PUA_SubTab
Windows
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
205,360 bytes
EXE
No
05 Jul 2016
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan creates the following folders:
- %User Temp%\istA.tmp
- %User Temp%\istA.tmp\eInstall
- %User Temp%\istA.tmp\eInstall\image
- %User Temp%\istA.tmp\eInstall\image\default
- %User Temp%\istA.tmp\eInstall\Install
- %User Temp%\istA.tmp\eInstall\language
- %User Temp%\istA.tmp\eInstall\language\en_us
- %User Temp%\istA.tmp\eInstall\layout
- %User Temp%\istA.tmp\eInstall\layout\default
- %User Temp%\istA.tmp\eInstall\style
- %User Temp%\istA.tmp\omigazip
- %User Temp%\istA.tmp\omigazip\image
- %User Temp%\istA.tmp\omigazip\image\default
- %User Temp%\istA.tmp\omigazip\language
- %User Temp%\istA.tmp\omigazip\language\en_us
- %User Temp%\istA.tmp\omigazip\language\es_es
- %User Temp%\istA.tmp\omigazip\language\pt_br
- %User Temp%\istA.tmp\omigazip\language\tr_tr
- %User Temp%\istA.tmp\omigazip\language\zh_cn
- %User Temp%\istA.tmp\omigazip\language\zh_tw
- %User Temp%\istA.tmp\omigazip\layout
- %User Temp%\istA.tmp\omigazip\layout\default
- %User Temp%\istA.tmp\omigazip\style
- %User Temp%\istA.tmp\omigazip\uninstaller
- %User Profile%\Application Data\eCyber
(Note: %User Temp% is the user's temporary folder, where it usually is C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\Users\{user name}\AppData\Local\Temp on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.. %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.)
Other System Modifications
This Trojan deletes the following files:
- %User Temp%\istA.tmp
- %User Temp%\~dl5.tmp
- %User Temp%\istA.tmp\eInstall\eInstall.exe
- %User Temp%\istA.tmp\eInstall\image\default\app_icon.png
- %User Temp%\istA.tmp\eInstall\image\default\browse_button.png
- %User Temp%\istA.tmp\eInstall\image\default\combo_skin.png
- %User Temp%\istA.tmp\eInstall\image\default\edit_skin.png
- %User Temp%\istA.tmp\eInstall\image\default\install_back.png
- %User Temp%\istA.tmp\eInstall\image\default\install_check_checked.png
- %User Temp%\istA.tmp\eInstall\image\default\install_check_intermediate.png
- %User Temp%\istA.tmp\eInstall\image\default\install_check_uncheck.png
- %User Temp%\istA.tmp\eInstall\image\default\install_logo.png
- %User Temp%\istA.tmp\eInstall\image\default\install_new_button_skin.png
- %User Temp%\istA.tmp\eInstall\image\default\install_resource.xml
- %User Temp%\istA.tmp\eInstall\image\default\pic-error.png
- %User Temp%\istA.tmp\eInstall\image\default\pic-info.png
- %User Temp%\istA.tmp\eInstall\image\default\pic-question.png
- %User Temp%\istA.tmp\eInstall\image\default\pic-warning.png
- %User Temp%\istA.tmp\eInstall\image\default\popup_dialog_bk.png
- %User Temp%\istA.tmp\eInstall\image\default\progressbar_bk.png
- %User Temp%\istA.tmp\eInstall\image\default\progressbar_image.png
- %User Temp%\istA.tmp\eInstall\image\default\radio_normal.png
- %User Temp%\istA.tmp\eInstall\image\default\radio_selected.png
- %User Temp%\istA.tmp\eInstall\image\default\sys_close.png
- %User Temp%\istA.tmp\eInstall\Install\OmigaZip.inst
- %User Temp%\istA.tmp\eInstall\language\en_us\install_lang.ini
- %User Temp%\istA.tmp\eInstall\layout\default\install_msgbox.xml
- %User Temp%\istA.tmp\eInstall\layout\default\languageSelect.xml
- %User Temp%\istA.tmp\eInstall\layout\default\OmigaZipInstall.xml
- %User Temp%\istA.tmp\eInstall\layout\default\uninstOmigaZip.xml
- %User Temp%\istA.tmp\eInstall\main
- %User Temp%\istA.tmp\eInstall\segoeui.ttf
- %User Temp%\istA.tmp\eInstall\segoeuib.ttf
- %User Temp%\istA.tmp\eInstall\style\install_style.xml
- %User Temp%\istA.tmp\omigazip\7z.dll
- %User Temp%\istA.tmp\omigazip\curlpp.dll
- %User Temp%\istA.tmp\omigazip\image\default\additem.png
- %User Temp%\istA.tmp\omigazip\image\default\app_icon.png
- %User Temp%\istA.tmp\omigazip\image\default\back.png
- %User Temp%\istA.tmp\omigazip\image\default\Background_Main.png
- %User Temp%\istA.tmp\omigazip\image\default\Background_Small_2.png
- %User Temp%\istA.tmp\omigazip\image\default\browse_button.png
- %User Temp%\istA.tmp\omigazip\image\default\checkbox_blank.png
- %User Temp%\istA.tmp\omigazip\image\default\checkbox_select.png
- %User Temp%\istA.tmp\omigazip\image\default\combo.png
- %User Temp%\istA.tmp\omigazip\image\default\combo_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\deleteitem.png
- %User Temp%\istA.tmp\omigazip\image\default\deskbtnbk.png
- %User Temp%\istA.tmp\omigazip\image\default\edit_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\extractto.png
- %User Temp%\istA.tmp\omigazip\image\default\folder.png
- %User Temp%\istA.tmp\omigazip\image\default\footerbg.png
- %User Temp%\istA.tmp\omigazip\image\default\install_back.png
- %User Temp%\istA.tmp\omigazip\image\default\install_button_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\install_check_checked.png
- %User Temp%\istA.tmp\omigazip\image\default\install_check_intermediate.png
- %User Temp%\istA.tmp\omigazip\image\default\install_check_uncheck.png
- %User Temp%\istA.tmp\omigazip\image\default\install_logo.png
- %User Temp%\istA.tmp\omigazip\image\default\install_new_button_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\install_resource.xml
- %User Temp%\istA.tmp\omigazip\image\default\listctrl_header_bk.png
- %User Temp%\istA.tmp\omigazip\image\default\listview_report.png
- %User Temp%\istA.tmp\omigazip\image\default\listview_thumb.png
- %User Temp%\istA.tmp\omigazip\image\default\menubg.png
- %User Temp%\istA.tmp\omigazip\image\default\menu_bkg.png
- %User Temp%\istA.tmp\omigazip\image\default\menu_item_over.png
- %User Temp%\istA.tmp\omigazip\image\default\onekeyextract.png
- %User Temp%\istA.tmp\omigazip\image\default\patch_file_icon.png
- %User Temp%\istA.tmp\omigazip\image\default\pic-error.png
- %User Temp%\istA.tmp\omigazip\image\default\pic-info.png
- %User Temp%\istA.tmp\omigazip\image\default\pic-question.png
- %User Temp%\istA.tmp\omigazip\image\default\pic-warning.png
- %User Temp%\istA.tmp\omigazip\image\default\popup_dialog_bk.png
- %User Temp%\istA.tmp\omigazip\image\default\progressbar_bk.png
- %User Temp%\istA.tmp\omigazip\image\default\progressbar_image.png
- %User Temp%\istA.tmp\omigazip\image\default\progress_bk.png
- %User Temp%\istA.tmp\omigazip\image\default\progress_meter.png
- %User Temp%\istA.tmp\omigazip\image\default\pwd_lock.png
- %User Temp%\istA.tmp\omigazip\image\default\pwd_unlock.png
- %User Temp%\istA.tmp\omigazip\image\default\radio_normal.png
- %User Temp%\istA.tmp\omigazip\image\default\radio_selected.png
- %User Temp%\istA.tmp\omigazip\image\default\resource.xml
- %User Temp%\istA.tmp\omigazip\image\default\settingbkg.png
- %User Temp%\istA.tmp\omigazip\image\default\settingtab.png
- %User Temp%\istA.tmp\omigazip\image\default\sys_button_close.png
- %User Temp%\istA.tmp\omigazip\image\default\sys_button_max.PNG
- %User Temp%\istA.tmp\omigazip\image\default\sys_button_min.PNG
- %User Temp%\istA.tmp\omigazip\image\default\sys_button_restore.PNG
- %User Temp%\istA.tmp\omigazip\image\default\sys_close.png
- %User Temp%\istA.tmp\omigazip\image\default\tobutton1.png
- %User Temp%\istA.tmp\omigazip\image\default\vscroll.png
- %User Temp%\istA.tmp\omigazip\language\en_us\eCompress_lang.ini
- %User Temp%\istA.tmp\omigazip\language\en_us\install_lang.ini
- %User Temp%\istA.tmp\omigazip\language\es_es\eCompress_lang.ini
- %User Temp%\istA.tmp\omigazip\language\es_es\install_lang.ini
- %User Temp%\istA.tmp\omigazip\language\pt_br\eCompress_lang.ini
- %User Temp%\istA.tmp\omigazip\language\pt_br\install_lang.ini
- %User Temp%\istA.tmp\omigazip\language\tr_tr\eCompress_lang.ini
- %User Temp%\istA.tmp\omigazip\language\tr_tr\install_lang.ini
- %User Temp%\istA.tmp\omigazip\layout\default\about.xml
- %User Temp%\istA.tmp\omigazip\layout\default\brower.xml
- %User Temp%\istA.tmp\omigazip\layout\default\compresspath.xml
- %User Temp%\istA.tmp\omigazip\layout\default\compresspwd.xml
- %User Temp%\istA.tmp\omigazip\layout\default\error.xml
- %User Temp%\istA.tmp\omigazip\layout\default\extractpath.xml
- %User Temp%\istA.tmp\omigazip\layout\default\install_msgbox.xml
- %User Temp%\istA.tmp\omigazip\layout\default\languageSelect.xml
- %User Temp%\istA.tmp\omigazip\layout\default\msgbox.xml
- %User Temp%\istA.tmp\omigazip\layout\default\OmigaZipInstall.xml
- %User Temp%\istA.tmp\omigazip\layout\default\overwrite.xml
- %User Temp%\istA.tmp\omigazip\layout\default\password.xml
- %User Temp%\istA.tmp\omigazip\layout\default\progress.xml
- %User Temp%\istA.tmp\omigazip\layout\default\rename.xml
- %User Temp%\istA.tmp\omigazip\layout\default\setting.xml
- %User Temp%\istA.tmp\omigazip\layout\default\uninstOmigaZip.xml
- %User Temp%\istA.tmp\omigazip\libcurl.dll
- %User Temp%\istA.tmp\omigazip\libeay32.dll
- %User Temp%\istA.tmp\omigazip\main
- %User Temp%\istA.tmp\omigazip\msvcp110.dll
- %User Temp%\istA.tmp\omigazip\msvcr110.dll
- %User Temp%\istA.tmp\omigazip\ssleay32.dll
- %User Temp%\istA.tmp\omigazip\style\install_style.xml
- %User Temp%\istA.tmp\omigazip\style\style.xml
- %User Temp%\istA.tmp\omigazip\uninstaller\OmigaZip.inst
- %User Temp%\istA.tmp\omigazip\winziper.exe
- %User Temp%\istA.tmp\omigazip\winzipersvc.exe
- %User Temp%\istA.tmp\omigazip\wzdl.exe
- %User Temp%\istA.tmp\omigazip\wzShellctx.dll
- %User Temp%\istA.tmp\omigazip\wzShellctx64.dll
- %User Temp%\istA.tmp\omigazip\wzUninstall.exe
- %User Temp%\istA.tmp\omigazip\wzUpg.exe
- %User Temp%\istA.tmp\omigazip\wz_settings.ini
- %User Temp%\istA.tmp\omigazip\zlib1.dll
(Note: %User Temp% is the user's temporary folder, where it usually is C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\Users\{user name}\AppData\Local\Temp on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.)
It deletes the following folders:
- %User Temp%\istA.tmp\eInstall\image\default
- %User Temp%\istA.tmp\eInstall\image
- %User Temp%\istA.tmp\eInstall\Install
- %User Temp%\istA.tmp\eInstall\language\en_us
- %User Temp%\istA.tmp\eInstall\language
- %User Temp%\istA.tmp\eInstall\layout\default
- %User Temp%\istA.tmp\eInstall\layout
- %User Temp%\istA.tmp\eInstall\style
- %User Temp%\istA.tmp\eInstall
- %User Temp%\istA.tmp\omigazip\image\default
- %User Temp%\istA.tmp\omigazip\image
- %User Temp%\istA.tmp\omigazip\language\en_us
- %User Temp%\istA.tmp\omigazip\language\es_es
- %User Temp%\istA.tmp\omigazip\language\pt_br
- %User Temp%\istA.tmp\omigazip\language\tr_tr
- %User Temp%\istA.tmp\omigazip\language\zh_cn
- %User Temp%\istA.tmp\omigazip\language\zh_tw
- %User Temp%\istA.tmp\omigazip\language
- %User Temp%\istA.tmp\omigazip\layout\default
- %User Temp%\istA.tmp\omigazip\layout
- %User Temp%\istA.tmp\omigazip\style
- %User Temp%\istA.tmp\omigazip\uninstaller
- %User Temp%\istA.tmp\omigazip
(Note: %User Temp% is the user's temporary folder, where it usually is C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\Users\{user name}\AppData\Local\Temp on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.)
It adds the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
WinZip
HKEY_LOCAL_MACHINE\Software\WinZiper
HKEY_CLASSES_ROOT\CLSID\{1006967F-7059-4DB4-A310-4F1A30F7BDC4}
