TROJ_NSIS.AE
PWS:Win32/Fignotok.A (Microsoft); [2.nsis]:Generic.dx!fjp (McAfee); W32.Spybot.Worm (Symantec); ARC:NSIS, [data0002]:Trojan.Win32.VB.uqe, [data0002]:Trojan.Win32.VB.uqe, ARC:[data0003]:RAR (Kaspersky); Trojan.Win32.VBInject.gen (v) (Sunbelt); Trojan.Dropper.Agent.VCO (FSecure)
Windows 2000, Windows XP, Windows Server 2003
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
3,367,872 bytes
EXE
No
14 Nov 2011
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan creates the following folders:
- %System Root%\DOCUME~1
- %System Root%\DOCUME~1\ADMINI~1
- %User Profile%\LOCALS~1
- %User Temp%\RarSFX0
- files
- files\ABIT
- files\ABIT\info
- files\Acer
- files\Acer\info
- files\ADVENT
- files\ADVENT\info
- files\ALIENWARE
- files\ALIENWARE\info
- files\AMD
- files\AMD\info
- files\AMDPH2
- files\AMDPH2\info
- files\AMDPH3
- files\AMDPH3\info
- files\AMDSemp
- files\AMDSemp\info
- files\AMDX2
- files\AMDX2\info
- files\AOPEN
- files\AOPEN\info
- files\APPLE
- files\APPLE\info
- files\ASROCK
- files\ASROCK\info
- files\ASUS
- files\ASUS\info
- files\ATI
- files\ATI\info
- files\BenQ
- files\BenQ\info
- files\BIOSTAR
- files\BIOSTAR\info
- files\certs
- files\Compal
- files\Compal\info
- files\Compaq
- files\Compaq\info
- files\Dell
- files\Dell\info
- files\DFI
- files\DFI\info
- files\ECS
- files\ECS\info
- files\eMachines
- files\eMachines\info
- files\EPOX
- files\EPOX\info
- files\FOUNDER
- files\FOUNDER\info
- files\Fujitsu
- files\Fujitsu\info
- files\Gateway
- files\Gateway\info
- files\GIGABYTE
- files\GIGABYTE\info
- files\HP
- files\HP\info
- files\IBM
- files\IBM\info
- files\INTELCore2
- files\INTELCore2\info
- files\INTELCore2Q
- files\INTELCore2Q\info
- files\INTELViiv
- files\INTELViiv\info
- files\Lenovo
- files\Lenovo\info
- files\LG
- files\LG\info
- files\MDG
- files\MDG\info
- files\Medion
- files\Medion\info
- files\Mercury
- files\Mercury\info
- files\MSI
- files\MSI\info
- files\NEC
- files\NEC\info
- files\NEO
- files\NEO\info
- files\Nvidia
- files\Nvidia\info
- files\NvidiaSLI
- files\NvidiaSLI\info
- files\NvidiaXFX
- files\NvidiaXFX\info
- files\PB
- files\PB\info
- files\Samsung
- files\Samsung\info
- files\SONY
- files\SONY\info
- files\Toshiba
- files\Toshiba\info
- files\Viglen
- files\Viglen\info
- files\XPC
- files\XPC\info
(Note: %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.. %User Profile% is the current user's profile folder, which is usually C:\Windows\Profiles\{user name} on Windows 98 and ME, C:\WINNT\Profiles\{user name} on Windows NT, and C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003.. %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
Other System Modifications
This Trojan deletes the following files:
- %User Temp%\nsv1.tmp
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
Dropping Routine
This Trojan drops the following files:
- %User Temp%\ftp.exe
- %User Temp%\7loader 1.5.exe
- __tmp_rar_sfx_access_check_45390
- oem.exe
- files\ABIT\info\ABITLOGO.GIF
- files\ABIT\info\ABIT_BADGE.BMP
- files\ABIT\info\ABIT_BADGE.PNG
- files\ABIT\info\ABIT_BAR.PNG
- files\ABIT\info\ABIT_LOGO.PNG
- files\ABIT\info\ABIT_MCE_LOGO.PNG
- files\ABIT\info\OOBE.XML
- files\Acer\info\ACERLOGO.GIF
- files\Acer\info\ACER_BADGE.BMP
- files\Acer\info\ACER_BADGE.PNG
- files\Acer\info\ACER_BAR.PNG
- files\Acer\info\ACER_LOGO.PNG
- files\Acer\info\ACER_MCE_LOGO.PNG
- files\Acer\info\OOBE.XML
- files\ADVENT\info\ADVENTLOGO.GIF
- files\ADVENT\info\ADVENT_BADGE.BMP
- files\ADVENT\info\ADVENT_BADGE.PNG
- files\ADVENT\info\ADVENT_BAR.PNG
- files\ADVENT\info\ADVENT_LOGO.PNG
- files\ADVENT\info\ADVENT_MCE_LOGO.PNG
- files\ADVENT\info\OOBE.XML
- files\ALIENWARE\info\ALIENWARELOGO.GIF
- files\ALIENWARE\info\ALIENWARE_BADGE.BMP
- files\ALIENWARE\info\ALIENWARE_BADGE.PNG
- files\ALIENWARE\info\ALIENWARE_BAR.PNG
- files\ALIENWARE\info\ALIENWARE_LOGO.PNG
- files\ALIENWARE\info\ALIENWARE_MCE_LOGO.PNG
- files\ALIENWARE\info\OOBE.XML
- files\AMD\info\AMDLOGO.GIF
- files\AMD\info\AMD_BADGE.BMP
- files\AMD\info\AMD_BADGE.PNG
- files\AMD\info\AMD_BAR.PNG
- files\AMD\info\AMD_LOGO.PNG
- files\AMD\info\AMD_MCE_LOGO.PNG
- files\AMD\info\OOBE.XML
- files\AMDPH2\info\AMDLOGO.GIF
- files\AMDPH2\info\AMD_BADGE.bmp
- files\AMDPH2\info\AMD_BADGE.PNG
