Technical Information
- '<SYSTEM32>\vijbmtds.exe'
- '<SYSTEM32>\xdruobqs.exe' /pid=3428
- '<SYSTEM32>\wxwuyfyc.exe'
- '<SYSTEM32>\aubvxkov.exe' /pid=1324
- '<SYSTEM32>\tsxnllvt.exe'
- '<SYSTEM32>\wpiaqisd.exe'
- '<SYSTEM32>\slejawdg.exe'
- '<SYSTEM32>\swnfjkat.exe'
- '<SYSTEM32>\symjffzj.exe' /pid=2088
- '<SYSTEM32>\tbizebtj.exe'
- '<SYSTEM32>\lqhbhkmx.exe' /pid=3532
- '<SYSTEM32>\rtnygtpm.exe'
- '<SYSTEM32>\aevdhiub.exe'
- '<SYSTEM32>\xdruobqs.exe'
- '<SYSTEM32>\symjffzj.exe'
- '<SYSTEM32>\pxrfjsvl.exe'
- '<SYSTEM32>\dzewnnyw.exe'
- '<SYSTEM32>\anvbmueq.exe'
- '<SYSTEM32>\hmckxalc.exe'
- '<SYSTEM32>\mkibupxh.exe'
- '<SYSTEM32>\rxrcwaky.exe'
- '<SYSTEM32>\lqhbhkmx.exe'
- '<SYSTEM32>\tqksftjh.exe'
- '<SYSTEM32>\aubvxkov.exe'
- '<SYSTEM32>\wewtjvsp.exe'
- '<SYSTEM32>\cjqzgrae.exe'
- <SYSTEM32>\svchost.exe
- ClassName: '(null)' WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS' WindowName: '(null)'
- ClassName: '(null)' WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass' WindowName: '(null)'
- ClassName: '(null)' WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'GBDYLLO' WindowName: '(null)'
- ClassName: 'OLLYDBG' WindowName: '(null)'
- ClassName: 'FilemonClass' WindowName: '(null)'
- ClassName: 'pediy06' WindowName: '(null)'
- <SYSTEM32>\tqksftjh.exe
- <SYSTEM32>\tsxnllvt.exe
- <SYSTEM32>\wpiaqisd.exe
- <SYSTEM32>\cjqzgrae.exe
- <SYSTEM32>\rxrcwaky.exe
- <SYSTEM32>\lqhbhkmx.exe
- <SYSTEM32>\vijbmtds.exe
- <SYSTEM32>\aevdhiub.exe
- <SYSTEM32>\swnfjkat.exe
- <SYSTEM32>\tbizebtj.exe
- <SYSTEM32>\wxwuyfyc.exe
- <SYSTEM32>\slejawdg.exe
- <SYSTEM32>\rtnygtpm.exe
- <SYSTEM32>\dzewnnyw.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\mswinsck[1].ocx
- <SYSTEM32>\anvbmueq.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\mswinsck[1].ocx
- <SYSTEM32>\MSWINSCK.ocx
- <SYSTEM32>\hmckxalc.exe
- <SYSTEM32>\mkibupxh.exe
- <SYSTEM32>\aubvxkov.exe
- <SYSTEM32>\wewtjvsp.exe
- <SYSTEM32>\xdruobqs.exe
- <SYSTEM32>\symjffzj.exe
- <SYSTEM32>\pxrfjsvl.exe
- <SYSTEM32>\wpiaqisd.exe
- <SYSTEM32>\vijbmtds.exe
- <SYSTEM32>\tsxnllvt.exe
- <SYSTEM32>\lqhbhkmx.exe
- <SYSTEM32>\tqksftjh.exe
- <SYSTEM32>\wxwuyfyc.exe
- <SYSTEM32>\swnfjkat.exe
- <SYSTEM32>\tbizebtj.exe
- <SYSTEM32>\aevdhiub.exe
- <SYSTEM32>\slejawdg.exe
- <SYSTEM32>\rtnygtpm.exe
- <SYSTEM32>\xdruobqs.exe
- <SYSTEM32>\symjffzj.exe
- <SYSTEM32>\hmckxalc.exe
- <SYSTEM32>\dzewnnyw.exe
- <SYSTEM32>\anvbmueq.exe
- <SYSTEM32>\pxrfjsvl.exe
- <SYSTEM32>\cjqzgrae.exe
- <SYSTEM32>\rxrcwaky.exe
- <SYSTEM32>\wewtjvsp.exe
- <SYSTEM32>\mkibupxh.exe
- <SYSTEM32>\aubvxkov.exe
- %TEMP%\~DF2F09.tmp
- %TEMP%\~DF2070.tmp
- %TEMP%\~DFC2A1.tmp
- %TEMP%\~DF5E4C.tmp
- %TEMP%\~DFCE8E.tmp
- %TEMP%\~DF65B9.tmp
- %TEMP%\~DF2771.tmp
- %TEMP%\~DF1B7E.tmp
- %TEMP%\~DFFF86.tmp
- %TEMP%\~DF82C1.tmp
- %TEMP%\~DFC6A8.tmp
- %TEMP%\~DF6A.tmp
- %TEMP%\~DF70E4.tmp
- %TEMP%\~DF10B3.tmp
- %TEMP%\~DFB0AE.tmp
- %TEMP%\~DFA490.tmp
- %TEMP%\~DF64EE.tmp
- %TEMP%\~DF216C.tmp
- %TEMP%\~DF6E07.tmp
- %TEMP%\~DFD8B.tmp
- %TEMP%\~DFCDBF.tmp
- %TEMP%\~DFC348.tmp
- %TEMP%\~DF7013.tmp
- %TEMP%\~DF5D8B.tmp
- %TEMP%\~DFF456.tmp
- %TEMP%\~DF6085.tmp
- %TEMP%\~DFF16.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\mswinsck[1].ocx
- %TEMP%\~DF1640.tmp
- %TEMP%\~DFA00.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\mswinsck[1].ocx
- %TEMP%\~DFB2F2.tmp
- %TEMP%\~DFC372.tmp
- %TEMP%\~DFDD2C.tmp
- %TEMP%\~DF491A.tmp
- %TEMP%\~DFE96C.tmp
- %TEMP%\~DF8871.tmp
- %TEMP%\~DF7A6F.tmp
- %TEMP%\~DF3B07.tmp
- %TEMP%\~DFFCEA.tmp
- %TEMP%\~DFAE14.tmp
- %TEMP%\~DFB13.tmp
- %TEMP%\~DFAA0E.tmp
- %TEMP%\~DFA15E.tmp
- 'localhost':1064
- 'localhost':1066
- 'localhost':1062
- 'localhost':1058
- 'localhost':1060
- 'localhost':1068
- 'localhost':1076
- 'localhost':1078
- 'localhost':1074
- 'localhost':1070
- 'localhost':1072
- 'localhost':1056
- 'localhost':1040
- 'localhost':1042
- 'localhost':1038
- 'localhost':1035
- 'pd###.egloos.com':80
- 'localhost':1044
- 'localhost':1052
- 'localhost':1054
- 'localhost':1050
- 'localhost':1046
- 'localhost':1048
- pd###.egloos.com/pds/201304/27/64/mswinsck.ocx
- DNS ASK pd###.egloos.com
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: '18467-41' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'