HKEY_CLASSES_ROOT\.7z
HKEY_CLASSES_ROOT\WinZippers.7z
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.7z\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.7z\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.7z\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.7z\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.7z\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.7z\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.7z\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.7z\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.7z\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.7z\shellex\DropHandler
HKEY_CLASSES_ROOT\WinZippers.zip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.zip\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.zip\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.zip\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.zip\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.zip\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.zip\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.zip\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.zip\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.zip\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.zip\shellex\DropHandler
HKEY_CLASSES_ROOT\.rar
HKEY_CLASSES_ROOT\WinZippers.rar
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rar\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rar\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rar\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rar\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rar\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rar\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rar\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rar\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rar\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.001
HKEY_CLASSES_ROOT\WinZippers.001
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.001\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.001\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.001\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.001\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.001\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.001\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.001\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.001\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.001\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\WinZippers.cab
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cab\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cab\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cab\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cab\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cab\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cab\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cab\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cab\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cab\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.iso
HKEY_CLASSES_ROOT\WinZippers.iso
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.iso\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.iso\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.iso\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.iso\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.iso\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.iso\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.iso\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.iso\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.iso\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.xz
HKEY_CLASSES_ROOT\WinZippers.xz
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xz\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xz\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xz\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xz\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xz\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xz\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xz\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xz\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xz\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.txz
HKEY_CLASSES_ROOT\WinZippers.txz
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.txz\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.txz\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.txz\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.txz\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.txz\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.txz\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.txz\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.txz\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.txz\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.lzma
HKEY_CLASSES_ROOT\WinZippers.lzma
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzma\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzma\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzma\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzma\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzma\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzma\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzma\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzma\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzma\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\WinZippers.tar
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tar\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tar\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tar\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tar\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tar\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tar\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tar\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tar\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tar\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tar\shellex\DropHandler
HKEY_CLASSES_ROOT\.cpio
HKEY_CLASSES_ROOT\WinZippers.cpio
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cpio\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cpio\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cpio\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cpio\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cpio\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cpio\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cpio\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cpio\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.cpio\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.bz2
HKEY_CLASSES_ROOT\WinZippers.bz2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bz2\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bz2\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bz2\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bz2\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bz2\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bz2\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bz2\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bz2\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bz2\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.bzip2
HKEY_CLASSES_ROOT\WinZippers.bzip2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bzip2\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bzip2\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bzip2\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bzip2\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bzip2\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bzip2\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bzip2\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bzip2\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.bzip2\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.tbz2
HKEY_CLASSES_ROOT\WinZippers.tbz2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz2\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz2\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz2\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz2\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz2\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz2\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz2\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz2\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz2\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.tbz
HKEY_CLASSES_ROOT\WinZippers.tbz
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tbz\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\WinZippers.gz
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gz\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gz\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gz\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gz\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gz\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gz\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gz\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gz\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gz\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.gzip
HKEY_CLASSES_ROOT\WinZippers.gzip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gzip\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gzip\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gzip\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gzip\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gzip\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gzip\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gzip\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gzip\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.gzip\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\WinZippers.tgz
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tgz\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tgz\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tgz\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tgz\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tgz\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tgz\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tgz\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tgz\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tgz\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.tpz
HKEY_CLASSES_ROOT\WinZippers.tpz
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tpz\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tpz\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tpz\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tpz\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tpz\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tpz\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tpz\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tpz\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.tpz\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\WinZippers.z
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.z\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.z\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.z\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.z\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.z\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.z\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.z\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.z\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.z\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.taz
HKEY_CLASSES_ROOT\WinZippers.taz
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.taz\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.taz\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.taz\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.taz\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.taz\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.taz\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.taz\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.taz\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.taz\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.lzh
HKEY_CLASSES_ROOT\WinZippers.lzh
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzh\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzh\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzh\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzh\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzh\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzh\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzh\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzh\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lzh\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.lha
HKEY_CLASSES_ROOT\WinZippers.lha
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lha\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lha\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lha\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lha\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lha\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lha\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lha\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lha\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.lha\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.rpm
HKEY_CLASSES_ROOT\WinZippers.rpm
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rpm\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rpm\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rpm\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rpm\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rpm\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rpm\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rpm\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rpm\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.rpm\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.deb
HKEY_CLASSES_ROOT\WinZippers.deb
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.deb\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.deb\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.deb\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.deb\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.deb\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.deb\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.deb\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.deb\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.deb\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.arj
HKEY_CLASSES_ROOT\WinZippers.arj
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.arj\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.arj\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.arj\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.arj\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.arj\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.arj\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.arj\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.arj\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.arj\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.vhd
HKEY_CLASSES_ROOT\WinZippers.vhd
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.vhd\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.vhd\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.vhd\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.vhd\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.vhd\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.vhd\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.vhd\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.vhd\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.vhd\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.wim
HKEY_CLASSES_ROOT\WinZippers.wim
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.wim\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.wim\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.wim\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.wim\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.wim\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.wim\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.wim\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.wim\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.wim\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.swm
HKEY_CLASSES_ROOT\WinZippers.swm
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.swm\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.swm\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.swm\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.swm\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.swm\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.swm\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.swm\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.swm\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.swm\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.fat
HKEY_CLASSES_ROOT\WinZippers.fat
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.fat\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.fat\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.fat\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.fat\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.fat\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.fat\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.fat\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.fat\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.fat\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.ntfs
HKEY_CLASSES_ROOT\WinZippers.ntfs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.ntfs\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.ntfs\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.ntfs\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.ntfs\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.ntfs\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.ntfs\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.ntfs\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.ntfs\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.ntfs\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.dmg
HKEY_CLASSES_ROOT\WinZippers.dmg
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.dmg\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.dmg\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.dmg\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.dmg\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.dmg\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.dmg\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.dmg\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.dmg\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.dmg\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.hfs
HKEY_CLASSES_ROOT\WinZippers.hfs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.hfs\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.hfs\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.hfs\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.hfs\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.hfs\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.hfs\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.hfs\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.hfs\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.hfs\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.xar
HKEY_CLASSES_ROOT\WinZippers.xar
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xar\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xar\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xar\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xar\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xar\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xar\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xar\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xar\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.xar\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_CLASSES_ROOT\.squashfs
HKEY_CLASSES_ROOT\WinZippers.squashfs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.squashfs\DefaultIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.squashfs\shell
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.squashfs\shell\open
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.squashfs\shell\open\
command
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.squashfs\shellex
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.squashfs\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.squashfs\shellex\ContextMenuHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.squashfs\shellex\PropertySheetHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
WinZippers.squashfs\shellex\PropertySheetHandlers\
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
*\shellex\ContextMenuHandlers\
WinZipper
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Folder\shellex\ContextMenuHandlers\
WinZipper
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
Directory\shellex\ContextMenuHandlers\
WinZipper
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
lnkfile\shellex\ContextMenuHandlers\
WinZipper
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}\InprocServer32
It adds the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Fonts
Segoe UI(OpenType) = "segoeui.ttf"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Fonts
Segoe UI Bold(OpenType) = "segoeuib.ttf"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
WinZip
UninstallString = "%Program Files%\WinZipper\wzUninstall.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
WinZip
DisplayIcon = "%Program Files%\WinZipper\winziper.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
WinZip
DisplayVersion = "2.2.11"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
WinZip
URLInfoAbout = "http://www.{BLOCKED}pers.com"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
WinZip
Publisher = "Winzipper Pvt Ltd."
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
WinZip
DisplayName = "WinZip"
