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE525 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Paths to value 426 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1\CachePath to
value C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache127 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2\CachePath to
11 / 32
value C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache228 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3\CachePath to
value C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache329 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4\CachePath to
value C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache430 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1\CacheLimit to
value 16372431 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2\CacheLimit to
value 16372432 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3\CacheLimit to
value 16372433 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4\CacheLimit to
value 16372434 Set key
\REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellFolders\Cookies to value C:\Documents and Settings\Administrator\Cookies
35 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
36 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
37 Set key\REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellFolders\History to value C:\Documents and Settings\Administrator\Local Settings\History
38 Created mutex c:!documents and settings!administrator!local settings!temporary internet files!content.ie5!39 Created mutex c:!documents and settings!administrator!cookies!40 Created mutex c:!documents and settings!administrator!local settings!history!history.ie5!41 Created mutex WininetConnectionMutex42 Created mutex43 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inen
edpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"44 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and
Settings\Administrator\Application Data\Myysry\enyzolq.exe"45 Created Process "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe" -child46 Deleted file c:\documents and settings\administrator\sample.exe47 Set key \REGISTRY\MACHINE\SOFTWARE\uQjb6Q\Tasks to value NULL48 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\uQjb6Q\Tasks to value NULL49 Deleted file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tmp781f8c98.bat50 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inen
edpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"51 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and
Settings\Administrator\Application Data\Myysry\enyzolq.exe"52 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inen
edpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"53 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and
Settings\Administrator\Application Data\Myysry\enyzolq.exe"54 Set key
\REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellFolders\AppData to value C:\Documents and Settings\Administrator\Application Data
55 Created mutex Local\{A3C4EA23-1B1A-AD61-B859-15889600F576}56 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Internet
Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\enyzolq.exe to value 1100157 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inen
edpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"58 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and
Settings\Administrator\Application Data\Myysry\enyzolq.exe"59 Set key
\REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellFolders\Cache to value C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
60 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Directory to valueC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
61 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Paths to value 462 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1\CachePath to
value C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache163 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2\CachePath to
value C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache264 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3\CachePath to
value C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache365 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4\CachePath to
value C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Cache4
12 / 32
66 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1\CacheLimit tovalue 163724
67 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2\CacheLimit tovalue 163724
68 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3\CacheLimit tovalue 163724
69 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4\CacheLimit tovalue 163724
70 Set key\REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellFolders\Cookies to value C:\Documents and Settings\Administrator\Cookies
71 Set key\REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellFolders\History to value C:\Documents and Settings\Administrator\Local Settings\History
72 Created mutex73 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\
@xpsp3res.dll to value -2000174 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\ProxyBypass to value 175 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\IntranetName to value 176 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\UNCAsIntranet to value 177 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\ProxyBypass to value 178 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\IntranetName to value 179 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\UNCAsIntranet to value 180 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inen
edpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"81 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and
Settings\Administrator\Application Data\Myysry\enyzolq.exe"82 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inen
edpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"83 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and
Settings\Administrator\Application Data\Myysry\enyzolq.exe"84 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common AppData to value
C:\Documents and Settings\All Users\Application Data85 Set key
\REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellFolders\AppData to value C:\Documents and Settings\Administrator\Application Data
86 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\InternetSettings\MigrateProxy to value 1
87 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\InternetSettings\ProxyEnable to value 0
88 Set key \REGISTRY\MACHINE\SYSTEM\ControlSet001\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\InternetSettings\ProxyEnable to value 0
89 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\InternetSettings\Connections\SavedLegacySettings to value NULL
90 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
91 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
92 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
93 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
94 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
95 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
96 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
97 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
98 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
13 / 32
99 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
100 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
101 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
102 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
103 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
104 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
105 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
106 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
107 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
108 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
109 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
110 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
111 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
112 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
113 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
114 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
115 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
116 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
117 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
118 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
119 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
120 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