- files\AMDPH2\info\AMD_BAR.PNG
- files\AMDPH2\info\AMD_LOGO.PNG
- files\AMDPH2\info\AMD_MCE_LOGO.PNG
- files\AMDPH2\info\OOBE.XML
- files\AMDPH3\info\AMDLOGO.GIF
- files\AMDPH3\info\AMD_BADGE.bmp
- files\AMDPH3\info\AMD_BADGE.PNG
- files\AMDPH3\info\AMD_BAR.PNG
- files\AMDPH3\info\AMD_LOGO.PNG
- files\AMDPH3\info\AMD_MCE_LOGO.PNG
- files\AMDPH3\info\OOBE.XML
- files\AMDSemp\info\AMDLOGO.GIF
- files\AMDSemp\info\AMD_BADGE.BMP
- files\AMDSemp\info\AMD_BADGE.PNG
- files\AMDSemp\info\AMD_BAR.PNG
- files\AMDSemp\info\AMD_LOGO.PNG
- files\AMDSemp\info\AMD_MCE_LOGO.PNG
- files\AMDSemp\info\OOBE.XML
- files\AMDX2\info\AMDLOGO.GIF
- files\AMDX2\info\AMD_BADGE.BMP
- files\AMDX2\info\AMD_BADGE.PNG
- files\AMDX2\info\AMD_BAR.PNG
- files\AMDX2\info\AMD_LOGO.PNG
- files\AMDX2\info\AMD_MCE_LOGO.PNG
- files\AMDX2\info\OOBE.XML
- files\AOPEN\info\AOPENLOGO.GIF
- files\AOPEN\info\AOPEN_BADGE.BMP
- files\AOPEN\info\AOPEN_BADGE.PNG
- files\AOPEN\info\AOPEN_BAR.PNG
- files\AOPEN\info\AOPEN_LOGO.PNG
- files\AOPEN\info\AOPEN_MCE_LOGO.PNG
- files\AOPEN\info\OOBE.XML
- files\APPLE\info\APPLELOGO.GIF
- files\APPLE\info\APPLE_BADGE.BMP
- files\APPLE\info\APPLE_BADGE.PNG
- files\APPLE\info\APPLE_BAR.PNG
- files\APPLE\info\APPLE_LOGO.PNG
- files\APPLE\info\APPLE_MCE_LOGO.PNG
- files\APPLE\info\OOBE.XML
- files\ASROCK\info\ASROCKLOGO.GIF
- files\ASROCK\info\ASROCK_BADGE.BMP
- files\ASROCK\info\ASROCK_BADGE.PNG
- files\ASROCK\info\ASROCK_BAR.PNG
- files\ASROCK\info\ASROCK_LOGO.PNG
- files\ASROCK\info\ASROCK_MCE_LOGO.PNG
- files\ASROCK\info\OOBE.XML
- files\ASUS\info\ASUSLOGO.GIF
- files\ASUS\info\ASUS_BADGE.BMP
- files\ASUS\info\ASUS_BADGE.PNG
- files\ASUS\info\ASUS_BAR.PNG
- files\ASUS\info\ASUS_LOGO.PNG
- files\ASUS\info\ASUS_MCE_LOGO.PNG
- files\ASUS\info\OOBE.XML
- files\ATI\info\ATILOGO.GIF
- files\ATI\info\ATI_BADGE.BMP
- files\ATI\info\ATI_BADGE.PNG
- files\ATI\info\ATI_BAR.PNG
- files\ATI\info\ATI_LOGO.PNG
- files\ATI\info\ATI_MCE_LOGO.PNG
- files\ATI\info\OOBE.XML
- files\BenQ\info\BENQLOGO.GIF
- files\BenQ\info\BenQ_BADGE.BMP
- files\BenQ\info\BENQ_BADGE.PNG
- files\BenQ\info\BenQ_BAR.PNG
- files\BenQ\info\BENQ_LOGO.PNG
- files\BenQ\info\BenQ_MCE_LOGO.PNG
- files\BenQ\info\OOBE.XML
- files\BIOSTAR\info\BIOSTARLOGO.GIF
- files\BIOSTAR\info\BIOSTAR_BADGE.BMP
- files\BIOSTAR\info\BIOSTAR_BADGE.PNG
- files\BIOSTAR\info\BIOSTAR_BAR.PNG
- files\BIOSTAR\info\BIOSTAR_LOGO.PNG
- files\BIOSTAR\info\BIOSTAR_MCE_LOGO.PNG
- files\BIOSTAR\info\OOBE.XML
- files\certs\ACER.XRM-MS
- files\certs\ACRSYSACRPRDCT.XRM-MS
- files\certs\ADVENT-DSGLTD.XRM-MS
- files\certs\ALIENWARE.XRM-MS
- files\certs\ASUS.XRM-MS
- files\certs\AVERATEC-TRIGEM.XRM-MS
- files\certs\BENQ.XRM-MS
- files\certs\COMPAQ-HP.XRM-MS
- files\certs\DEALIN-DEPO.XRM-MS
- files\certs\DELL.XRM-MS
- files\certs\DELLB8K.XRM-MS
- files\certs\EMACHINE-GATEWAY.XRM-MS
- files\certs\EVEREX-FIC.XRM-MS
- files\certs\FOUNDER.XRM-MS
- files\certs\FOUNDRFOUNDRPC.XRM-MS
- files\certs\FSCPC.xrm-ms
- files\certs\FUJITSU-SIEMENS.XRM-MS
- files\certs\FUJITSU.XRM-MS
- files\certs\GATEWASYSTEMv1.xrm-ms
- files\certs\GATEWASYSTEMv2.xrm-ms
- files\certs\GATEWAY.XRM-MS
- files\certs\GERICOM.XRM-MS
- files\certs\GIGABYTE.XRM-MS
- files\certs\GREATWALL.XRM-MS
- files\certs\HAIER.XRM-MS
- files\certs\HASEE.XRM-MS
- files\certs\HEDY.XRM-MS
- files\certs\HP-PROLIANT.XRM-MS
- files\certs\HPQOEMSLIC-CPC.XRM-MS
- files\certs\HPQOEMSLIC-MPC.XRM-MS
- files\certs\IBM-LENOVO.XRM-MS
- files\certs\KOUZIRO-FRONTIER.XRM-MS
- files\certs\KSYSTEMS-IRBIS.XRM-MS
- files\certs\LENOVO.XRM-MS
- files\certs\LENOVOTC-03.XRM-MS
- files\certs\LENOVOTC-2P.XRM-MS
- files\certs\LENOVOTP-79.XRM-MS
- files\certs\LG.XRM-MS
- files\certs\MEDION.XRM-MS
- files\certs\MEDIONAGv1.xrm-ms
- files\certs\MEDIONAGv2.xrm-ms
- files\certs\MESHPC.XRM-MS
- files\certs\MSI.XRM-MS
- files\certs\NEC.XRM-MS
- files\certs\NECCAP.XRM-MS
- files\certs\NECND000146.xrm-ms
- files\certs\NECND000147.xrm-ms
- files\certs\oemcert.XRM-MS
- files\certs\OQO.XRM-MS
- files\certs\PACKARDBELL.XRM-MS
- files\certs\PANASONIC.XRM-MS
- files\certs\POWERSPEC.XRM-MS
- files\certs\ROVERCOMPUTERS.XRM-MS
- files\certs\SAMSUNG.XRM-MS
- files\certs\SECCSDLH43STAR.XRM-MS
- files\certs\SHARP.XRM-MS
- files\certs\SONY.XRM-MS
- files\certs\SYSTEMAX.XRM-MS
- files\certs\TARGA.XRM-MS
- files\certs\TCL.XRM-MS
- files\certs\TONGFANG.XRM-MS
- files\certs\TOSHIBA-A0037.XRM-MS
- files\certs\TOSHIBA-ASU00.XRM-MS
- files\certs\TOSHIBA-CPL00.XRM-MS
- files\certs\TOSHIBA-INV00.XRM-MS
- files\certs\TOSHIBA-QCI00.XRM-MS
- files\certs\TOSINVTOSINV00.xrm-ms
- files\certs\TOSQCITOSQCI00.XRM-MS
- files\certs\VELOCITYMICRO.XRM-MS
- files\Compal\info\COMPALLOGO.GIF
- files\Compal\info\COMPAL_BADGE.BMP
- files\Compal\info\COMPAL_BADGE.PNG
- files\Compal\info\COMPAL_BAR.PNG
- files\Compal\info\COMPAL_LOGO.PNG
- files\Compal\info\COMPAL_MCE_LOGO.PNG
- files\Compal\info\OOBE.XML
- files\Compaq\info\COMPAQLOGO.GIF
- files\Compaq\info\COMPAQ_BADGE.BMP
- files\Compaq\info\COMPAQ_BADGE.PNG
- files\Compaq\info\COMPAQ_BAR.PNG
- files\Compaq\info\COMPAQ_LOGO.PNG
- files\Compaq\info\COMPAQ_MCE_LOGO.PNG
- files\Compaq\info\OOBE.XML
- files\Dell\info\DELLLOGO.GIF
- files\Dell\info\DELL_BADGE.BMP
- files\Dell\info\DELL_BADGE.PNG
- files\Dell\info\DELL_BAR.PNG
- files\Dell\info\DELL_LOGO.PNG
- files\Dell\info\DELL_MCE_LOGO.PNG
- files\Dell\info\OOBE.XML
- files\DFI\info\DFILOGO.GIF
- files\DFI\info\DFI_BADGE.BMP
- files\DFI\info\DFI_BADGE.PNG
- files\DFI\info\DFI_BAR.PNG
- files\DFI\info\DFI_LOGO.PNG
- files\DFI\info\DFI_MCE_LOGO.PNG
- files\DFI\info\OOBE.XML
- files\ECS\info\ECSLOGO.GIF
- files\ECS\info\ECS_BADGE.BMP
- files\ECS\info\ECS_BADGE.PNG
- files\ECS\info\ECS_BAR.PNG
- files\ECS\info\ECS_LOGO.PNG
- files\ECS\info\ECS_MCE_LOGO.PNG
- files\ECS\info\OOBE.XML
- files\eMachines\info\EMACHINESLOGO.GIF
- files\eMachines\info\EMACHINES_BADGE.BMP
- files\eMachines\info\EMACHINES_BADGE.PNG
- files\eMachines\info\EMACHINES_BAR.PNG
- files\eMachines\info\EMACHINES_LOGO.PNG
- files\eMachines\info\EMACHINES_MCE_LOGO.PNG
- files\eMachines\info\OOBE.XML
- files\EPOX\info\EPOXLOGO.GIF
- files\EPOX\info\EPOX_BADGE.BMP
- files\EPOX\info\EPOX_BADGE.PNG
- files\EPOX\info\EPOX_BAR.PNG
- files\EPOX\info\EPOX_LOGO.PNG
- files\EPOX\info\EPOX_MCE_LOGO.PNG
- files\EPOX\info\OOBE.XML
- files\FOUNDER\info\FOUNDERLOGO.GIF
- files\FOUNDER\info\FOUNDER_BADGE.BMP
- files\FOUNDER\info\FOUNDER_BADGE.PNG
- files\FOUNDER\info\FOUNDER_BAR.PNG
- files\FOUNDER\info\FOUNDER_LOGO.PNG
- files\FOUNDER\info\FOUNDER_MCE_LOGO.PNG
- files\FOUNDER\info\OOBE.XML
- files\Fujitsu\info\FUJITSULOGO.GIF
- files\Fujitsu\info\FUJITSU_BADGE.BMP
- files\Fujitsu\info\FUJITSU_BADGE.PNG
- files\Fujitsu\info\FUJITSU_BAR.PNG
- files\Fujitsu\info\FUJITSU_LOGO.PNG
- files\Fujitsu\info\FUJITSU_MCE_LOGO.PNG
- files\Fujitsu\info\OOBE.XML
- files\Gateway\info\GATEWAYLOGO.GIF
- files\Gateway\info\GATEWAY_BADGE.BMP
- files\Gateway\info\GATEWAY_BADGE.PNG
- files\Gateway\info\GATEWAY_BAR.PNG
- files\Gateway\info\GATEWAY_LOGO.PNG
- files\Gateway\info\GATEWAY_MCE_LOGO.PNG
- files\Gateway\info\OOBE.XML
- files\GIGABYTE\info\GYGABYTELOGO.GIF
- files\GIGABYTE\info\GYGABYTE_BADGE.BMP
- files\GIGABYTE\info\GYGABYTE_BADGE.PNG
- files\GIGABYTE\info\GYGABYTE_BAR.PNG
- files\GIGABYTE\info\GYGABYTE_LOGO.PNG
- files\GIGABYTE\info\GYGABYTE_MCE_LOGO.PNG
- files\GIGABYTE\info\OOBE.XML
- files\HP\info\HPLOGO.GIF
- files\HP\info\HP_BADGE.BMP
- files\HP\info\HP_BADGE.PNG
- files\HP\info\HP_BAR.PNG
- files\HP\info\HP_LOGO.PNG
- files\HP\info\HP_MCE_LOGO.PNG
- files\HP\info\OOBE.XML
- files\IBM\info\IBMLOGO.GIF
- files\IBM\info\IBM_BADGE.BMP
- files\IBM\info\IBM_BADGE.PNG
- files\IBM\info\IBM_BAR.PNG
- files\IBM\info\IBM_LOGO.PNG
- files\IBM\info\IBM_MCE_LOGO.PNG
- files\IBM\info\OOBE.XML
- files\INTELCore2\info\INTELLOGO.GIF
- files\INTELCore2\info\INTEL_BADGE.BMP
- files\INTELCore2\info\INTEL_BADGE.PNG
- files\INTELCore2\info\INTEL_BAR.PNG
- files\INTELCore2\info\INTEL_LOGO.PNG
- files\INTELCore2\info\INTEL_MCE_LOGO.PNG
- files\INTELCore2\info\OOBE.XML
- files\INTELCore2Q\info\INTELLOGO.GIF
- files\INTELCore2Q\info\INTEL_BADGE.bmp
- files\INTELCore2Q\info\INTEL_BADGE.PNG
- files\INTELCore2Q\info\INTEL_BAR.PNG
- files\INTELCore2Q\info\INTEL_LOGO.PNG
- files\INTELCore2Q\info\INTEL_MCE_LOGO.PNG
- files\INTELCore2Q\info\OOBE.XML
- files\INTELViiv\info\INTELLOGO.GIF
- files\INTELViiv\info\INTEL_BADGE.BMP
- files\INTELViiv\info\INTEL_BADGE.PNG
- files\INTELViiv\info\INTEL_BAR.PNG
- files\INTELViiv\info\INTEL_LOGO.PNG
- files\INTELViiv\info\INTEL_MCE_LOGO.PNG