HKEY_LOCAL_MACHINE\SOFTWARE\WinZiper
path = "%Program Files%\WinZipper"
HKEY_LOCAL_MACHINE\SOFTWARE\WinZiper
Language = "49"
HKEY_LOCAL_MACHINE\SOFTWARE\WinZiper
cp = "2.2.11"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{1006967F-7059-4DB4-A310-4F1A30F7BDC4}
win = "576ed5ac"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Shell Extensions\
Approved
{DC638EEA-2BA2-4459-9C46-85A2F0BE6040} = "WinZipper Shell Extension"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}\InprocServer32
ThreadingModel = "Apartment"
It deletes the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
.zip\CompressedFolder\ShellNew
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
.zip\CompressedFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
.zip\OpenWithProgids
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
.zip\PersistentHandler
HKEY_CLASSES_ROOT\.zip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
.cab\PersistentHandler
HKEY_CLASSES_ROOT\.cab
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
.tar\PersistentHandler
HKEY_CLASSES_ROOT\.tar
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
.gz\PersistentHandler
HKEY_CLASSES_ROOT\.gz
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
.tgz\PersistentHandler
HKEY_CLASSES_ROOT\.tgz
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
.z\PersistentHandler
HKEY_CLASSES_ROOT\.z
Dropping Routine
This Trojan drops the following files:
- %User Temp%\istA.tmp\dlzipdata
- %User Temp%\istA.tmp\omigazip\main
- %User Temp%\istA.tmp\eInstall\main
- %User Temp%\istA.tmp\omigazip\image\default\additem.png
- %User Temp%\istA.tmp\eInstall\image\default\app_icon.png
- %User Temp%\istA.tmp\omigazip\image\default\app_icon.png
- %User Temp%\istA.tmp\omigazip\image\default\back.png
- %User Temp%\istA.tmp\omigazip\image\default\Background_Main.png
- %User Temp%\istA.tmp\omigazip\image\default\Background_Small_2.png
- %User Temp%\istA.tmp\eInstall\image\default\browse_button.png
- %User Temp%\istA.tmp\omigazip\image\default\browse_button.png
- %User Temp%\istA.tmp\omigazip\image\default\checkbox_blank.png
- %User Temp%\istA.tmp\omigazip\image\default\checkbox_select.png
- %User Temp%\istA.tmp\omigazip\image\default\combo.png
- %User Temp%\istA.tmp\eInstall\image\default\combo_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\combo_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\deleteitem.png
- %User Temp%\istA.tmp\omigazip\image\default\deskbtnbk.png
- %User Temp%\istA.tmp\eInstall\image\default\edit_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\edit_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\extractto.png
- %User Temp%\istA.tmp\omigazip\image\default\folder.png
- %User Temp%\istA.tmp\omigazip\image\default\footerbg.png
- %User Temp%\istA.tmp\eInstall\image\default\install_back.png
- %User Temp%\istA.tmp\omigazip\image\default\install_back.png
- %User Temp%\istA.tmp\omigazip\image\default\install_button_skin.png
- %User Temp%\istA.tmp\eInstall\image\default\install_check_checked.png
- %User Temp%\istA.tmp\omigazip\image\default\install_check_checked.png
- %User Temp%\istA.tmp\eInstall\image\default\install_check_intermediate.png
- %User Temp%\istA.tmp\omigazip\image\default\install_check_intermediate.png
- %User Temp%\istA.tmp\eInstall\image\default\install_check_uncheck.png
- %User Temp%\istA.tmp\omigazip\image\default\install_check_uncheck.png
- %User Temp%\istA.tmp\eInstall\image\default\install_logo.png
- %User Temp%\istA.tmp\omigazip\image\default\install_logo.png
- %User Temp%\istA.tmp\eInstall\image\default\install_new_button_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\install_new_button_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\listctrl_header_bk.png
- %User Temp%\istA.tmp\omigazip\image\default\listview_report.png
- %User Temp%\istA.tmp\omigazip\image\default\listview_thumb.png
- %User Temp%\istA.tmp\omigazip\image\default\menubg.png
- %User Temp%\istA.tmp\omigazip\image\default\menu_bkg.png
- %User Temp%\istA.tmp\omigazip\image\default\menu_item_over.png
- %User Temp%\istA.tmp\omigazip\image\default\onekeyextract.png
- %User Temp%\istA.tmp\omigazip\image\default\patch_file_icon.png
- %User Temp%\istA.tmp\eInstall\image\default\pic-error.png
- %User Temp%\istA.tmp\omigazip\image\default\pic-error.png
- %User Temp%\istA.tmp\eInstall\image\default\pic-info.png
- %User Temp%\istA.tmp\omigazip\image\default\pic-info.png
- %User Temp%\istA.tmp\eInstall\image\default\pic-question.png
- %User Temp%\istA.tmp\omigazip\image\default\pic-question.png
- %User Temp%\istA.tmp\eInstall\image\default\pic-warning.png
- %User Temp%\istA.tmp\omigazip\image\default\pic-warning.png
- %User Temp%\istA.tmp\eInstall\image\default\popup_dialog_bk.png
- %User Temp%\istA.tmp\omigazip\image\default\popup_dialog_bk.png
- %User Temp%\istA.tmp\eInstall\image\default\progressbar_bk.png
- %User Temp%\istA.tmp\omigazip\image\default\progressbar_bk.png
- %User Temp%\istA.tmp\eInstall\image\default\progressbar_image.png
- %User Temp%\istA.tmp\omigazip\image\default\progressbar_image.png
- %User Temp%\istA.tmp\omigazip\image\default\progress_bk.png
- %User Temp%\istA.tmp\omigazip\image\default\progress_meter.png
- %User Temp%\istA.tmp\omigazip\image\default\pwd_lock.png
- %User Temp%\istA.tmp\omigazip\image\default\pwd_unlock.png
- %User Temp%\istA.tmp\eInstall\image\default\radio_normal.png
- %User Temp%\istA.tmp\omigazip\image\default\radio_normal.png
- %User Temp%\istA.tmp\eInstall\image\default\radio_selected.png
- %User Temp%\istA.tmp\omigazip\image\default\radio_selected.png
- %User Temp%\istA.tmp\omigazip\image\default\settingbkg.png
- %User Temp%\istA.tmp\omigazip\image\default\settingtab.png
- %User Temp%\istA.tmp\omigazip\image\default\sys_button_close.png
- %User Temp%\istA.tmp\omigazip\image\default\sys_button_max.PNG
- %User Temp%\istA.tmp\omigazip\image\default\sys_button_min.PNG
- %User Temp%\istA.tmp\omigazip\image\default\sys_button_restore.PNG
- %User Temp%\istA.tmp\eInstall\image\default\sys_close.png
- %User Temp%\istA.tmp\omigazip\image\default\sys_close.png
- %User Temp%\istA.tmp\omigazip\image\default\tobutton1.png
- %User Temp%\istA.tmp\omigazip\image\default\vscroll.png
- %User Temp%\istA.tmp\omigazip\layout\default\about.xml
- %User Temp%\istA.tmp\omigazip\layout\default\brower.xml
- %User Temp%\istA.tmp\omigazip\layout\default\compresspath.xml
- %User Temp%\istA.tmp\omigazip\layout\default\compresspwd.xml
- %User Temp%\istA.tmp\omigazip\layout\default\error.xml
- %User Temp%\istA.tmp\omigazip\layout\default\extractpath.xml
- %User Temp%\istA.tmp\eInstall\layout\default\install_msgbox.xml
- %User Temp%\istA.tmp\omigazip\layout\default\install_msgbox.xml
- %User Temp%\istA.tmp\omigazip\image\default\install_resource.xml
- %User Temp%\istA.tmp\eInstall\image\default\install_resource.xml
- %User Temp%\istA.tmp\omigazip\style\install_style.xml
- %User Temp%\istA.tmp\eInstall\style\install_style.xml
- %User Temp%\istA.tmp\eInstall\layout\default\languageSelect.xml
- %User Temp%\istA.tmp\omigazip\layout\default\languageSelect.xml
- %User Temp%\istA.tmp\omigazip\layout\default\msgbox.xml
- %User Temp%\istA.tmp\eInstall\layout\default\OmigaZipInstall.xml
- %User Temp%\istA.tmp\omigazip\layout\default\OmigaZipInstall.xml
- %User Temp%\istA.tmp\omigazip\layout\default\overwrite.xml
- %User Temp%\istA.tmp\omigazip\layout\default\password.xml
- %User Temp%\istA.tmp\omigazip\layout\default\progress.xml
- %User Temp%\istA.tmp\omigazip\layout\default\rename.xml
- %User Temp%\istA.tmp\omigazip\image\default\resource.xml
- %User Temp%\istA.tmp\omigazip\layout\default\setting.xml
- %User Temp%\istA.tmp\omigazip\style\style.xml
- %User Temp%\istA.tmp\eInstall\layout\default\uninstOmigaZip.xml
- %User Temp%\istA.tmp\omigazip\layout\default\uninstOmigaZip.xml
- %User Temp%\istA.tmp\omigazip\language\es_es\eCompress_lang.ini
- %User Temp%\istA.tmp\omigazip\language\en_us\eCompress_lang.ini
- %User Temp%\istA.tmp\omigazip\language\pt_br\eCompress_lang.ini
- %User Temp%\istA.tmp\omigazip\language\tr_tr\eCompress_lang.ini
- %User Temp%\istA.tmp\omigazip\language\es_es\install_lang.ini
- %User Temp%\istA.tmp\omigazip\language\en_us\install_lang.ini
- %User Temp%\istA.tmp\omigazip\language\pt_br\install_lang.ini
- %User Temp%\istA.tmp\omigazip\language\tr_tr\install_lang.ini
- %User Temp%\istA.tmp\eInstall\language\en_us\install_lang.ini
- %User Temp%\istA.tmp\omigazip\wz_settings.ini
- %User Temp%\istA.tmp\eInstall\segoeui.ttf
- %User Temp%\istA.tmp\eInstall\segoeuib.ttf
- %User Temp%\istA.tmp\eInstall\Install\OmigaZip.inst
- %User Temp%\istA.tmp\omigazip\uninstaller\OmigaZip.inst
- %User Temp%\istA.tmp\eInstall\eInstall.exe
- %User Temp%\istA.tmp\omigazip\winziper.exe
- %User Temp%\istA.tmp\omigazip\winzipersvc.exe
- %User Temp%\istA.tmp\omigazip\wzdl.exe
- %User Temp%\istA.tmp\omigazip\wzUninstall.exe
- %User Temp%\istA.tmp\omigazip\wzUpg.exe
- %User Temp%\istA.tmp\omigazip\7z.dll
- %User Temp%\istA.tmp\omigazip\curlpp.dll
- %User Temp%\istA.tmp\omigazip\libcurl.dll
- %User Temp%\istA.tmp\omigazip\libeay32.dll
- %User Temp%\istA.tmp\omigazip\msvcp110.dll
- %User Temp%\istA.tmp\omigazip\msvcr110.dll
- %User Temp%\istA.tmp\omigazip\ssleay32.dll
- %User Temp%\istA.tmp\omigazip\wzShellctx.dll
- %User Temp%\istA.tmp\omigazip\wzShellctx64.dll
- %User Temp%\istA.tmp\omigazip\zlib1.dll
- %Start Menu%\Programs\WinZip\Uninstall.lnk
- %Program Files%\WinZipper\segoeui.ttf
- %Program Files%\WinZipper\segoeuib.ttf
- %Program Files%\WinZipper\main
- %Program Files%\WinZipper\wzShellctx.dll
- %Program Files%\WinZipper\ebase.dll
- %Program Files%\WinZipper\7z.dll
- %Program Files%\WinZipper\curlpp.dll
- %Program Files%\WinZipper\libcurl.dll
- %Program Files%\WinZipper\libeay32.dll
- %Program Files%\WinZipper\ssleay32.dll
- %Program Files%\WinZipper\msvcp110.dll
- %Program Files%\WinZipper\msvcr110.dll
- %Program Files%\WinZipper\zlib1.dll
- %Program Files%\WinZipper\libpng.dll
- %Program Files%\WinZipper\ouilibnl.dll
- %Program Files%\WinZipper\winziper.exe
- %Program Files%\WinZipper\wzUninstall.exe
- %Program Files%\WinZipper\wzdl.exe
- %Program Files%\WinZipper\winzipersvc.exe
- %Program Files%\WinZipper\sqlite3.dll
- %Program Files%\WinZipper\wzUpg.exe
- %Program Files%\WinZipper\wz_settings.ini
- %System%\msvcp110.dll
- %System%\msvcr110.dll
(Note: %User Temp% is the user's temporary folder, where it usually is C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\Users\{user name}\AppData\Local\Temp on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.. %Start Menu% is the Start Menu folder, where it usually is C:\Documents and Settings\{user name}\Start Menu on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\Users\{user name}\AppData\Roaming\Microsoft\Windows\Start Menu on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.. %Program Files% is the Program Files folder, where it usually is C:\Program Files on all Windows operating system versions; C:\Program Files (x86) for 32-bit applications running on Windows 64-bit operating systems.. %System% is the Windows system folder, where it usually is C:\Windows\System32 on all Windows operating system versions.)
