Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Attempted file edits/reads
- C:\WINDOWS\_default.pif
- C:\DosDevices\A:
- C:\DosDevices\B:
- C:\MSDOS.SYS
- C:\IO.SYS
- C:\WINDOWS\system32\ntio.sys
- C:\WINDOWS\system32\ntdos.sys
- C:\
- C:\WINDOWS\SYSTEM32\CONFIG.NT
- C:\WINDOWS\TEMP\scs1.tmp
- C:\WINDOWS\TEMP\SCS1.TMP
- C:\WINDOWS\SYSTEM32\HIMEM.SYS
- C:\WINDOWS\SYSTEM32\COUNTRY.SYS
- C:\DosDevices\C:
- C:\WINDOWS\SYSTEM32\COMMAND.COM
- C:\WINDOWS\SYSTEM32
- C:\WINDOWS\SYSTEM32\AUTOEXEC.NT
- C:\WINDOWS\TEMP\scs2.tmp
- C:\WINDOWS\TEMP\SCS2.TMP
- C:\Documents and Settings
- C:\Documents and Settings\All Users
- C:\Documents and Settings\User\Application Data
- C:\Program Files
- C:\Program Files\Common Files
- MSCDEXNT.EXE
- C:\WINDOWS\SYSTEM32\MSCDEXNT.EXE
- REDIR">>>
- C:\WINDOWS\SYSTEM32\REDIR.EXE
- DOSX">>>
- C:\WINDOWS\SYSTEM32\DOSX.EXE
- C:\WINDOWS\SYSTEM.INI
- C:\DOCUME~1\User\LOCALS~1\Temp
- C:\DOCUME~1\USER\LOCALS~1\TEMP\RAIDCA~1.EXE
- A:
- B:
- E:
- F:
- G:
- H:
- I:
- J:
- K:
- L:
- M:
- N:
- O:
- P:
- Q:
- R:
- S:
- T:
- U:
- V:
- W:
- X:
- Y:
- Z:
- REG Keys modified;
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Wow\CpuEnv
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\WOW\Console
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WOW
- HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\SYSTEM
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Setup
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server
- HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement