Path
Name
File Name
First Used By Program
First SeenLast SeenFile SizeDeterminationMalware GroupSiblings
%WINDIR%\SYSTEM32\28/09/2006 06:46:0016/07/2005 00:55:1327/08/2008 07:10:0281 BRootkit.Haxdoor7
?:\07/11/2006 17:02:0031/07/2005 18:20:4005/08/2008 09:26:06253952 G6
?:\internet\security & protection\ad-awrare\spyware\03/08/2005 06:49:0003/08/2005 06:49:1109/04/2006 15:38:181258486 U22130
?:\CEIT99\PRIXDIVERS\ACCU\DOS\16/08/2005 19:42:0016/08/2005 19:41:5616/08/2005 19:41:5684496 G1
?:\cd_projects\game_dos2\actions\xerix\08/09/2005 16:05:0008/09/2005 16:04:4118/03/2006 12:22:3720427 G1
?:\FACT\CUR\FACT\15/09/2005 12:03:0015/09/2005 12:02:5915/09/2005 12:02:59146650 G427
03/10/2005 18:30:0003/10/2005 18:30:2603/10/2005 18:30:26184320 U1
?:\04/10/2005 11:13:0004/10/2005 11:12:1108/09/2007 12:24:171581056 G1
?:\ntutil\decompresser\05/10/2005 16:11:0005/10/2005 16:10:5805/10/2005 16:10:5836864 U1
%programfiles%\pebuilder313\plugin\1_ubdwiz\06/10/2005 04:04:0006/10/2005 04:03:3306/10/2005 04:03:33116752 U1
?:\31/10/2005 23:50:0031/10/2005 23:49:3519/09/2006 20:35:38970752 G1
%DESKTOP%\NEW FOLDER\05/11/2005 17:40:0005/11/2005 17:39:3305/11/2005 17:39:33191621 U22130
?:\pojie\加壳\xinstall\xqbox\19/01/2006 11:35:0019/01/2006 11:35:0719/01/2006 11:35:07535040 U1
?:\installation programs for setting up pc\xerox workcentre xk50ck\01/02/200630/01/2006 23:56:4230/01/2006 23:56:42765952 U1
?:\llexell\09/03/2006 10:49:0009/03/2006 10:48:0809/03/2006 10:48:08479744 G929
?:\03/04/2006 15:27:0003/04/2006 15:19:1217/03/2007 23:10:50752640 U1
?:\csg\acsr\05/04/2006 23:30:0005/04/2006 23:12:2810/07/2006 10:19:17184320 U1
?:\06/04/2006 13:09:0006/04/2006 13:02:0006/04/2006 13:09:39815104 G1
?:\10/04/2006 07:55:0010/04/2006 07:47:3825/12/2007 05:31:271585152 G1
?:\codesamples\gameprogrammingsamples\wgpdumb\games\xtris\13/04/2006 06:06:0013/04/2006 05:55:5513/04/2006 05:55:55657985 U352
%programfiles%\qrtoolbar\17/04/2006 01:45:0017/04/2006 01:10:1117/04/2006 01:10:1120480 U1
?:\02/05/2006 06:53:0002/05/2006 06:53:1127/07/2007 14:12:45966656 U1
%temp%\a2archive\17/05/2006 12:22:0017/05/2006 12:22:1317/05/2006 12:22:1374435 U1
%profiles%\top secret\local settings\temp\~acetemp\eurotalk - talk now!-russian\11/06/2006 02:03:0011/06/2006 02:03:1011/06/2006 02:06:08317488 U1
?:\program files\application\livepdf\25/06/2006 10:38:0025/06/2006 10:37:3725/06/2006 10:37:3720480 U1
?:\apertum98\20/07/2006 14:11:0020/07/2006 14:10:3820/07/2006 14:10:38725813 U10125
?:\david\walter medina\zebra\central\os_2\os2mg\d1\29/07/2006 17:00:0029/07/2006 16:57:2229/07/2006 16:57:22348071 U1
?:\david\walter medina\zebra\central\win31\mg\d1\29/07/2006 17:00:0029/07/2006 16:57:2229/07/2006 16:57:22286832 U1
%restore%\02/09/2006 10:09:0013/08/2006 13:47:3201/11/2006 12:42:1162976 BDownloader.Drev.A1
%profiles%\vali\03/09/2006 14:48:0003/09/2006 14:47:5027/03/2007 20:15:1362464 BCovert.Sys.Exec1
%DESKTOP%\10/09/2006 18:45:0010/09/2006 18:44:4110/11/2006 14:38:1363488 BCovert.Sys.Exec1
%programfiles%\xinstall\11/09/2006 18:22:0011/09/2006 18:15:5311/09/2006 18:15:53320512 U1
?:\24/10/2006 21:25:0014/09/2006 12:37:4819/10/2006 15:02:25138862 BDownloader.Drev.A8935
?:\18/09/2006 07:30:0018/09/2006 07:30:1830/10/2007 14:44:191585152 G1
%DESKTOP%\18/09/2006 09:03:0018/09/2006 09:02:4918/09/2006 09:02:4962478 U1
%DESKTOP%\21/09/2006 16:21:0021/09/2006 16:13:2807/02/2007 06:40:5152305 BDownloader.Drev.A1
%CACHE%\CONTENT.IE5\????????\27/10/2006 18:03:0021/09/2006 16:23:0121/09/2006 16:23:0142037 BDownloader.Drev.A1
%profiles%\ville\21/09/2006 17:12:0021/09/2006 17:10:3821/09/2006 17:31:4252257 U1
%profiles%\ville\21/09/2006 17:17:0021/09/2006 17:15:5421/09/2006 17:15:5447877 U1
%profiles%\ville\21/09/2006 17:36:0021/09/2006 17:36:1824/09/2006 09:31:2350797 U1
%profiles%\ville\21/09/2006 17:47:0021/09/2006 17:46:3321/09/2006 17:55:3349337 U1
%profiles%\ville\21/09/2006 17:57:0021/09/2006 17:56:5021/09/2006 17:56:5036197 U1
%PROFILES%\ALEX\22/09/2006 04:51:0022/09/2006 03:44:5122/09/2006 03:44:5128815 U1
%DESKTOP%\23/09/2006 16:13:0023/09/2006 14:51:0723/09/2006 17:08:4150799 BDownloader.Drev.A1
%WINDIR%\SYSTEM32\24/09/2006 18:22:0024/09/2006 08:51:3025/09/2006 03:06:2252259 U1
?:\system volume information\_restore{?sid?}\rp{folder}\19/05/2007 09:14:0025/09/2006 02:59:3629/09/2006 16:11:5249339 U1
%DESKTOP%\25/09/2006 16:55:0025/09/2006 16:55:1828/07/2008 14:57:27176640 BPolynomial.Code.Exploit1
%WINDIR%\SYSTEM32\03/10/2006 02:15:0003/10/2006 00:00:3503/10/2006 00:48:5652305 U1
%WINDIR%\SYSTEM32\08/10/2006 12:36:0008/10/2006 12:35:5408/10/2006 12:35:5462380 U1
?:\my documents\manuals & documentation\sspa\809-0007-001 hpa control utility\10/10/2006 11:34:0010/10/2006 11:32:4010/10/2006 11:32:40222297 U1