Other Details
This Trojan connects to the following possibly malicious URL:
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/vmwarexvirtualxidexhardxdrive_00000000000000000001?action=wzp.1.0202011.100
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/vmwarexvirtualxidexhardxdrive_00000000000000000001?action=wzp.1.0202011.101
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/vmwarexvirtualxidexhardxdrive_00000000000000000001?action=wzp.1.0202011.2
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/Public/softs/wzp/2.2.11/all/newzp.exe
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/vmwarexvirtualxidexhardxdrive_00000000000000000001?action=wzp.1.0202011.4
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/vmwarexvirtualxidexhardxdrive_00000000000000000001?action=wzp.1.0202011.6
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/vmwarexvirtualxidexhardxdrive_00000000000000000001?action=wzp.1.0202011.8
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/vmwarexvirtualxidexhardxdrive_00000000000000000001?action=wzp.1.0202011.12
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/VMwareXVirtualXIDEXHardXDrive_00000000000000000001?action=wzp.2.0202011.15
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/VMwareXVirtualXIDEXHardXDrive_00000000000000000001?action=wzp.2.0202011.3
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/VMwareXVirtualXIDEXHardXDrive_00000000000000000001?action=wzp.2.0202011.4
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/VMwareXVirtualXIDEXHardXDrive_00000000000000000001?action=wzp.2.0202011.5
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/VMwareXVirtualXIDEXHardXDrive_00000000000000000001?action=wzp.2.0202011.6
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/VMwareXVirtualXIDEXHardXDrive_00000000000000000001?action=wzp.2.0202011.7
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/VMwareXVirtualXIDEXHardXDrive_00000000000000000001?action=wzp.2.0202011.8
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/VMwareXVirtualXIDEXHardXDrive_00000000000000000001?action=wzp.2.0202011.9
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/VMwareXVirtualXIDEXHardXDrive_00000000000000000001?action=wzp.2.0202011.10
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/VMwareXVirtualXIDEXHardXDrive_00000000000000000001?action=wzp.2.0202011.11
- http://d1wmnlsnh8rftl.{BLOCKED}ront.net/v4/sof-pbd-dl/VMwareXVirtualXIDEXHardXDrive_00000000000000000001?action=wzp.2.0202011.12
- {BLOCKED}.141.184
- {BLOCKED}.141.198
This report is generated via an automated analysis system.
SOLUTION
9.8
Step 1
Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must disable System Restore to allow full scanning of their computers.
Step 2
Delete this registry key
Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
- WinZip
- In HKEY_LOCAL_MACHINE\Software
- WinZiper
- In HKEY_CLASSES_ROOT\CLSID
- {1006967F-7059-4DB4-A310-4F1A30F7BDC4}
- In HKEY_CLASSES_ROOT
- .7z
- In HKEY_CLASSES_ROOT
- WinZippers.7z
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.7z
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.7z
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.7z\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.7z\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.7z
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.7z\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.7z\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.7z\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.7z\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.7z\shellex
- DropHandler
- In HKEY_CLASSES_ROOT
- WinZippers.zip
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.zip
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.zip
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.zip\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.zip\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.zip
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.zip\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.zip\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.zip\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.zip\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.zip\shellex
- DropHandler
- In HKEY_CLASSES_ROOT
- .rar
- In HKEY_CLASSES_ROOT
- WinZippers.rar
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rar
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rar
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rar\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rar\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rar
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rar\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rar\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rar\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rar\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .001
- In HKEY_CLASSES_ROOT
- WinZippers.001
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.001
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.001
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.001\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.001\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.001
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.001\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.001\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.001\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.001\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- WinZippers.cab
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cab
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cab
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cab\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cab\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cab
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cab\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cab\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cab\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cab\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .iso
- In HKEY_CLASSES_ROOT
- WinZippers.iso
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.iso
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.iso
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.iso\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.iso\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.iso
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.iso\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.iso\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.iso\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.iso\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .xz
- In HKEY_CLASSES_ROOT
- WinZippers.xz
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xz
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xz
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xz\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xz\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xz
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xz\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xz\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xz\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xz\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .txz
- In HKEY_CLASSES_ROOT
- WinZippers.txz
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.txz
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.txz
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.txz\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.txz\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.txz
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.txz\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.txz\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.txz\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.txz\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .lzma
- In HKEY_CLASSES_ROOT
- WinZippers.lzma
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzma
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzma
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzma\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzma\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzma
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzma\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzma\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzma\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzma\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- WinZippers.tar
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tar
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tar
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tar\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tar\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tar
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tar\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tar\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tar\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tar\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tar\shellex
- DropHandler
- In HKEY_CLASSES_ROOT
- .cpio
- In HKEY_CLASSES_ROOT
- WinZippers.cpio
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cpio
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cpio
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cpio\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cpio\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cpio
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cpio\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cpio\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cpio\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.cpio\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .bz2
- In HKEY_CLASSES_ROOT
- WinZippers.bz2
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bz2
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bz2
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bz2\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bz2\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bz2
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bz2\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bz2\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bz2\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bz2\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .bzip2
- In HKEY_CLASSES_ROOT
- WinZippers.bzip2
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bzip2
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bzip2
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bzip2\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bzip2\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bzip2
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bzip2\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bzip2\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bzip2\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.bzip2\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .tbz2
- In HKEY_CLASSES_ROOT
- WinZippers.tbz2
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz2
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz2
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz2\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz2\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz2
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz2\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz2\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz2\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz2\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .tbz
- In HKEY_CLASSES_ROOT
- WinZippers.tbz
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tbz\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- WinZippers.gz
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gz
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gz
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gz\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gz\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gz
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gz\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gz\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gz\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gz\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .gzip
- In HKEY_CLASSES_ROOT
- WinZippers.gzip
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gzip
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gzip
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gzip\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gzip\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gzip
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gzip\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gzip\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gzip\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.gzip\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- WinZippers.tgz
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tgz
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tgz
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tgz\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tgz\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tgz
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tgz\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tgz\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tgz\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tgz\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .tpz
- In HKEY_CLASSES_ROOT
- WinZippers.tpz
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tpz
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tpz
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tpz\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tpz\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tpz
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tpz\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tpz\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tpz\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.tpz\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- WinZippers.z
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.z
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.z
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.z\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.z\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.z
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.z\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.z\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.z\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.z\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .taz
- In HKEY_CLASSES_ROOT
- WinZippers.taz
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.taz
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.taz
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.taz\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.taz\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.taz
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.taz\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.taz\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.taz\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.taz\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .lzh
- In HKEY_CLASSES_ROOT
- WinZippers.lzh
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzh
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzh
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzh\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzh\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzh
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzh\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzh\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzh\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lzh\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .lha
- In HKEY_CLASSES_ROOT
- WinZippers.lha
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lha
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lha
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lha\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lha\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lha
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lha\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lha\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lha\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.lha\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .rpm
- In HKEY_CLASSES_ROOT
- WinZippers.rpm
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rpm
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rpm
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rpm\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rpm\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rpm
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rpm\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rpm\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rpm\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.rpm\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .deb
- In HKEY_CLASSES_ROOT
- WinZippers.deb
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.deb
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.deb
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.deb\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.deb\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.deb
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.deb\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.deb\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.deb\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.deb\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .arj
- In HKEY_CLASSES_ROOT
- WinZippers.arj
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.arj
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.arj
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.arj\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.arj\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.arj
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.arj\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.arj\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.arj\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.arj\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .vhd
- In HKEY_CLASSES_ROOT
- WinZippers.vhd
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.vhd
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.vhd
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.vhd\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.vhd\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.vhd
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.vhd\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.vhd\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.vhd\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.vhd\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .wim
- In HKEY_CLASSES_ROOT
- WinZippers.wim
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.wim
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.wim
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.wim\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.wim\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.wim
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.wim\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.wim\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.wim\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.wim\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .swm
- In HKEY_CLASSES_ROOT
- WinZippers.swm
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.swm
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.swm
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.swm\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.swm\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.swm
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.swm\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.swm\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.swm\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.swm\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .fat
- In HKEY_CLASSES_ROOT
- WinZippers.fat
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.fat
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.fat
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.fat\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.fat\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.fat
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.fat\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.fat\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.fat\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.fat\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .ntfs
- In HKEY_CLASSES_ROOT
- WinZippers.ntfs
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.ntfs
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.ntfs
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.ntfs\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.ntfs\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.ntfs
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.ntfs\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.ntfs\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.ntfs\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.ntfs\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .dmg
- In HKEY_CLASSES_ROOT
- WinZippers.dmg
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.dmg
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.dmg
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.dmg\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.dmg\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.dmg
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.dmg\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.dmg\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.dmg\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.dmg\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .hfs
- In HKEY_CLASSES_ROOT
- WinZippers.hfs
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.hfs
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.hfs
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.hfs\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.hfs\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.hfs
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.hfs\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.hfs\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.hfs\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.hfs\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .xar
- In HKEY_CLASSES_ROOT
- WinZippers.xar
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xar
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xar
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xar\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xar\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xar
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xar\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xar\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xar\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.xar\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_CLASSES_ROOT
- .squashfs
- In HKEY_CLASSES_ROOT
- WinZippers.squashfs
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.squashfs
- DefaultIcon
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.squashfs
- shell
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.squashfs\shell
- open
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.squashfs\shell\open
- command
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.squashfs
- shellex
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.squashfs\shellex
- ContextMenuHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.squashfs\shellex\ContextMenuHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.squashfs\shellex
- PropertySheetHandlers
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZippers.squashfs\shellex\PropertySheetHandlers
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers
- WinZipper
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers
- WinZipper
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers
- WinZipper
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers
- WinZipper
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}
- InprocServer32
Step 3
Delete this registry value
Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
- Segoe UI(OpenType) = "segoeui.ttf"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
- Segoe UI Bold(OpenType) = "segoeuib.ttf"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip
- UninstallString = "%Program Files%\WinZipper\wzUninstall.exe"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip
- DisplayIcon = "%Program Files%\WinZipper\winziper.exe"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip
- DisplayVersion = "2.2.11"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip
- URLInfoAbout = "http://www.{BLOCKED}pers.com"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip
- Publisher = "Winzipper Pvt Ltd."
