Viniamin, please be sure you are uploading safe files. The release of R@pelay that was uploaded shows up as
InfoStealer. :(
In this particular instance, even without running the executable, simply extracting it, Norton traced its actions and repaired the following issues:
Full Path: Not Available
____________________________
____________________________
On computers as of Not Available
Last Used 10/15/2012 at 7:30:00 PM
Startup Item No
Launched No
____________________________
____________________________
Unknown
Number of users in the Norton Community that have used this file: Unknown____________________________
Unknown
This file release is currently not known.
____________________________
High
This file risk is high.
____________________________
Threat Details
Threat type: Virus. Programs that infect other programs, files, or areas of a computer by inserting themselves or attaching themselves to that medium.
____________________________
____________________________
File Actions
File: rapelay-en.exe
No fix attempted
____________________________
Registry Actions
Registry change: HKEY_USERS\S-1-5-21-2869643221-3741603377-2481745458-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->Hidden:1
No Action Required
Registry change: HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->Hidden:1
Repaired
Registry change: HKEY_USERS\S-1-5-21-2869643221-3741603377-2481745458-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->Hidden:1
Repaired
Registry change: HKEY_USERS\S-1-5-21-2869643221-3741603377-2481745458-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->Hidden:1
Repaired
Registry change: HKEY_USERS\S-1-5-21-2869643221-3741603377-2481745458-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->Hidden:1
Repaired
Registry change: HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->Hidden:1
Repaired
Registry change: HKEY_USERS\S-1-5-21-2869643221-3741603377-2481745458-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->ShowSuperHidden:1
No Action Required
Registry change: HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->ShowSuperHidden:1
Repaired
Registry change: HKEY_USERS\S-1-5-21-2869643221-3741603377-2481745458-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->ShowSuperHidden:1
Repaired
Registry change: HKEY_USERS\S-1-5-21-2869643221-3741603377-2481745458-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->ShowSuperHidden:1
Repaired
Registry change: HKEY_USERS\S-1-5-21-2869643221-3741603377-2481745458-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->ShowSuperHidden:1
Repaired
Registry change: HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->ShowSuperHidden:1
Repaired
Registry change: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL->CheckedValue:1
Repaired
Registry change: HKEY_USERS\S-1-5-21-2869643221-3741603377-2481745458-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->Hidden:1
Repaired
Registry change: HKEY_USERS\S-1-5-21-2869643221-3741603377-2481745458-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced->ShowSuperHidden:1
Repaired
____________________________
File Thumbprint - SHA:
Not Available
____________________________
File Thumbprint - MD5:
Not Available
____________________________
I know those registry keys are just the Hidden Files and Protected Files settings, but the fact remains that the program should NOT be messing with those options at all.