|
file
|
04/25 19:21:48
|
C:\Program Files\Internet Explorer\IEXPLORE.EXE
|
C:\WINDOWS\Temp\updates.exe
|
-
|
|
|
file
|
04/25 19:21:49
|
C:\WINDOWS\Temp\updates.exe
|
C:\Documents and Settings\******\Local Settings\Application Data\Windows Server\pqsidx.dll
|
-
|
|
|
registry
|
04/25 19:21:49
|
C:\WINDOWS\Temp\updates.exe
|
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Local AppData
|
-
|
|
|
registry
|
04/25 19:21:49
|
C:\WINDOWS\Temp\updates.exe
|
HKCU\Software\cobupqsidx\cobupqsidx
|
-
|
|
|
registry
|
04/25 19:21:49
|
C:\WINDOWS\Temp\updates.exe
|
HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls\AppSecDll
|
-
|
|
|
registry
|
04/25 19:21:49
|
C:\WINDOWS\Temp\updates.exe
|
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Templates
|
-
|
|
|
registry
|
04/25 19:21:49
|
C:\WINDOWS\Temp\updates.exe
|
HKLM\SYSTEM\ControlSet001\Control\Session Manager\PendingFileRenameOperations
|
-
|
|
|
registry
|
04/25 19:21:49
|
C:\WINDOWS\Temp\updates.exe
|
HKLM\SYSTEM\ControlSet001\Services\sr\Parameters\FirstRun
|
-
|
|
|
registry
|
04/25 19:21:49
|
C:\WINDOWS\Temp\updates.exe
|
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\DisableSR
|
-
|
|
|
registry
|
04/25 19:21:51
|
C:\Program Files\Internet Explorer\IEXPLORE.EXE
|
HKCU\Software\cobupqsidx\Run
|
-
|
|
|
registry
|
04/25 19:21:51
|
C:\Program Files\Internet Explorer\IEXPLORE.EXE
|
HKCU\Software\cobupqsidx\ID
|
-
|
|
|
process
|
04/25 19:21:49
|
UNKNOWN
|
C:\WINDOWS\Temp\updates.exe
|
-
|
|
|
registry
|
04/25 19:21:52
|
C:\WINDOWS\explorer.exe
|
HKCU\Software\cobupqsidx\cobupqsidx
|
-
|
|
|
process
|
04/25 19:21:49
|
C:\Program Files\Internet Explorer\IEXPLORE.EXE
|
C:\WINDOWS\Temp\updates.exe
|
-
|
|
|
registry
|
04/25 19:21:52
|
C:\Program Files\Internet Explorer\IEXPLORE.EXE
|
HKCU\Software\cobupqsidx\Run
|
-
|
|
|
registry
|
04/25 19:21:52
|
C:\Program Files\Internet Explorer\IEXPLORE.EXE
|
HKCU\Software\cobupqsidx\TimeGetWork
|
-
|
|
|
file
|
04/25 19:21:52
|
C:\Program Files\Internet Explorer\IEXPLORE.EXE
|
C:\feed.txt
|
-
|
|
|
registry
|
04/25 19:22:12
|
C:\WINDOWS\explorer.exe
|
HKCU\Software\cobupqsidx\cobupqsidx
|
-
|
|