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip
- DisplayName = "WinZip"
- In HKEY_LOCAL_MACHINE\SOFTWARE\WinZiper
- path = "%Program Files%\WinZipper"
- In HKEY_LOCAL_MACHINE\SOFTWARE\WinZiper
- Language = "49"
- In HKEY_LOCAL_MACHINE\SOFTWARE\WinZiper
- cp = "2.2.11"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1006967F-7059-4DB4-A310-4F1A30F7BDC4}
- win = "576ed5ac"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
- {DC638EEA-2BA2-4459-9C46-85A2F0BE6040} = "WinZipper Shell Extension"
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DC638EEA-2BA2-4459-9C46-85A2F0BE6040}\InprocServer32
- ThreadingModel = "Apartment"
Step 4
Search and delete these components
- %User Temp%\istA.tmp\dlzipdata
- %User Temp%\istA.tmp\omigazip\main
- %User Temp%\istA.tmp\eInstall\main
- %User Temp%\istA.tmp\omigazip\image\default\additem.png
- %User Temp%\istA.tmp\eInstall\image\default\app_icon.png
- %User Temp%\istA.tmp\omigazip\image\default\app_icon.png
- %User Temp%\istA.tmp\omigazip\image\default\back.png
- %User Temp%\istA.tmp\omigazip\image\default\Background_Main.png
- %User Temp%\istA.tmp\omigazip\image\default\Background_Small_2.png
- %User Temp%\istA.tmp\eInstall\image\default\browse_button.png
- %User Temp%\istA.tmp\omigazip\image\default\browse_button.png
- %User Temp%\istA.tmp\omigazip\image\default\checkbox_blank.png
- %User Temp%\istA.tmp\omigazip\image\default\checkbox_select.png
- %User Temp%\istA.tmp\omigazip\image\default\combo.png
- %User Temp%\istA.tmp\eInstall\image\default\combo_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\combo_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\deleteitem.png
- %User Temp%\istA.tmp\omigazip\image\default\deskbtnbk.png
- %User Temp%\istA.tmp\eInstall\image\default\edit_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\edit_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\extractto.png
- %User Temp%\istA.tmp\omigazip\image\default\folder.png
- %User Temp%\istA.tmp\omigazip\image\default\footerbg.png
- %User Temp%\istA.tmp\eInstall\image\default\install_back.png
- %User Temp%\istA.tmp\omigazip\image\default\install_back.png
- %User Temp%\istA.tmp\omigazip\image\default\install_button_skin.png
- %User Temp%\istA.tmp\eInstall\image\default\install_check_checked.png
- %User Temp%\istA.tmp\omigazip\image\default\install_check_checked.png
- %User Temp%\istA.tmp\eInstall\image\default\install_check_intermediate.png
- %User Temp%\istA.tmp\omigazip\image\default\install_check_intermediate.png
- %User Temp%\istA.tmp\eInstall\image\default\install_check_uncheck.png
- %User Temp%\istA.tmp\omigazip\image\default\install_check_uncheck.png
- %User Temp%\istA.tmp\eInstall\image\default\install_logo.png
- %User Temp%\istA.tmp\omigazip\image\default\install_logo.png
- %User Temp%\istA.tmp\eInstall\image\default\install_new_button_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\install_new_button_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\listctrl_header_bk.png
- %User Temp%\istA.tmp\omigazip\image\default\listview_report.png
- %User Temp%\istA.tmp\omigazip\image\default\listview_thumb.png
- %User Temp%\istA.tmp\omigazip\image\default\menubg.png
- %User Temp%\istA.tmp\omigazip\image\default\menu_bkg.png
- %User Temp%\istA.tmp\omigazip\image\default\menu_item_over.png
- %User Temp%\istA.tmp\omigazip\image\default\onekeyextract.png
- %User Temp%\istA.tmp\omigazip\image\default\patch_file_icon.png
- %User Temp%\istA.tmp\eInstall\image\default\pic-error.png
- %User Temp%\istA.tmp\omigazip\image\default\pic-error.png
- %User Temp%\istA.tmp\eInstall\image\default\pic-info.png
- %User Temp%\istA.tmp\omigazip\image\default\pic-info.png
- %User Temp%\istA.tmp\eInstall\image\default\pic-question.png
- %User Temp%\istA.tmp\omigazip\image\default\pic-question.png
- %User Temp%\istA.tmp\eInstall\image\default\pic-warning.png
- %User Temp%\istA.tmp\omigazip\image\default\pic-warning.png
- %User Temp%\istA.tmp\eInstall\image\default\popup_dialog_bk.png
- %User Temp%\istA.tmp\omigazip\image\default\popup_dialog_bk.png
- %User Temp%\istA.tmp\eInstall\image\default\progressbar_bk.png
- %User Temp%\istA.tmp\omigazip\image\default\progressbar_bk.png
- %User Temp%\istA.tmp\eInstall\image\default\progressbar_image.png
- %User Temp%\istA.tmp\omigazip\image\default\progressbar_image.png
- %User Temp%\istA.tmp\omigazip\image\default\progress_bk.png
- %User Temp%\istA.tmp\omigazip\image\default\progress_meter.png
- %User Temp%\istA.tmp\omigazip\image\default\pwd_lock.png
- %User Temp%\istA.tmp\omigazip\image\default\pwd_unlock.png
- %User Temp%\istA.tmp\eInstall\image\default\radio_normal.png
- %User Temp%\istA.tmp\omigazip\image\default\radio_normal.png
- %User Temp%\istA.tmp\eInstall\image\default\radio_selected.png
- %User Temp%\istA.tmp\omigazip\image\default\radio_selected.png
- %User Temp%\istA.tmp\omigazip\image\default\settingbkg.png
- %User Temp%\istA.tmp\omigazip\image\default\settingtab.png
- %User Temp%\istA.tmp\omigazip\image\default\sys_button_close.png
- %User Temp%\istA.tmp\omigazip\image\default\sys_button_max.PNG
- %User Temp%\istA.tmp\omigazip\image\default\sys_button_min.PNG
- %User Temp%\istA.tmp\omigazip\image\default\sys_button_restore.PNG
- %User Temp%\istA.tmp\eInstall\image\default\sys_close.png
- %User Temp%\istA.tmp\omigazip\image\default\sys_close.png
- %User Temp%\istA.tmp\omigazip\image\default\tobutton1.png
- %User Temp%\istA.tmp\omigazip\image\default\vscroll.png
- %User Temp%\istA.tmp\omigazip\layout\default\about.xml