121 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
122 Created file C:\Documents and Settings\Administrator\Cookies\administrator@google[1].txt123 Created file C:\Documents and Settings\Administrator\Cookies\administrator@google[2].txt124 Deleted file C:\Documents and Settings\Administrator\Cookies\administrator@google[1].txt125 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inen
edpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"126 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and
Settings\Administrator\Application Data\Myysry\enyzolq.exe"127 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inen
edpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"128 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and
Settings\Administrator\Application Data\Myysry\enyzolq.exe"129 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inen
edpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"130 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and
Settings\Administrator\Application Data\Myysry\enyzolq.exe"131 Created file C:\Documents and Settings\Administrator\Cookies\administrator@google[1].txt132 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inen
edpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"133 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and
Settings\Administrator\Application Data\Myysry\enyzolq.exe"134 Created file C:\Documents and Settings\Administrator\Cookies\administrator@google[3].txt135 Deleted file C:\Documents and Settings\Administrator\Cookies\administrator@google[1].txt
14 / 32
136 Created file C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\DF1LSW9G\google[1]137 Created file C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\DF1LSW9G\google[1].htm138 Created file C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\DF1LSW9G\google[1].htm139 Created mutex MSIMGSIZECacheMutex140 Set key
\REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellFolders\Local AppData to value C:\Documents and Settings\Administrator\Local Settings\Application Data
141 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
142 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
143 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
144 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
145 Created file C:\Documents and Settings\Administrator\Local Settings\Temporary InternetFiles\Content.IE5\K1XHOOEA\chrome-48[2].png
146 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
147 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
148 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
149 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
150 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
151 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
152 Created file C:\Documents and Settings\Administrator\Local Settings\Temporary InternetFiles\Content.IE5\LDKH2A5D\nav_logo80[2].png
153 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
154 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
155 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
156 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
157 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
158 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
159 Created file C:\Documents and Settings\Administrator\Local Settings\Temporary InternetFiles\Content.IE5\VPKKM73P\rs=AItRSTPqPxPQq9apHYeYn61I89z9NOuesQ[1]
160 Created file C:\Documents and Settings\Administrator\Local Settings\Temporary InternetFiles\Content.IE5\VPKKM73P\rs=AItRSTPqPxPQq9apHYeYn61I89z9NOuesQ[1]
161 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
162 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
163 Created file C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\VPKKM73P\logo9w[1].png164 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inen
edpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"165 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and
Settings\Administrator\Application Data\Myysry\enyzolq.exe"166 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inen
edpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"167 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and
Settings\Administrator\Application Data\Myysry\enyzolq.exe"168 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inen
edpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"169 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and
Settings\Administrator\Application Data\Myysry\enyzolq.exe"170 Created mutex Global\{A4BBAF3C-5E05-AA1E-8CAC-E722A2F507DC}171 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inen
edpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"172 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and
173 Created file C:\Documents and Settings\Administrator\Local Settings\Temporary InternetFiles\Content.IE5\K1XHOOEA\scm_2b9edb365d122da01f5cf2b5a536cae8[1].js
174 Created file C:\Documents and Settings\Administrator\Local Settings\Temporary InternetFiles\Content.IE5\K1XHOOEA\scm_2b9edb365d122da01f5cf2b5a536cae8[1].js
175 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
176 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
177 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
178 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
179 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
180 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
181 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
182 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
183 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
184 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
185 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
186 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
187 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
188 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
189 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
190 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
191 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
192 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
193 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
194 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
195 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
196 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
197 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
198 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
199 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
200 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
201 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
202 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
203 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
204 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
205 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
206 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
16 / 32
207 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
208 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
209 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
210 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
211 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
212 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
213 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
214 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
215 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
216 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
217 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
218 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
219 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
220 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
221 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
222 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
223 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
224 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
225 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
226 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
227 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
228 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
229 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
230 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
231 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
232 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
233 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
234 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
235 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