- files\INTELViiv\info\OOBE.XML
- files\Lenovo\info\LENOVOLOGO.GIF
- files\Lenovo\info\LENOVO_BADGE.BMP
- files\Lenovo\info\LENOVO_BADGE.PNG
- files\Lenovo\info\LENOVO_BAR.PNG
- files\Lenovo\info\LENOVO_LOGO.PNG
- files\Lenovo\info\LENOVO_MCE_LOGO.PNG
- files\Lenovo\info\OOBE.XML
- files\LG\info\LGLOGO.GIF
- files\LG\info\LG_BADGE.BMP
- files\LG\info\LG_BADGE.PNG
- files\LG\info\LG_BAR.PNG
- files\LG\info\LG_LOGO.PNG
- files\LG\info\LG_MCE_LOGO.PNG
- files\LG\info\OOBE.XML
- files\MDG\info\MDGLOGO.GIF
- files\MDG\info\MDG_BADGE.BMP
- files\MDG\info\MDG_BADGE.PNG
- files\MDG\info\MDG_BAR.PNG
- files\MDG\info\MDG_LOGO.PNG
- files\MDG\info\MDG_MCE_LOGO.PNG
- files\MDG\info\OOBE.XML
- files\Medion\info\MEDIONLOGO.gif
- files\Medion\info\MEDION_BADGE.BMP
- files\Medion\info\MEDION_BADGE.PNG
- files\Medion\info\medion_bar.png
- files\Medion\info\MEDION_LOGO.PNG
- files\Medion\info\MEDION_MCE_LOGO.PNG
- files\Medion\info\OOBE.XML
- files\Mercury\info\MERCURYLOGO.GIF
- files\Mercury\info\MERCURY_BADGE.BMP
- files\Mercury\info\MERCURY_BADGE.PNG
- files\Mercury\info\MERCURY_BAR.PNG
- files\Mercury\info\MERCURY_LOGO.PNG
- files\Mercury\info\MERCURY_MCE_LOGO.PNG
- files\Mercury\info\OOBE.XML
- files\MSI\info\MSILOGO.GIF
- files\MSI\info\MSI_BADGE.BMP
- files\MSI\info\MSI_BADGE.PNG
- files\MSI\info\MSI_BAR.PNG
- files\MSI\info\MSI_LOGO.PNG
- files\MSI\info\MSI_MCE_LOGO.PNG
- files\MSI\info\OOBE.XML
- files\NEC\info\NECLOGO.GIF
- files\NEC\info\NEC_BADGE.BMP
- files\NEC\info\NEC_BADGE.PNG
- files\NEC\info\NEC_BAR.PNG
- files\NEC\info\NEC_LOGO.PNG
- files\NEC\info\NEC_MCE_LOGO.PNG
- files\NEC\info\OOBE.XML
- files\NEO\info\NEOLOGO.GIF
- files\NEO\info\NEO_BADGE.BMP
- files\NEO\info\NEO_BADGE.PNG
- files\NEO\info\NEO_BAR.PNG
- files\NEO\info\NEO_LOGO.PNG
- files\NEO\info\NEO_MCE_LOGO.PNG
- files\NEO\info\OOBE.XML
- files\Nvidia\info\NVIDIALOGO.GIF
- files\Nvidia\info\NVIDIA_BADGE.BMP
- files\Nvidia\info\NVIDIA_BADGE.PNG
- files\Nvidia\info\NVIDIA_BAR.PNG
- files\Nvidia\info\NVIDIA_LOGO.PNG
- files\Nvidia\info\NVIDIA_MCE_LOGO.PNG
- files\Nvidia\info\OOBE.XML
- files\NvidiaSLI\info\NVIDIALOGO.GIF
- files\NvidiaSLI\info\NVIDIA_BADGE.BMP
- files\NvidiaSLI\info\NVIDIA_BADGE.PNG
- files\NvidiaSLI\info\NVIDIA_BAR.PNG
- files\NvidiaSLI\info\NVIDIA_LOGO.PNG
- files\NvidiaSLI\info\NVIDIA_MCE_LOGO.PNG
- files\NvidiaSLI\info\OOBE.XML
- files\NvidiaXFX\info\NVIDIALOGO.GIF
- files\NvidiaXFX\info\NVIDIA_BADGE.bmp
- files\NvidiaXFX\info\NVIDIA_BADGE.png
- files\NvidiaXFX\info\NVIDIA_BAR.PNG
- files\NvidiaXFX\info\NVIDIA_LOGO.PNG
- files\NvidiaXFX\info\NVIDIA_MCE_LOGO.PNG
- files\NvidiaXFX\info\OOBE.XML
- files\PB\info\OOBE.XML
- files\PB\info\PACKARDBELLLOGO.GIF
- files\PB\info\PACKARDBELL_BADGE.BMP
- files\PB\info\PACKARDBELL_BADGE.PNG
- files\PB\info\PACKARDBELL_BAR.PNG
- files\PB\info\PACKARDBELL_LOGO.PNG
- files\PB\info\PACKARDBELL_MCE_LOGO.PNG
- files\Samsung\info\OOBE.XML
- files\Samsung\info\SAMSUNGLOGO.GIF
- files\Samsung\info\SAMSUNG_BADGE.BMP
- files\Samsung\info\SAMSUNG_BADGE.PNG
- files\Samsung\info\SAMSUNG_BAR.PNG
- files\Samsung\info\SAMSUNG_LOGO.PNG
- files\Samsung\info\SAMSUNG_MCE_LOGO.PNG
- files\SONY\info\OOBE.XML
- files\SONY\info\VAIOLOGO.GIF
- files\SONY\info\VAIO_BADGE.BMP
- files\SONY\info\VAIO_BADGE.PNG
- files\SONY\info\VAIO_BAR.PNG
- files\SONY\info\VAIO_LOGO.PNG
- files\SONY\info\VAIO_MCE_LOGO.PNG
- files\Toshiba\info\OOBE.XML
- files\Toshiba\info\TOSHIBALOGO.GIF
- files\Toshiba\info\TOSHIBA_BADGE.BMP
- files\Toshiba\info\TOSHIBA_BADGE.PNG
- files\Toshiba\info\TOSHIBA_BAR.PNG
- files\Toshiba\info\TOSHIBA_LOGO.PNG
- files\Toshiba\info\TOSHIBA_MCE_LOGO.PNG
- files\Viglen\info\OOBE.XML
- files\Viglen\info\VIGLENLOGO.GIF
- files\Viglen\info\VIGLEN_BADGE.BMP
- files\Viglen\info\VIGLEN_BADGE.PNG
- files\Viglen\info\VIGLEN_BAR.PNG
- files\Viglen\info\VIGLEN_LOGO.PNG
- files\Viglen\info\VIGLEN_MCE_LOGO.PNG
- files\XPC\info\OOBE.XML
- files\XPC\info\XPCLOGO.GIF
- files\XPC\info\XPC_BADGE.BMP
- files\XPC\info\XPC_BADGE.PNG
- files\XPC\info\XPC_BAR.PNG
- files\XPC\info\XPC_LOGO.PNG
- files\XPC\info\XPC_MCE_LOGO.PNG
- files\Compaq\info\Compaq_BAR.bmp
- files\Compaq\info\Thumbs.db
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)
This report is generated via an automated analysis system.