- %User Temp%\istA.tmp\omigazip\layout\default\brower.xml
- %User Temp%\istA.tmp\omigazip\layout\default\compresspath.xml
- %User Temp%\istA.tmp\omigazip\layout\default\compresspwd.xml
- %User Temp%\istA.tmp\omigazip\layout\default\error.xml
- %User Temp%\istA.tmp\omigazip\layout\default\extractpath.xml
- %User Temp%\istA.tmp\eInstall\layout\default\install_msgbox.xml
- %User Temp%\istA.tmp\omigazip\layout\default\install_msgbox.xml
- %User Temp%\istA.tmp\omigazip\image\default\install_resource.xml
- %User Temp%\istA.tmp\eInstall\image\default\install_resource.xml
- %User Temp%\istA.tmp\omigazip\style\install_style.xml
- %User Temp%\istA.tmp\eInstall\style\install_style.xml
- %User Temp%\istA.tmp\eInstall\layout\default\languageSelect.xml
- %User Temp%\istA.tmp\omigazip\layout\default\languageSelect.xml
- %User Temp%\istA.tmp\omigazip\layout\default\msgbox.xml
- %User Temp%\istA.tmp\eInstall\layout\default\OmigaZipInstall.xml
- %User Temp%\istA.tmp\omigazip\layout\default\OmigaZipInstall.xml
- %User Temp%\istA.tmp\omigazip\layout\default\overwrite.xml
- %User Temp%\istA.tmp\omigazip\layout\default\password.xml
- %User Temp%\istA.tmp\omigazip\layout\default\progress.xml
- %User Temp%\istA.tmp\omigazip\layout\default\rename.xml
- %User Temp%\istA.tmp\omigazip\image\default\resource.xml
- %User Temp%\istA.tmp\omigazip\layout\default\setting.xml
- %User Temp%\istA.tmp\omigazip\style\style.xml
- %User Temp%\istA.tmp\eInstall\layout\default\uninstOmigaZip.xml
- %User Temp%\istA.tmp\omigazip\layout\default\uninstOmigaZip.xml
- %User Temp%\istA.tmp\omigazip\language\es_es\eCompress_lang.ini
- %User Temp%\istA.tmp\omigazip\language\en_us\eCompress_lang.ini
- %User Temp%\istA.tmp\omigazip\language\pt_br\eCompress_lang.ini
- %User Temp%\istA.tmp\omigazip\language\tr_tr\eCompress_lang.ini
- %User Temp%\istA.tmp\omigazip\language\es_es\install_lang.ini
- %User Temp%\istA.tmp\omigazip\language\en_us\install_lang.ini
- %User Temp%\istA.tmp\omigazip\language\pt_br\install_lang.ini
- %User Temp%\istA.tmp\omigazip\language\tr_tr\install_lang.ini
- %User Temp%\istA.tmp\eInstall\language\en_us\install_lang.ini
- %User Temp%\istA.tmp\omigazip\wz_settings.ini
- %User Temp%\istA.tmp\eInstall\segoeui.ttf
- %User Temp%\istA.tmp\eInstall\segoeuib.ttf
- %User Temp%\istA.tmp\eInstall\Install\OmigaZip.inst
- %User Temp%\istA.tmp\omigazip\uninstaller\OmigaZip.inst
- %User Temp%\istA.tmp\eInstall\eInstall.exe
- %User Temp%\istA.tmp\omigazip\winziper.exe
- %User Temp%\istA.tmp\omigazip\winzipersvc.exe
- %User Temp%\istA.tmp\omigazip\wzdl.exe
- %User Temp%\istA.tmp\omigazip\wzUninstall.exe
- %User Temp%\istA.tmp\omigazip\wzUpg.exe
- %User Temp%\istA.tmp\omigazip\7z.dll
- %User Temp%\istA.tmp\omigazip\curlpp.dll
- %User Temp%\istA.tmp\omigazip\libcurl.dll
- %User Temp%\istA.tmp\omigazip\libeay32.dll
- %User Temp%\istA.tmp\omigazip\msvcp110.dll
- %User Temp%\istA.tmp\omigazip\msvcr110.dll
- %User Temp%\istA.tmp\omigazip\ssleay32.dll
- %User Temp%\istA.tmp\omigazip\wzShellctx.dll
- %User Temp%\istA.tmp\omigazip\wzShellctx64.dll
- %User Temp%\istA.tmp\omigazip\zlib1.dll
- %Start Menu%\Programs\WinZip\Uninstall.lnk
- %Program Files%\WinZipper\segoeui.ttf
- %Program Files%\WinZipper\segoeuib.ttf
- %Program Files%\WinZipper\main
- %Program Files%\WinZipper\wzShellctx.dll
- %Program Files%\WinZipper\ebase.dll
- %Program Files%\WinZipper\7z.dll
- %Program Files%\WinZipper\curlpp.dll
- %Program Files%\WinZipper\libcurl.dll
- %Program Files%\WinZipper\libeay32.dll
- %Program Files%\WinZipper\ssleay32.dll
- %Program Files%\WinZipper\msvcp110.dll
- %Program Files%\WinZipper\msvcr110.dll
- %Program Files%\WinZipper\zlib1.dll
- %Program Files%\WinZipper\libpng.dll
- %Program Files%\WinZipper\ouilibnl.dll
- %Program Files%\WinZipper\winziper.exe
- %Program Files%\WinZipper\wzUninstall.exe
- %Program Files%\WinZipper\wzdl.exe
- %Program Files%\WinZipper\winzipersvc.exe
- %Program Files%\WinZipper\sqlite3.dll
- %Program Files%\WinZipper\wzUpg.exe
- %Program Files%\WinZipper\wz_settings.ini
- %System%\msvcp110.dll
- %System%\msvcr110.dll
Step 5
Search and delete these folders
- %User Temp%\istA.tmp
- %User Temp%\istA.tmp\eInstall
- %User Temp%\istA.tmp\eInstall\image
- %User Temp%\istA.tmp\eInstall\image\default
- %User Temp%\istA.tmp\eInstall\Install
- %User Temp%\istA.tmp\eInstall\language
- %User Temp%\istA.tmp\eInstall\language\en_us
- %User Temp%\istA.tmp\eInstall\layout
- %User Temp%\istA.tmp\eInstall\layout\default
- %User Temp%\istA.tmp\eInstall\style
- %User Temp%\istA.tmp\omigazip
- %User Temp%\istA.tmp\omigazip\image
- %User Temp%\istA.tmp\omigazip\image\default
- %User Temp%\istA.tmp\omigazip\language
- %User Temp%\istA.tmp\omigazip\language\en_us
- %User Temp%\istA.tmp\omigazip\language\es_es
- %User Temp%\istA.tmp\omigazip\language\pt_br
- %User Temp%\istA.tmp\omigazip\language\tr_tr
- %User Temp%\istA.tmp\omigazip\language\zh_cn
- %User Temp%\istA.tmp\omigazip\language\zh_tw
- %User Temp%\istA.tmp\omigazip\layout
- %User Temp%\istA.tmp\omigazip\layout\default
- %User Temp%\istA.tmp\omigazip\style
- %User Temp%\istA.tmp\omigazip\uninstaller
- %User Profile%\Application Data\eCyber
Step 6
Scan your computer with your Trend Micro product to delete files detected as PUA_SubTab. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.
Step 7
Restore this file from backup only Microsoft-related files will be restored. If this malware/grayware also deleted files related to programs that are not from Microsoft, please reinstall those programs on you computer again.