236 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
237 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
238 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
239 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
240 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
17 / 32
241 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
242 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
243 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
244 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
245 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
246 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
247 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
248 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
249 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
250 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
251 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
252 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
253 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
254 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
255 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
256 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
257 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
258 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
259 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
260 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
261 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
262 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
263 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
264 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
265 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
266 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
267 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
268 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
269 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
270 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
271 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
272 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
273 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
274 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
18 / 32
275 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
276 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
277 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
278 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
279 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
280 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
281 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
282 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
283 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
284 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
285 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
286 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
287 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
288 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
289 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
290 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
291 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
292 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
293 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
294 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
295 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
296 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
297 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
298 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
299 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
300 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
301 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
302 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
303 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
304 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
305 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
306 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
307 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
308 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
19 / 32
309 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
310 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
311 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
312 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
313 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
314 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
315 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
316 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
317 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
318 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
319 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
320 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
321 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
322 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
323 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
324 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
325 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
326 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
327 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
328 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
329 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
330 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
331 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
332 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
333 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
334 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
335 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
336 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
337 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
338 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
339 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
340 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
341 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
342 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
20 / 32
343 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
344 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
345 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
346 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
347 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
348 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
349 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
350 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
351 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
352 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
353 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
354 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
355 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
356 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
357 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
358 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
359 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
360 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
361 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
362 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
363 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
364 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
365 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
366 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
367 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
368 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
369 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
370 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
371 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
372 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
373 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
374 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
375 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
376 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
21 / 32
377 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
378 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
379 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
380 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
381 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
382 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