SOLUTION
9.200
Step 1
For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.
Step 2
Search and delete these folders
- %System Root%\DOCUME~1
- %System Root%\DOCUME~1\ADMINI~1
- %User Profile%\LOCALS~1
- %User Temp%\RarSFX0
- files
- files\ABIT
- files\ABIT\info
- files\Acer
- files\Acer\info
- files\ADVENT
- files\ADVENT\info
- files\ALIENWARE
- files\ALIENWARE\info
- files\AMD
- files\AMD\info
- files\AMDPH2
- files\AMDPH2\info
- files\AMDPH3
- files\AMDPH3\info
- files\AMDSemp
- files\AMDSemp\info
- files\AMDX2
- files\AMDX2\info
- files\AOPEN
- files\AOPEN\info
- files\APPLE
- files\APPLE\info
- files\ASROCK
- files\ASROCK\info
- files\ASUS
- files\ASUS\info
- files\ATI
- files\ATI\info
- files\BenQ
- files\BenQ\info
- files\BIOSTAR
- files\BIOSTAR\info
- files\certs
- files\Compal
- files\Compal\info
- files\Compaq
- files\Compaq\info
- files\Dell
- files\Dell\info
- files\DFI
- files\DFI\info
- files\ECS
- files\ECS\info
- files\eMachines
- files\eMachines\info
- files\EPOX
- files\EPOX\info
- files\FOUNDER
- files\FOUNDER\info
- files\Fujitsu
- files\Fujitsu\info
- files\Gateway
- files\Gateway\info
- files\GIGABYTE
- files\GIGABYTE\info
- files\HP
- files\HP\info
- files\IBM
- files\IBM\info
- files\INTELCore2
- files\INTELCore2\info
- files\INTELCore2Q
- files\INTELCore2Q\info
- files\INTELViiv
- files\INTELViiv\info
- files\Lenovo
- files\Lenovo\info
- files\LG
- files\LG\info
- files\MDG
- files\MDG\info
- files\Medion
- files\Medion\info
- files\Mercury
- files\Mercury\info
- files\MSI
- files\MSI\info
- files\NEC
- files\NEC\info
- files\NEO
- files\NEO\info
- files\Nvidia
- files\Nvidia\info
- files\NvidiaSLI
- files\NvidiaSLI\info
- files\NvidiaXFX
- files\NvidiaXFX\info
- files\PB
- files\PB\info
- files\Samsung
- files\Samsung\info
- files\SONY
- files\SONY\info
- files\Toshiba
- files\Toshiba\info
- files\Viglen
- files\Viglen\info
- files\XPC
- files\XPC\info
Step 3
Search and delete these files
- %User Temp%\ftp.exe
- %User Temp%\7loader 1.5.exe
- __tmp_rar_sfx_access_check_45390
- oem.exe
- files\ABIT\info\ABITLOGO.GIF
- files\ABIT\info\ABIT_BADGE.BMP
- files\ABIT\info\ABIT_BADGE.PNG
- files\ABIT\info\ABIT_BAR.PNG
- files\ABIT\info\ABIT_LOGO.PNG
- files\ABIT\info\ABIT_MCE_LOGO.PNG
- files\ABIT\info\OOBE.XML
- files\Acer\info\ACERLOGO.GIF
- files\Acer\info\ACER_BADGE.BMP
- files\Acer\info\ACER_BADGE.PNG
- files\Acer\info\ACER_BAR.PNG
- files\Acer\info\ACER_LOGO.PNG
- files\Acer\info\ACER_MCE_LOGO.PNG
- files\Acer\info\OOBE.XML
- files\ADVENT\info\ADVENTLOGO.GIF
- files\ADVENT\info\ADVENT_BADGE.BMP
- files\ADVENT\info\ADVENT_BADGE.PNG
- files\ADVENT\info\ADVENT_BAR.PNG
- files\ADVENT\info\ADVENT_LOGO.PNG
- files\ADVENT\info\ADVENT_MCE_LOGO.PNG
- files\ADVENT\info\OOBE.XML
- files\ALIENWARE\info\ALIENWARELOGO.GIF
- files\ALIENWARE\info\ALIENWARE_BADGE.BMP
- files\ALIENWARE\info\ALIENWARE_BADGE.PNG
- files\ALIENWARE\info\ALIENWARE_BAR.PNG
- files\ALIENWARE\info\ALIENWARE_LOGO.PNG
- files\ALIENWARE\info\ALIENWARE_MCE_LOGO.PNG
- files\ALIENWARE\info\OOBE.XML
- files\AMD\info\AMDLOGO.GIF
- files\AMD\info\AMD_BADGE.BMP
- files\AMD\info\AMD_BADGE.PNG
- files\AMD\info\AMD_BAR.PNG
- files\AMD\info\AMD_LOGO.PNG
- files\AMD\info\AMD_MCE_LOGO.PNG
- files\AMD\info\OOBE.XML
- files\AMDPH2\info\AMDLOGO.GIF
- files\AMDPH2\info\AMD_BADGE.bmp
- files\AMDPH2\info\AMD_BADGE.PNG
- files\AMDPH2\info\AMD_BAR.PNG
- files\AMDPH2\info\AMD_LOGO.PNG
- files\AMDPH2\info\AMD_MCE_LOGO.PNG
- files\AMDPH2\info\OOBE.XML
- files\AMDPH3\info\AMDLOGO.GIF
- files\AMDPH3\info\AMD_BADGE.bmp
- files\AMDPH3\info\AMD_BADGE.PNG
- files\AMDPH3\info\AMD_BAR.PNG
- files\AMDPH3\info\AMD_LOGO.PNG
- files\AMDPH3\info\AMD_MCE_LOGO.PNG
- files\AMDPH3\info\OOBE.XML
- files\AMDSemp\info\AMDLOGO.GIF
- files\AMDSemp\info\AMD_BADGE.BMP
- files\AMDSemp\info\AMD_BADGE.PNG
- files\AMDSemp\info\AMD_BAR.PNG
- files\AMDSemp\info\AMD_LOGO.PNG
- files\AMDSemp\info\AMD_MCE_LOGO.PNG
- files\AMDSemp\info\OOBE.XML
- files\AMDX2\info\AMDLOGO.GIF
- files\AMDX2\info\AMD_BADGE.BMP
- files\AMDX2\info\AMD_BADGE.PNG
- files\AMDX2\info\AMD_BAR.PNG
- files\AMDX2\info\AMD_LOGO.PNG
- files\AMDX2\info\AMD_MCE_LOGO.PNG
- files\AMDX2\info\OOBE.XML
- files\AOPEN\info\AOPENLOGO.GIF
- files\AOPEN\info\AOPEN_BADGE.BMP
- files\AOPEN\info\AOPEN_BADGE.PNG
- files\AOPEN\info\AOPEN_BAR.PNG
- files\AOPEN\info\AOPEN_LOGO.PNG
- files\AOPEN\info\AOPEN_MCE_LOGO.PNG
- files\AOPEN\info\OOBE.XML
- files\APPLE\info\APPLELOGO.GIF
- files\APPLE\info\APPLE_BADGE.BMP
- files\APPLE\info\APPLE_BADGE.PNG
- files\APPLE\info\APPLE_BAR.PNG
- files\APPLE\info\APPLE_LOGO.PNG
- files\APPLE\info\APPLE_MCE_LOGO.PNG
- files\APPLE\info\OOBE.XML
- files\ASROCK\info\ASROCKLOGO.GIF
- files\ASROCK\info\ASROCK_BADGE.BMP
- files\ASROCK\info\ASROCK_BADGE.PNG
- files\ASROCK\info\ASROCK_BAR.PNG
- files\ASROCK\info\ASROCK_LOGO.PNG
- files\ASROCK\info\ASROCK_MCE_LOGO.PNG
- files\ASROCK\info\OOBE.XML
- files\ASUS\info\ASUSLOGO.GIF
- files\ASUS\info\ASUS_BADGE.BMP
- files\ASUS\info\ASUS_BADGE.PNG
- files\ASUS\info\ASUS_BAR.PNG
- files\ASUS\info\ASUS_LOGO.PNG
- files\ASUS\info\ASUS_MCE_LOGO.PNG
- files\ASUS\info\OOBE.XML
- files\ATI\info\ATILOGO.GIF
- files\ATI\info\ATI_BADGE.BMP
- files\ATI\info\ATI_BADGE.PNG
- files\ATI\info\ATI_BAR.PNG
- files\ATI\info\ATI_LOGO.PNG
- files\ATI\info\ATI_MCE_LOGO.PNG
- files\ATI\info\OOBE.XML
- files\BenQ\info\BENQLOGO.GIF
- files\BenQ\info\BenQ_BADGE.BMP
- files\BenQ\info\BENQ_BADGE.PNG
- files\BenQ\info\BenQ_BAR.PNG
- files\BenQ\info\BENQ_LOGO.PNG
- files\BenQ\info\BenQ_MCE_LOGO.PNG
- files\BenQ\info\OOBE.XML
- files\BIOSTAR\info\BIOSTARLOGO.GIF
- files\BIOSTAR\info\BIOSTAR_BADGE.BMP
- files\BIOSTAR\info\BIOSTAR_BADGE.PNG
- files\BIOSTAR\info\BIOSTAR_BAR.PNG
- files\BIOSTAR\info\BIOSTAR_LOGO.PNG
- files\BIOSTAR\info\BIOSTAR_MCE_LOGO.PNG
- files\BIOSTAR\info\OOBE.XML
- files\certs\ACER.XRM-MS
- files\certs\ACRSYSACRPRDCT.XRM-MS
- files\certs\ADVENT-DSGLTD.XRM-MS
- files\certs\ALIENWARE.XRM-MS
- files\certs\ASUS.XRM-MS
- files\certs\AVERATEC-TRIGEM.XRM-MS
- files\certs\BENQ.XRM-MS
- files\certs\COMPAQ-HP.XRM-MS
- files\certs\DEALIN-DEPO.XRM-MS
- files\certs\DELL.XRM-MS
- files\certs\DELLB8K.XRM-MS
- files\certs\EMACHINE-GATEWAY.XRM-MS
- files\certs\EVEREX-FIC.XRM-MS
- files\certs\FOUNDER.XRM-MS
- files\certs\FOUNDRFOUNDRPC.XRM-MS
- files\certs\FSCPC.xrm-ms
- files\certs\FUJITSU-SIEMENS.XRM-MS
- files\certs\FUJITSU.XRM-MS
- files\certs\GATEWASYSTEMv1.xrm-ms
- files\certs\GATEWASYSTEMv2.xrm-ms
- files\certs\GATEWAY.XRM-MS
- files\certs\GERICOM.XRM-MS
- files\certs\GIGABYTE.XRM-MS
- files\certs\GREATWALL.XRM-MS
- files\certs\HAIER.XRM-MS
- files\certs\HASEE.XRM-MS
- files\certs\HEDY.XRM-MS
- files\certs\HP-PROLIANT.XRM-MS
- files\certs\HPQOEMSLIC-CPC.XRM-MS
- files\certs\HPQOEMSLIC-MPC.XRM-MS
- files\certs\IBM-LENOVO.XRM-MS
- files\certs\KOUZIRO-FRONTIER.XRM-MS
- files\certs\KSYSTEMS-IRBIS.XRM-MS
- files\certs\LENOVO.XRM-MS
- files\certs\LENOVOTC-03.XRM-MS
- files\certs\LENOVOTC-2P.XRM-MS
- files\certs\LENOVOTP-79.XRM-MS
- files\certs\LG.XRM-MS
- files\certs\MEDION.XRM-MS
- files\certs\MEDIONAGv1.xrm-ms
- files\certs\MEDIONAGv2.xrm-ms
- files\certs\MESHPC.XRM-MS
- files\certs\MSI.XRM-MS
- files\certs\NEC.XRM-MS
- files\certs\NECCAP.XRM-MS
- files\certs\NECND000146.xrm-ms
- files\certs\NECND000147.xrm-ms
- files\certs\oemcert.XRM-MS
- files\certs\OQO.XRM-MS
- files\certs\PACKARDBELL.XRM-MS
- files\certs\PANASONIC.XRM-MS
- files\certs\POWERSPEC.XRM-MS
- files\certs\ROVERCOMPUTERS.XRM-MS
- files\certs\SAMSUNG.XRM-MS
- files\certs\SECCSDLH43STAR.XRM-MS
- files\certs\SHARP.XRM-MS
- files\certs\SONY.XRM-MS
- files\certs\SYSTEMAX.XRM-MS
- files\certs\TARGA.XRM-MS
- files\certs\TCL.XRM-MS
- files\certs\TONGFANG.XRM-MS
- files\certs\TOSHIBA-A0037.XRM-MS
- files\certs\TOSHIBA-ASU00.XRM-MS
- files\certs\TOSHIBA-CPL00.XRM-MS
- files\certs\TOSHIBA-INV00.XRM-MS
- files\certs\TOSHIBA-QCI00.XRM-MS
- files\certs\TOSINVTOSINV00.xrm-ms
- files\certs\TOSQCITOSQCI00.XRM-MS
- files\certs\VELOCITYMICRO.XRM-MS
- files\Compal\info\COMPALLOGO.GIF
- files\Compal\info\COMPAL_BADGE.BMP
- files\Compal\info\COMPAL_BADGE.PNG
- files\Compal\info\COMPAL_BAR.PNG
- files\Compal\info\COMPAL_LOGO.PNG
- files\Compal\info\COMPAL_MCE_LOGO.PNG
- files\Compal\info\OOBE.XML