- %User Temp%\istA.tmp
- %User Temp%\~dl5.tmp
- %User Temp%\istA.tmp\eInstall\eInstall.exe
- %User Temp%\istA.tmp\eInstall\image\default\app_icon.png
- %User Temp%\istA.tmp\eInstall\image\default\browse_button.png
- %User Temp%\istA.tmp\eInstall\image\default\combo_skin.png
- %User Temp%\istA.tmp\eInstall\image\default\edit_skin.png
- %User Temp%\istA.tmp\eInstall\image\default\install_back.png
- %User Temp%\istA.tmp\eInstall\image\default\install_check_checked.png
- %User Temp%\istA.tmp\eInstall\image\default\install_check_intermediate.png
- %User Temp%\istA.tmp\eInstall\image\default\install_check_uncheck.png
- %User Temp%\istA.tmp\eInstall\image\default\install_logo.png
- %User Temp%\istA.tmp\eInstall\image\default\install_new_button_skin.png
- %User Temp%\istA.tmp\eInstall\image\default\install_resource.xml
- %User Temp%\istA.tmp\eInstall\image\default\pic-error.png
- %User Temp%\istA.tmp\eInstall\image\default\pic-info.png
- %User Temp%\istA.tmp\eInstall\image\default\pic-question.png
- %User Temp%\istA.tmp\eInstall\image\default\pic-warning.png
- %User Temp%\istA.tmp\eInstall\image\default\popup_dialog_bk.png
- %User Temp%\istA.tmp\eInstall\image\default\progressbar_bk.png
- %User Temp%\istA.tmp\eInstall\image\default\progressbar_image.png
- %User Temp%\istA.tmp\eInstall\image\default\radio_normal.png
- %User Temp%\istA.tmp\eInstall\image\default\radio_selected.png
- %User Temp%\istA.tmp\eInstall\image\default\sys_close.png
- %User Temp%\istA.tmp\eInstall\Install\OmigaZip.inst
- %User Temp%\istA.tmp\eInstall\language\en_us\install_lang.ini
- %User Temp%\istA.tmp\eInstall\layout\default\install_msgbox.xml
- %User Temp%\istA.tmp\eInstall\layout\default\languageSelect.xml
- %User Temp%\istA.tmp\eInstall\layout\default\OmigaZipInstall.xml
- %User Temp%\istA.tmp\eInstall\layout\default\uninstOmigaZip.xml
- %User Temp%\istA.tmp\eInstall\main
- %User Temp%\istA.tmp\eInstall\segoeui.ttf
- %User Temp%\istA.tmp\eInstall\segoeuib.ttf
- %User Temp%\istA.tmp\eInstall\style\install_style.xml
- %User Temp%\istA.tmp\omigazip\7z.dll
- %User Temp%\istA.tmp\omigazip\curlpp.dll
- %User Temp%\istA.tmp\omigazip\image\default\additem.png
- %User Temp%\istA.tmp\omigazip\image\default\app_icon.png
- %User Temp%\istA.tmp\omigazip\image\default\back.png
- %User Temp%\istA.tmp\omigazip\image\default\Background_Main.png
- %User Temp%\istA.tmp\omigazip\image\default\Background_Small_2.png
- %User Temp%\istA.tmp\omigazip\image\default\browse_button.png
- %User Temp%\istA.tmp\omigazip\image\default\checkbox_blank.png
- %User Temp%\istA.tmp\omigazip\image\default\checkbox_select.png
- %User Temp%\istA.tmp\omigazip\image\default\combo.png
- %User Temp%\istA.tmp\omigazip\image\default\combo_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\deleteitem.png
- %User Temp%\istA.tmp\omigazip\image\default\deskbtnbk.png
- %User Temp%\istA.tmp\omigazip\image\default\edit_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\extractto.png
- %User Temp%\istA.tmp\omigazip\image\default\folder.png
- %User Temp%\istA.tmp\omigazip\image\default\footerbg.png
- %User Temp%\istA.tmp\omigazip\image\default\install_back.png
- %User Temp%\istA.tmp\omigazip\image\default\install_button_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\install_check_checked.png
- %User Temp%\istA.tmp\omigazip\image\default\install_check_intermediate.png
- %User Temp%\istA.tmp\omigazip\image\default\install_check_uncheck.png
- %User Temp%\istA.tmp\omigazip\image\default\install_logo.png
- %User Temp%\istA.tmp\omigazip\image\default\install_new_button_skin.png
- %User Temp%\istA.tmp\omigazip\image\default\install_resource.xml
- %User Temp%\istA.tmp\omigazip\image\default\listctrl_header_bk.png
- %User Temp%\istA.tmp\omigazip\image\default\listview_report.png
- %User Temp%\istA.tmp\omigazip\image\default\listview_thumb.png
- %User Temp%\istA.tmp\omigazip\image\default\menubg.png
- %User Temp%\istA.tmp\omigazip\image\default\menu_bkg.png
- %User Temp%\istA.tmp\omigazip\image\default\menu_item_over.png
- %User Temp%\istA.tmp\omigazip\image\default\onekeyextract.png
- %User Temp%\istA.tmp\omigazip\image\default\patch_file_icon.png
- %User Temp%\istA.tmp\omigazip\image\default\pic-error.png
- %User Temp%\istA.tmp\omigazip\image\default\pic-info.png
- %User Temp%\istA.tmp\omigazip\image\default\pic-question.png
- %User Temp%\istA.tmp\omigazip\image\default\pic-warning.png
- %User Temp%\istA.tmp\omigazip\image\default\popup_dialog_bk.png
- %User Temp%\istA.tmp\omigazip\image\default\progressbar_bk.png
- %User Temp%\istA.tmp\omigazip\image\default\progressbar_image.png
- %User Temp%\istA.tmp\omigazip\image\default\progress_bk.png
- %User Temp%\istA.tmp\omigazip\image\default\progress_meter.png
- %User Temp%\istA.tmp\omigazip\image\default\pwd_lock.png
- %User Temp%\istA.tmp\omigazip\image\default\pwd_unlock.png
- %User Temp%\istA.tmp\omigazip\image\default\radio_normal.png
- %User Temp%\istA.tmp\omigazip\image\default\radio_selected.png
- %User Temp%\istA.tmp\omigazip\image\default\resource.xml
- %User Temp%\istA.tmp\omigazip\image\default\settingbkg.png
- %User Temp%\istA.tmp\omigazip\image\default\settingtab.png
- %User Temp%\istA.tmp\omigazip\image\default\sys_button_close.png
- %User Temp%\istA.tmp\omigazip\image\default\sys_button_max.PNG
- %User Temp%\istA.tmp\omigazip\image\default\sys_button_min.PNG
- %User Temp%\istA.tmp\omigazip\image\default\sys_button_restore.PNG
- %User Temp%\istA.tmp\omigazip\image\default\sys_close.png
- %User Temp%\istA.tmp\omigazip\image\default\tobutton1.png
- %User Temp%\istA.tmp\omigazip\image\default\vscroll.png
- %User Temp%\istA.tmp\omigazip\language\en_us\eCompress_lang.ini
- %User Temp%\istA.tmp\omigazip\language\en_us\install_lang.ini
- %User Temp%\istA.tmp\omigazip\language\es_es\eCompress_lang.ini
- %User Temp%\istA.tmp\omigazip\language\es_es\install_lang.ini
- %User Temp%\istA.tmp\omigazip\language\pt_br\eCompress_lang.ini
- %User Temp%\istA.tmp\omigazip\language\pt_br\install_lang.ini
- %User Temp%\istA.tmp\omigazip\language\tr_tr\eCompress_lang.ini
- %User Temp%\istA.tmp\omigazip\language\tr_tr\install_lang.ini
- %User Temp%\istA.tmp\omigazip\layout\default\about.xml
- %User Temp%\istA.tmp\omigazip\layout\default\brower.xml
- %User Temp%\istA.tmp\omigazip\layout\default\compresspath.xml
- %User Temp%\istA.tmp\omigazip\layout\default\compresspwd.xml
- %User Temp%\istA.tmp\omigazip\layout\default\error.xml
- %User Temp%\istA.tmp\omigazip\layout\default\extractpath.xml
- %User Temp%\istA.tmp\omigazip\layout\default\install_msgbox.xml
- %User Temp%\istA.tmp\omigazip\layout\default\languageSelect.xml
- %User Temp%\istA.tmp\omigazip\layout\default\msgbox.xml
- %User Temp%\istA.tmp\omigazip\layout\default\OmigaZipInstall.xml
- %User Temp%\istA.tmp\omigazip\layout\default\overwrite.xml
- %User Temp%\istA.tmp\omigazip\layout\default\password.xml
- %User Temp%\istA.tmp\omigazip\layout\default\progress.xml
- %User Temp%\istA.tmp\omigazip\layout\default\rename.xml
- %User Temp%\istA.tmp\omigazip\layout\default\setting.xml
- %User Temp%\istA.tmp\omigazip\layout\default\uninstOmigaZip.xml
- %User Temp%\istA.tmp\omigazip\libcurl.dll
- %User Temp%\istA.tmp\omigazip\libeay32.dll
- %User Temp%\istA.tmp\omigazip\main
- %User Temp%\istA.tmp\omigazip\msvcp110.dll
- %User Temp%\istA.tmp\omigazip\msvcr110.dll
- %User Temp%\istA.tmp\omigazip\ssleay32.dll
- %User Temp%\istA.tmp\omigazip\style\install_style.xml
- %User Temp%\istA.tmp\omigazip\style\style.xml
- %User Temp%\istA.tmp\omigazip\uninstaller\OmigaZip.inst
- %User Temp%\istA.tmp\omigazip\winziper.exe
- %User Temp%\istA.tmp\omigazip\winzipersvc.exe
- %User Temp%\istA.tmp\omigazip\wzdl.exe
- %User Temp%\istA.tmp\omigazip\wzShellctx.dll
- %User Temp%\istA.tmp\omigazip\wzShellctx64.dll
- %User Temp%\istA.tmp\omigazip\wzUninstall.exe
- %User Temp%\istA.tmp\omigazip\wzUpg.exe
- %User Temp%\istA.tmp\omigazip\wz_settings.ini
- %User Temp%\istA.tmp\omigazip\zlib1.dll
Step 8
Restore these deleted registry keys/values from backup
*Note: Only Microsoft-related keys/values will be restored. If the malware/grayware also deleted registry keys/values related to programs that are not from Microsoft, please reinstall those programs on your computer.
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip\CompressedFolder
- ShellNew
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip
- CompressedFolder
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip
- OpenWithProgids
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip
- PersistentHandler
- In HKEY_CLASSES_ROOT
- .zip
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cab
- PersistentHandler
- In HKEY_CLASSES_ROOT
- .cab
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.tar
- PersistentHandler
- In HKEY_CLASSES_ROOT
- .tar
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.gz
- PersistentHandler
- In HKEY_CLASSES_ROOT
- .gz
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.tgz
- PersistentHandler
- In HKEY_CLASSES_ROOT
- .tgz
- In HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.z
- PersistentHandler
- In HKEY_CLASSES_ROOT
- .z
Did this description help? Tell us how we did.