XPSecurityCenter

XPSecurityCenter

Found: 
2008-06-02
Known system changes: 

Created Files

  • %Temp%Binaries3.zip
  • c:\Temp\Binaries1.zip
  • c:\Temp\Binaries2.zip
  • c:\Temp\Binaries3.zip
  • %Temp%Binaries1.zip
  • %Temp%Binaries2.zip
  • %Desktop%XPSecurityCenter.lnk
  • %CommonProgramFiles%ratywyk.ban
  • %CommonProgramFiles%yzem.bin
  • %CommonProgramFiles%ygideze.dat
  • %CommonProgramFiles%jodarota.scr
  • %CommonProgramFiles%abopev.sys
  • %CommonProgramFiles%gagejemoj.sys
  • %Windir%reny._dl
  • %Windir%funato.ban
  • %Windir%hefomerox.reg
  • %Windir%bidami.scr
  • %System%lega.db
  • %System%udozuw.db
  • %CommonDesktop%XPSecurityCenter.lnk
  • %CommonStartMenu%Program\XPSecurityCenter
  • %CommonStartMenu%Programs\XPSecurityCenter
  • %CommonDesktop%XPSecurityCenter..lnk
  • %Desktop%XPSecurityCenter..lnk
  • %CommonDesktop%XPSecurityCenter.lnk

Created Folders

  • %ProgramFiles%XPSecurityCenter
  • %CommonPrograms%XPSecurityCenter
  • %CommonStartMenu%Programs\XPSecurityCenter
  • %ProgramFiles%XPSecurityCenter
  • %CommonStartMenu%XPSecurityCenter
  • %CommonStartMenu%Program\XPSecurityCenter
  • %CommonStartMenu%Programs\XPSecurityCenter
  • %CommonStartMenu%Program\XPSecurityCenter

Registry Entries

  • Key: HKEY_LOCAL_MACHINE\software\xp_securitycenter
  • Value:
  • Data:
  • Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
  • Value: xp securitycenter
  • Data:
  • Key: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\menuorder\start menu\programs\xpsecuritycenter
  • Value:
  • Data:
  • Key: HKEY_CURRENT_USER\software\microsoft\security center
  • Value: antivirusdisablenotify
  • Data:
  • Key: HKEY_CURRENT_USER\software\microsoft\security center
  • Value: firewalldisablenotify
  • Data:
  • Key: HKEY_CURRENT_USER\software\microsoft\security center
  • Value: updatesdisablenotify
  • Data:
  • Key: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\runmru
  • Value: c
  • Data:
  • Key: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\menuorder\start menu\programs\lavasoft
  • Value:
  • Data: