The presence of the following files:
<system folder>\cmmput.exe
<system folder>\csrsrss.exe
<system folder>\SystemMonitor.exe
%windir%\sfoundfiles.txt
ACDSee 5.5.exe
Age of Empires 2 crack.exe
all microsoft software keygenerator.exe
Ana Kournikova Sex Video.exe
Animated Screen 7.0b.exe
aol cracker.exe
AOL Instant Messenger.exe
aol password cracker.exe
AquaNox2 Crack.exe
Audiograbber 2.05.exe
AVP Antivirus Pro Key Crack.exe
BabeFest 2007 ScreenSaver 1.5.exe
Babylon 3.50b reg_crack.exe
Battlefield1942_bloodpatch.exe
Battlefield1942_keygen.exe
Britney Spears Sex Video.exe
Buffy Vampire Slayer Movie.exe
Business Card Designer Plus 7.9.exe
cable modem ultility pack.exe
Clone CD 9.0.0.3 (crack).exe
Clone CD 9.0.0.3.exe
Coffee Cup Free zip 7.0b.exe
Cool Edit Pro v2.55.exe
counter-strike.exe
Crack Passwords Mail.exe
Crackeador de TODOS los programas.exe
cracker to ALL software.exe
Credit Card Numbers generator(incl Visa,MasterCard,...).exe
Cristina Aguilera Sex Video.exe
delphi.exe
Diablo 2 Crack.exe
DirectDVD 5.0.exe
DirectX Buster (all versions).exe
DirectX InfoTool.exe
divx pro.exe
DivX Video Bundle 6.5.exe
divx_pro.exe
Download Accelerator Plus 6.1.exe
DVD Copy Plus v5.0.exe
DVD Region-Free 2.3.exe
Edonkey2000-Speed me up scotty.exe
El rey de los huevones full divx - comprimida.exe
FIFA2004 crack.exe
Final Fantasy VII XP Patch 1.5.exe
Flash MX crack (trial).exe
FlashGet 1.5.exe
FreeRAM XP Pro 1.9.exe
Game Cube Real Emulator.exe
GetRight 5.0a.exe
Global DiVX Player 3.0.exe
Gothic2 licence.exe
GTA 3 Crack.exe
GTA 3 Serial.exe
Guitar Chords Library 5.5.exe
Hentai Anime Girls Movie.exe
Hitman_2_no_cd_crack.exe
Hot Babes XXX Screen Saver.exe
HotGirls.exe
Hotmail Hacker 2007-Xss Exploit.exe
hotmail_hack.exe
ICQ Pro 2007a.exe
ICQ Pro 2007b (new beta).exe
iMesh 3.6.exe
iMesh 3.7b (beta).exe
IrfanView 4.5.exe
Jenifer Lopez Sex Video.exe
KaZaA Hack 2.5.0.exe
Kazaa SDK + Xbit speedUp for 2.xx.exe
KaZaA Speedup 3.6.exe
Links 2007 Golf game (crack).exe
Living Waterfalls 1.3.exe
Macromedia all software key generator.exe
macromedia dreamweaver key generator.exe
Mafia_crack.exe
Matrix Movie.exe
Matrix Screensaver 1.5.exe
Mcafee Antivirus Scan Crack.exe
MediaPlayer Update.exe
Metodo crackear hotmail actualizado 30-09-2006.exe
Microsoft KeyGenerator-Allmost all microsoft stuff.exe
mIRC 6.40.exe
Mision imposible 3 Game.exe
mp3Trim PRO 2.5.exe
MSN Messenger 8.2.exe
NBA2007_crack.exe
Need 4 Speed crack.exe
Need 4 Speed Most Wanted Full With Crack.exe
Nero Burning ROM crack.exe
Netbios Nuker 2004.exe
Netfast 1.8.exe
Network Cable e ADSL Speed 2.0.5.exe
NHL 2004 crack.exe
Nimo CodecPack (new) 8.0.exe
Norton Anvirus Key Crack.exe
PalTalk 5.01b.exe
pamela_anderson.exe
Panda Antivirus Titanium Crack.exe
PerAntivirus 8.9.exe
play station one two and three emulator.exe
Pop-Up Stopper 3.5.exe
Popup Defender 6.5.exe
PS2 PlayStation Simulator.exe
Quick Time Key Crack.exe
QuickTime_Pro_Crack.exe
Sakura Card Captor Movie.exe
Samsung ALL models unlocker.exe
Screen saver christina aguilera naked.exe
Screen saver christina aguilera.exe
Security-2007-Update.exe
Serials 2004 v.8.0 Full.exe
serials2007.exe
Sex Live Simulator.exe
Sex Passwords.exe
SmartFTP 2.0.0.exe
SmartRipper v2.7.exe
Space Invaders 1978.exe
Spiderman Movie.exe
Splinter_Cell_Crack.exe
Starcraft serial.exe
Start Wars Trilogy Movies.exe
Steinberg_WaveLab_5_crack.exe
Stripping MP3 dancer+crack.exe
subseven.exe
Thalia Sex Video.exe
The Hacker Antivirus 5.7.exe
Trillian 0.85 (free).exe
TweakAll 3.8.exe
Unreal2_bloodpatch.exe
Unreal2_crack.exe
UT2004_bloodpatch.exe
UT2004_keygen.exe
UT2004_no cd (crack).exe
UT2004_patch.exe
UT2007 full & crack.exe
VB6.exe
Virtua Girl (Full).exe
virtua girl - adriana.exe
virtua girl - bailey short skirt.exe
VirtualSex.exe
Visual Basic 6.0 Msdn Plugin.exe
Visual basic 6.exe
warcraft 3 crack.exe
warcraft 3 serials.exe
WarCraft_3_crack.exe
Winamp 7.8.exe
winamp plugin pack.exe
WindowBlinds 4.0.exe
Windows Stearter Edition crack.exe
Windows XP complete + serial.exe
Windows Xp Exploit.exe
WinOnCD 4 PE_crack.exe
WinRar 3.xx Password Cracker.exe
WinZip 9.0b.exe
winzip full version key generator.exe
Winzip KeyGenerator Crack.exe .exe
WinZipped Visual C++ Tutorial.exe
xbox360 emulator.exe
XNuker 2004 2.93b.exe
Yahoo Messenger 6.0.exe
Zelda Classic 2.00.exe
The presence of the following registry modifications:
In subkey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Sets value: "SysTemperatureNotRemove"
Sets value: "Windows Services"
Sets value: "Sysmon"
In subkey: HKLM\SOFTWARE\Classes\exefile\shell\open\command
Sets value: "(default)"
With data: "<system folder>\systemmonitor.exe "%1" %*"
In subkey:HKLM\SOFTWARE\Classes\batfile\shell\open\command
Sets value: "(default)"
With data: "<system folder>\systemmonitor.exe "%1" %*"
In subkey: HKLM\SOFTWARE\Classes\comfile\shell\open\command
Sets value: "(default)"
With data: "<system folder>\systemmonitor.exe "%1" %*"
In subkey: HKLM\SOFTWARE\Classes\piffile\shell\open\command
Sets value: "(default)"
With data: "<system folder>\systemmonitor.exe "%1" %*"
In subkey: HKLM\SOFTWARE\Classes\cmdfile\shell\open\command
Sets value: "(default)"
With data: "<system folder>\systemmonitor.exe "%1" %*"
In subkey: HKLM\SOFTWARE\Classes\scrfile\shell\open\command
Sets value: "(default)"
With data: "<system folder>\systemmonitor.exe "%1" /s"
In subkey: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
Sets value: "DisableTaskMgr"
With data: "1"
In subkey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
Sets value: "DisableSR"
With data: "1"
In subkey: HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
Sets value: "DisableNotifications"
With data: "1"
In subkey: HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
Sets value: "DisableNotifications"
With data: "1"
In subkey: HKLM\SYSTEM\CurrentControlSet\Services\PAVfnsvr
Sets value: "START"
With data: "4"
In subkey: HKLM\SYSTEM\CurrentControlSet\Services\Pavkre
Sets value: "START"
With data: "4"
In subkey: HKLM\SYSTEM\CurrentControlSet\Services\PavProc
Sets value: "START"
With data: "4"
In subkey: HKLM\SYSTEM\CurrentControlSet\Services\PavProt
Sets value: "START"
With data: "4"
In subkey: HKLM\SYSTEM\CurrentControlSet\Services\PavPrSrv
Sets value: "START"
With data: "4"