383 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
384 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
385 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
386 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
387 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
388 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
389 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
390 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
391 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
392 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
393 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
394 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
395 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
396 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
397 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
398 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
399 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
400 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
401 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
402 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
403 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
404 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
405 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
406 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
407 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
408 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
409 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
410 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
22 / 32
411 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
412 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
413 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
414 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
415 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
416 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
417 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
418 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
419 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
420 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
421 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
422 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
423 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
424 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
425 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
426 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
427 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
428 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
429 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
430 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
431 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
432 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
433 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
434 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
435 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
436 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
437 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
438 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
439 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
440 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
441 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
442 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
443 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
444 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
23 / 32
445 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
446 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
447 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
448 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
449 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
450 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
451 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
452 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
453 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
454 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
455 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
456 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
457 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
458 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
459 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
460 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
461 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
462 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
463 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
464 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
465 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
466 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
467 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
468 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
469 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
470 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
471 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
472 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
473 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\WINDOWS\System32\logon.scr to value Logon Screen Saver
474 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\SessionInformation\ProgramCount to value 2475 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\SessionInformation\ProgramCount to value 3476 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inen
edpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"477 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and
Settings\Administrator\Application Data\Myysry\enyzolq.exe"478 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inen
edpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"479 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and
480 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
481 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
482 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
483 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
484 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
485 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
486 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
487 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
488 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
489 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
490 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
491 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
492 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
493 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
494 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
495 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
496 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
497 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
498 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
499 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents andSettings\Administrator\Application Data\Myysry\enyzolq.exe"
500 Set key \REGISTRY\USER\S-1-5-21-2052111302-1214440339-682003330-500\Software\Microsoft\Windows\CurrentVersion\Run\Inenedpyaqwyipq to value "C:\Documents and Settings\Administrator\Application Data\Myysry\enyzolq.exe"
Report truncated due to excessive length. 2.2. VM2 (Windows 7, Adobe Reader 11, Flash 11, Office 2010)
2.2.1. Behavioral Summary This sample was found to be malware on this virtual machine.
Behavior Created a file in the Windows folder Created or modified files Spawned new processes Deleted itself Started or stopped a system service Registered a file as auto-start from a local directory Modified registries or system configuration to enable auto start capablity Modified Windows registries Created an executable file in a user document folder Attempted to sleep for a long period
2.2.2. Network Activity
No network data available.
25 / 32
2.2.3. Host ActivityProcess Name - "C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"(command: "C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe")
Process Name - "C:\Windows\system32\cmd.exe" /c"C:\Users\ADMINI~1\AppData\Local\Temp\tmp21df0dae.bat"(command: "C:\Windows\system32\cmd.exe" /c "C:\Users\ADMINI~1\AppData\Local\Temp\tmp21df0dae.bat")