- files\Compaq\info\COMPAQLOGO.GIF
- files\Compaq\info\COMPAQ_BADGE.BMP
- files\Compaq\info\COMPAQ_BADGE.PNG
- files\Compaq\info\COMPAQ_BAR.PNG
- files\Compaq\info\COMPAQ_LOGO.PNG
- files\Compaq\info\COMPAQ_MCE_LOGO.PNG
- files\Compaq\info\OOBE.XML
- files\Dell\info\DELLLOGO.GIF
- files\Dell\info\DELL_BADGE.BMP
- files\Dell\info\DELL_BADGE.PNG
- files\Dell\info\DELL_BAR.PNG
- files\Dell\info\DELL_LOGO.PNG
- files\Dell\info\DELL_MCE_LOGO.PNG
- files\Dell\info\OOBE.XML
- files\DFI\info\DFILOGO.GIF
- files\DFI\info\DFI_BADGE.BMP
- files\DFI\info\DFI_BADGE.PNG
- files\DFI\info\DFI_BAR.PNG
- files\DFI\info\DFI_LOGO.PNG
- files\DFI\info\DFI_MCE_LOGO.PNG
- files\DFI\info\OOBE.XML
- files\ECS\info\ECSLOGO.GIF
- files\ECS\info\ECS_BADGE.BMP
- files\ECS\info\ECS_BADGE.PNG
- files\ECS\info\ECS_BAR.PNG
- files\ECS\info\ECS_LOGO.PNG
- files\ECS\info\ECS_MCE_LOGO.PNG
- files\ECS\info\OOBE.XML
- files\eMachines\info\EMACHINESLOGO.GIF
- files\eMachines\info\EMACHINES_BADGE.BMP
- files\eMachines\info\EMACHINES_BADGE.PNG
- files\eMachines\info\EMACHINES_BAR.PNG
- files\eMachines\info\EMACHINES_LOGO.PNG
- files\eMachines\info\EMACHINES_MCE_LOGO.PNG
- files\eMachines\info\OOBE.XML
- files\EPOX\info\EPOXLOGO.GIF
- files\EPOX\info\EPOX_BADGE.BMP
- files\EPOX\info\EPOX_BADGE.PNG
- files\EPOX\info\EPOX_BAR.PNG
- files\EPOX\info\EPOX_LOGO.PNG
- files\EPOX\info\EPOX_MCE_LOGO.PNG
- files\EPOX\info\OOBE.XML
- files\FOUNDER\info\FOUNDERLOGO.GIF
- files\FOUNDER\info\FOUNDER_BADGE.BMP
- files\FOUNDER\info\FOUNDER_BADGE.PNG
- files\FOUNDER\info\FOUNDER_BAR.PNG
- files\FOUNDER\info\FOUNDER_LOGO.PNG
- files\FOUNDER\info\FOUNDER_MCE_LOGO.PNG
- files\FOUNDER\info\OOBE.XML
- files\Fujitsu\info\FUJITSULOGO.GIF
- files\Fujitsu\info\FUJITSU_BADGE.BMP
- files\Fujitsu\info\FUJITSU_BADGE.PNG
- files\Fujitsu\info\FUJITSU_BAR.PNG
- files\Fujitsu\info\FUJITSU_LOGO.PNG
- files\Fujitsu\info\FUJITSU_MCE_LOGO.PNG
- files\Fujitsu\info\OOBE.XML
- files\Gateway\info\GATEWAYLOGO.GIF
- files\Gateway\info\GATEWAY_BADGE.BMP
- files\Gateway\info\GATEWAY_BADGE.PNG
- files\Gateway\info\GATEWAY_BAR.PNG
- files\Gateway\info\GATEWAY_LOGO.PNG
- files\Gateway\info\GATEWAY_MCE_LOGO.PNG
- files\Gateway\info\OOBE.XML
- files\GIGABYTE\info\GYGABYTELOGO.GIF
- files\GIGABYTE\info\GYGABYTE_BADGE.BMP
- files\GIGABYTE\info\GYGABYTE_BADGE.PNG
- files\GIGABYTE\info\GYGABYTE_BAR.PNG
- files\GIGABYTE\info\GYGABYTE_LOGO.PNG
- files\GIGABYTE\info\GYGABYTE_MCE_LOGO.PNG
- files\GIGABYTE\info\OOBE.XML
- files\HP\info\HPLOGO.GIF
- files\HP\info\HP_BADGE.BMP
- files\HP\info\HP_BADGE.PNG
- files\HP\info\HP_BAR.PNG
- files\HP\info\HP_LOGO.PNG
- files\HP\info\HP_MCE_LOGO.PNG
- files\HP\info\OOBE.XML
- files\IBM\info\IBMLOGO.GIF
- files\IBM\info\IBM_BADGE.BMP
- files\IBM\info\IBM_BADGE.PNG
- files\IBM\info\IBM_BAR.PNG
- files\IBM\info\IBM_LOGO.PNG
- files\IBM\info\IBM_MCE_LOGO.PNG
- files\IBM\info\OOBE.XML
- files\INTELCore2\info\INTELLOGO.GIF
- files\INTELCore2\info\INTEL_BADGE.BMP
- files\INTELCore2\info\INTEL_BADGE.PNG
- files\INTELCore2\info\INTEL_BAR.PNG
- files\INTELCore2\info\INTEL_LOGO.PNG
- files\INTELCore2\info\INTEL_MCE_LOGO.PNG
- files\INTELCore2\info\OOBE.XML
- files\INTELCore2Q\info\INTELLOGO.GIF
- files\INTELCore2Q\info\INTEL_BADGE.bmp
- files\INTELCore2Q\info\INTEL_BADGE.PNG
- files\INTELCore2Q\info\INTEL_BAR.PNG
- files\INTELCore2Q\info\INTEL_LOGO.PNG
- files\INTELCore2Q\info\INTEL_MCE_LOGO.PNG
- files\INTELCore2Q\info\OOBE.XML
- files\INTELViiv\info\INTELLOGO.GIF
- files\INTELViiv\info\INTEL_BADGE.BMP
- files\INTELViiv\info\INTEL_BADGE.PNG
- files\INTELViiv\info\INTEL_BAR.PNG
- files\INTELViiv\info\INTEL_LOGO.PNG
- files\INTELViiv\info\INTEL_MCE_LOGO.PNG
- files\INTELViiv\info\OOBE.XML
- files\Lenovo\info\LENOVOLOGO.GIF
- files\Lenovo\info\LENOVO_BADGE.BMP
- files\Lenovo\info\LENOVO_BADGE.PNG
- files\Lenovo\info\LENOVO_BAR.PNG
- files\Lenovo\info\LENOVO_LOGO.PNG
- files\Lenovo\info\LENOVO_MCE_LOGO.PNG
- files\Lenovo\info\OOBE.XML
- files\LG\info\LGLOGO.GIF
- files\LG\info\LG_BADGE.BMP
- files\LG\info\LG_BADGE.PNG
- files\LG\info\LG_BAR.PNG
- files\LG\info\LG_LOGO.PNG
- files\LG\info\LG_MCE_LOGO.PNG
- files\LG\info\OOBE.XML