1 Created Process C:\Users\Administrator\sample.exe2 Created mutex Global\{2E1D74D7-3CB9-1778-01A8-E27B2162028A}3 Created file C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe4 Created file C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe5 Created file C:\Windows\Tasks\Security Center Update - 3118959435.job6 Created service SecurityCenterServer3118959435 from "C:\Windows\system32\kaawali.exe" -service
"C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"7 Set key \REGISTRY\MACHINE\SOFTWARE\Xjhyfzdocs\License to value 4448 Set key \REGISTRY\USER\S-1-5-21-3965103109-1166398021-282280064-500\Software\Xjhyfzdocs\License to value 4449 Created Process "C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"10 Created mutex Local\{9404519C-19F2-AD61-01A8-E27B2162028A}11 Created file C:\Users\ADMINI~1\AppData\Local\Temp\tmp21df0dae.bat12 Created file C:\Users\ADMINI~1\AppData\Local\Temp\tmp21df0dae.bat13 Created mutex Global\{DE4482B9-CAD7-E721-01A8-E27B2162028A}14 Created mutex Local\{BFA234AE-7CC0-86C7-01A8-E27B2162028A}15 Created mutex Global\{64E4C08E-88E0-5D81-EC21-E721CCEB07D0}16 Created Process "C:\Windows\system32\cmd.exe" /c "C:\Users\ADMINI~1\AppData\Local\Temp\tmp21df0dae.bat"17 Deleted file C:\Users\Administrator\sample.exe18 Deleted file C:\Users\ADMINI~1\AppData\Local\Temp\tmp21df0dae.bat19 Created mutex20 Set key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Woakygemhet to value
"C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"21 Set key \REGISTRY\USER\S-1-5-21-3965103109-1166398021-282280064-500\Software\Microsoft\Windows\CurrentVersion\Run\Woa
kygemhet to value "C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"22 Created mutex ALTTAB_RUNNING_MUTEX23 Created mutex24 Created mutex25 Created mutex26 Created mutex27 Created mutex28 Created mutex29 Created mutex30 Created mutex31 Created mutex32 Created mutex33 Created mutex34 Created mutex35 Created mutex36 Created mutex37 Created mutex38 Created mutex39 Created mutex40 Created mutex41 Created mutex42 Created mutex43 Created mutex CDBurnNotify44 Created mutex Global\CDBurnExclusive45 Created Process "C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"46 Created mutex Local\{9404519C-19F2-AD61-01A8-E27B2162028A}47 Created mutex Global\{DE4482B9-CAD7-E721-01A8-E27B2162028A}48 Created mutex Local\{BFA234AE-7CC0-86C7-01A8-E27B2162028A}49 Created mutex Global\{64E4C08E-88E0-5D81-EC21-E721CCEB07D0}50 Created mutex Global\{64E4C08E-88E0-5D81-9C23-E721BCE907D0}51 Created Process "C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"52 Created mutex Local\{9404519C-19F2-AD61-01A8-E27B2162028A}53 Created mutex Global\{DE4482B9-CAD7-E721-01A8-E27B2162028A}54 Created mutex Local\{BFA234AE-7CC0-86C7-01A8-E27B2162028A}
30 / 32
55 Created mutex Global\{64E4C08E-88E0-5D81-EC21-E721CCEB07D0}56 Created mutex Global\{64E4C08E-88E0-5D81-9C23-E721BCE907D0}57 Created Process "C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"58 Created mutex Local\{9404519C-19F2-AD61-01A8-E27B2162028A}59 Created mutex Global\{DE4482B9-CAD7-E721-01A8-E27B2162028A}60 Created mutex Local\{BFA234AE-7CC0-86C7-01A8-E27B2162028A}61 Created mutex Global\{64E4C08E-88E0-5D81-EC21-E721CCEB07D0}62 Created mutex Global\{64E4C08E-88E0-5D81-9C23-E721BCE907D0}63 Created Process "C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"64 Created mutex Local\{9404519C-19F2-AD61-01A8-E27B2162028A}65 Created mutex Global\{DE4482B9-CAD7-E721-01A8-E27B2162028A}66 Created mutex Local\{BFA234AE-7CC0-86C7-01A8-E27B2162028A}67 Created mutex Global\{64E4C08E-88E0-5D81-EC21-E721CCEB07D0}68 Created mutex Global\{64E4C08E-88E0-5D81-9C23-E721BCE907D0}69 Created Process "C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"70 Created mutex Local\{9404519C-19F2-AD61-01A8-E27B2162028A}71 Created mutex Global\{DE4482B9-CAD7-E721-01A8-E27B2162028A}72 Created mutex Local\{BFA234AE-7CC0-86C7-01A8-E27B2162028A}73 Created mutex Global\{64E4C08E-88E0-5D81-EC21-E721CCEB07D0}74 Created mutex Global\{64E4C08E-88E0-5D81-9C23-E721BCE907D0}75 Created Process "C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"76 Created mutex Local\{9404519C-19F2-AD61-01A8-E27B2162028A}77 Created mutex Global\{DE4482B9-CAD7-E721-01A8-E27B2162028A}78 Created mutex Local\{BFA234AE-7CC0-86C7-01A8-E27B2162028A}79 Created mutex Global\{64E4C08E-88E0-5D81-EC21-E721CCEB07D0}80 Created mutex Global\{64E4C08E-88E0-5D81-9C23-E721BCE907D0}81 Created mutex82 Created mutex83 Created mutex84 Created mutex85 Created Process "C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"86 Created mutex Local\{9404519C-19F2-AD61-01A8-E27B2162028A}87 Created mutex Global\{DE4482B9-CAD7-E721-01A8-E27B2162028A}88 Created mutex Local\{BFA234AE-7CC0-86C7-01A8-E27B2162028A}89 Created mutex Global\{64E4C08E-88E0-5D81-EC21-E721CCEB07D0}90 Created mutex Global\{64E4C08E-88E0-5D81-9C23-E721BCE907D0}91 Created Process "C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"92 Created mutex Local\{9404519C-19F2-AD61-01A8-E27B2162028A}93 Created mutex Global\{DE4482B9-CAD7-E721-01A8-E27B2162028A}94 Created mutex Local\{BFA234AE-7CC0-86C7-01A8-E27B2162028A}95 Created mutex Global\{64E4C08E-88E0-5D81-EC21-E721CCEB07D0}96 Created mutex Global\{64E4C08E-88E0-5D81-9C23-E721BCE907D0}97 Set key \REGISTRY\USER\S-1-5-21-3965103109-1166398021-282280064-500\Software\Microsoft\Windows\CurrentVersion\Action
Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.103\CheckSetting to value NULL98 Set key \REGISTRY\USER\S-1-5-21-3965103109-1166398021-282280064-500\Software\Microsoft\Windows\CurrentVersion\Action
Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.100\CheckSetting to value NULL99 Set key \REGISTRY\USER\S-1-5-21-3965103109-1166398021-282280064-500\Software\Microsoft\Windows\CurrentVersion\Action
Center\Checks\{E8433B72-5842-4d43-8645-BC2C35960837}.check.102\CheckSetting to value NULL100 Created file C:\Users\Administrator\AppData\Local\Microsoft\Windows\WER\ERC\statecache.lock101 Deleted file C:\Users\Administrator\AppData\Local\Microsoft\Windows\WER\ERC\statecache.lock102 Set key \REGISTRY\USER\S-1-5-21-3965103109-1166398021-282280064-500\Software\Microsoft\Windows\CurrentVersion\Action
Center\Checks\{852FB1F8-5CC6-4567-9C0E-7C330F8807C2}.check.100\CheckSetting to value NULL103 Set key \REGISTRY\USER\S-1-5-21-3965103109-1166398021-282280064-500\Software\Microsoft\Windows\CurrentVersion\Action
Center\Checks\{852FB1F8-5CC6-4567-9C0E-7C330F8807C2}.check.101\CheckSetting to value NULL104 Set key \REGISTRY\USER\S-1-5-21-3965103109-1166398021-282280064-500\Software\Microsoft\Windows\CurrentVersion\Action
Center\Checks\{01979c6a-42fa-414c-b8aa-eee2c8202018}.check.100\CheckSetting to value NULL105 Created Process "C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"106 Created mutex Local\{9404519C-19F2-AD61-01A8-E27B2162028A}107 Created mutex Global\{DE4482B9-CAD7-E721-01A8-E27B2162028A}108 Created mutex Local\{BFA234AE-7CC0-86C7-01A8-E27B2162028A}109 Created mutex Global\{64E4C08E-88E0-5D81-EC21-E721CCEB07D0}110 Set key \REGISTRY\USER\S-1-5-21-3965103109-1166398021-282280064-500\Software\Microsoft\Windows\CurrentVersion\Action
Center\Checks\{945a8954-c147-4acd-923f-40c45405a658}.check.42\CheckSetting to value NULL111 Set key \REGISTRY\USER\S-1-5-21-3965103109-1166398021-282280064-500\Software\Microsoft\Windows\CurrentVersion\Action
Center\Checks\{945a8954-c147-4acd-923f-40c45405a658}.check.42\CheckSetting to value NULL112 Created Process "C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"113 Created mutex Local\{9404519C-19F2-AD61-01A8-E27B2162028A}114 Created mutex Global\{DE4482B9-CAD7-E721-01A8-E27B2162028A}
31 / 32
115 Created mutex Local\{BFA234AE-7CC0-86C7-01A8-E27B2162028A}116 Created mutex Global\{64E4C08E-88E0-5D81-EC21-E721CCEB07D0}117 Created Process "C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"118 Created mutex Local\{9404519C-19F2-AD61-01A8-E27B2162028A}119 Created mutex Global\{DE4482B9-CAD7-E721-01A8-E27B2162028A}120 Created mutex Local\{BFA234AE-7CC0-86C7-01A8-E27B2162028A}121 Created mutex Global\{64E4C08E-88E0-5D81-EC21-E721CCEB07D0}122 Created Process "C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"123 Created mutex Local\{9404519C-19F2-AD61-01A8-E27B2162028A}124 Created mutex Global\{DE4482B9-CAD7-E721-01A8-E27B2162028A}125 Created mutex Local\{BFA234AE-7CC0-86C7-01A8-E27B2162028A}126 Created mutex Global\{64E4C08E-88E0-5D81-EC21-E721CCEB07D0}127 Created Process "C:\Users\Administrator\AppData\Roaming\Etuqedi\acysn.exe"128 Created mutex Local\{9404519C-19F2-AD61-01A8-E27B2162028A}129 Created mutex Global\{DE4482B9-CAD7-E721-01A8-E27B2162028A}130 Created mutex Local\{BFA234AE-7CC0-86C7-01A8-E27B2162028A}131 Created mutex Global\{64E4C08E-88E0-5D81-EC21-E721CCEB07D0}