- files\MDG\info\MDGLOGO.GIF
- files\MDG\info\MDG_BADGE.BMP
- files\MDG\info\MDG_BADGE.PNG
- files\MDG\info\MDG_BAR.PNG
- files\MDG\info\MDG_LOGO.PNG
- files\MDG\info\MDG_MCE_LOGO.PNG
- files\MDG\info\OOBE.XML
- files\Medion\info\MEDIONLOGO.gif
- files\Medion\info\MEDION_BADGE.BMP
- files\Medion\info\MEDION_BADGE.PNG
- files\Medion\info\medion_bar.png
- files\Medion\info\MEDION_LOGO.PNG
- files\Medion\info\MEDION_MCE_LOGO.PNG
- files\Medion\info\OOBE.XML
- files\Mercury\info\MERCURYLOGO.GIF
- files\Mercury\info\MERCURY_BADGE.BMP
- files\Mercury\info\MERCURY_BADGE.PNG
- files\Mercury\info\MERCURY_BAR.PNG
- files\Mercury\info\MERCURY_LOGO.PNG
- files\Mercury\info\MERCURY_MCE_LOGO.PNG
- files\Mercury\info\OOBE.XML
- files\MSI\info\MSILOGO.GIF
- files\MSI\info\MSI_BADGE.BMP
- files\MSI\info\MSI_BADGE.PNG
- files\MSI\info\MSI_BAR.PNG
- files\MSI\info\MSI_LOGO.PNG
- files\MSI\info\MSI_MCE_LOGO.PNG
- files\MSI\info\OOBE.XML
- files\NEC\info\NECLOGO.GIF
- files\NEC\info\NEC_BADGE.BMP
- files\NEC\info\NEC_BADGE.PNG
- files\NEC\info\NEC_BAR.PNG
- files\NEC\info\NEC_LOGO.PNG
- files\NEC\info\NEC_MCE_LOGO.PNG
- files\NEC\info\OOBE.XML
- files\NEO\info\NEOLOGO.GIF
- files\NEO\info\NEO_BADGE.BMP
- files\NEO\info\NEO_BADGE.PNG
- files\NEO\info\NEO_BAR.PNG
- files\NEO\info\NEO_LOGO.PNG
- files\NEO\info\NEO_MCE_LOGO.PNG
- files\NEO\info\OOBE.XML
- files\Nvidia\info\NVIDIALOGO.GIF
- files\Nvidia\info\NVIDIA_BADGE.BMP
- files\Nvidia\info\NVIDIA_BADGE.PNG
- files\Nvidia\info\NVIDIA_BAR.PNG
- files\Nvidia\info\NVIDIA_LOGO.PNG
- files\Nvidia\info\NVIDIA_MCE_LOGO.PNG
- files\Nvidia\info\OOBE.XML
- files\NvidiaSLI\info\NVIDIALOGO.GIF
- files\NvidiaSLI\info\NVIDIA_BADGE.BMP
- files\NvidiaSLI\info\NVIDIA_BADGE.PNG
- files\NvidiaSLI\info\NVIDIA_BAR.PNG
- files\NvidiaSLI\info\NVIDIA_LOGO.PNG
- files\NvidiaSLI\info\NVIDIA_MCE_LOGO.PNG
- files\NvidiaSLI\info\OOBE.XML
- files\NvidiaXFX\info\NVIDIALOGO.GIF
- files\NvidiaXFX\info\NVIDIA_BADGE.bmp
- files\NvidiaXFX\info\NVIDIA_BADGE.png
- files\NvidiaXFX\info\NVIDIA_BAR.PNG
- files\NvidiaXFX\info\NVIDIA_LOGO.PNG
- files\NvidiaXFX\info\NVIDIA_MCE_LOGO.PNG
- files\NvidiaXFX\info\OOBE.XML
- files\PB\info\OOBE.XML
- files\PB\info\PACKARDBELLLOGO.GIF
- files\PB\info\PACKARDBELL_BADGE.BMP
- files\PB\info\PACKARDBELL_BADGE.PNG
- files\PB\info\PACKARDBELL_BAR.PNG
- files\PB\info\PACKARDBELL_LOGO.PNG
- files\PB\info\PACKARDBELL_MCE_LOGO.PNG
- files\Samsung\info\OOBE.XML
- files\Samsung\info\SAMSUNGLOGO.GIF
- files\Samsung\info\SAMSUNG_BADGE.BMP
- files\Samsung\info\SAMSUNG_BADGE.PNG
- files\Samsung\info\SAMSUNG_BAR.PNG
- files\Samsung\info\SAMSUNG_LOGO.PNG
- files\Samsung\info\SAMSUNG_MCE_LOGO.PNG
- files\SONY\info\OOBE.XML
- files\SONY\info\VAIOLOGO.GIF
- files\SONY\info\VAIO_BADGE.BMP
- files\SONY\info\VAIO_BADGE.PNG
- files\SONY\info\VAIO_BAR.PNG
- files\SONY\info\VAIO_LOGO.PNG
- files\SONY\info\VAIO_MCE_LOGO.PNG
- files\Toshiba\info\OOBE.XML
- files\Toshiba\info\TOSHIBALOGO.GIF
- files\Toshiba\info\TOSHIBA_BADGE.BMP
- files\Toshiba\info\TOSHIBA_BADGE.PNG
- files\Toshiba\info\TOSHIBA_BAR.PNG
- files\Toshiba\info\TOSHIBA_LOGO.PNG
- files\Toshiba\info\TOSHIBA_MCE_LOGO.PNG
- files\Viglen\info\OOBE.XML
- files\Viglen\info\VIGLENLOGO.GIF
- files\Viglen\info\VIGLEN_BADGE.BMP
- files\Viglen\info\VIGLEN_BADGE.PNG
- files\Viglen\info\VIGLEN_BAR.PNG
- files\Viglen\info\VIGLEN_LOGO.PNG
- files\Viglen\info\VIGLEN_MCE_LOGO.PNG
- files\XPC\info\OOBE.XML
- files\XPC\info\XPCLOGO.GIF
- files\XPC\info\XPC_BADGE.BMP
- files\XPC\info\XPC_BADGE.PNG
- files\XPC\info\XPC_BAR.PNG
- files\XPC\info\XPC_LOGO.PNG
- files\XPC\info\XPC_MCE_LOGO.PNG
- files\Compaq\info\Compaq_BAR.bmp
- files\Compaq\info\Thumbs.db
Step 4
Scan your computer with your Trend Micro product to delete files detected as TROJ_NSIS.AE. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.
Step 5
Restore this file from backup only Microsoft-related files will be restored. If this malware/grayware also deleted files related to programs that are not from Microsoft, please reinstall those programs on you computer again. %User Temp%\nsv1.tmp
Did this description help? Tell us how we did.