Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,C:\ProgramData\sIAowgok\rSYkcwMw.exe,'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rSYkcwMw.exe' = 'C:\ProgramData\sIAowgok\rSYkcwMw.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'GocwIYEU.exe' = '%HOMEPATH%\CaIocokM\GocwIYEU.exe'
- [<HKLM>\SYSTEM\ControlSet001\services\yoYkgMRX] 'Start' = '00000002'
- C:\ProgramData\Package Cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\vcredist_x86.exe
- hidden files
- file extensions
- User Account Control (UAC)
- 'C:\ProgramData\ZQIIosos\XiskIEYE.exe'
- 'C:\ProgramData\sIAowgok\rSYkcwMw.exe'
- '%HOMEPATH%\CaIocokM\GocwIYEU.exe'
- '<SYSTEM32>\conhost.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
- '<SYSTEM32>\reg.exe'
- '<SYSTEM32>\reg.exe' /pid=0x160 /log
- '<SYSTEM32>\conhost.exe' /c ""%TEMP%\mSMUwsYY.bat" "<Full path to virus>""
- '<SYSTEM32>\reg.exe' /pid=0x770 /log
- '<SYSTEM32>\reg.exe' /c ""%TEMP%\QUQMEIAQ.bat" "<Full path to virus>""
- '<SYSTEM32>\reg.exe' /pid=0x1e0 /log
- '<SYSTEM32>\wbem\wmiprvse.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
- '<SYSTEM32>\conhost.exe' /c ""%TEMP%\huAQcUAs.bat" "<Full path to virus>""
- '<SYSTEM32>\reg.exe' 0x8b4 <Virus name>.exe
- '<SYSTEM32>\reg.exe' /c "<Current directory>\<Virus name>"
- '<SYSTEM32>\reg.exe' 0x500 <Virus name>.exe
- '<SYSTEM32>\cscript.exe' /pid=0x804 /log
- '<SYSTEM32>\cscript.exe' <LS_APPDATA>\Temp/file.vbs
- '<SYSTEM32>\reg.exe' /pid=0xd70 /log
- '<SYSTEM32>\cscript.exe'
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
- '<SYSTEM32>\reg.exe' /pid=0x808 /log
- '<SYSTEM32>\conhost.exe' /c "<Current directory>\<Virus name>"
- '<SYSTEM32>\conhost.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
- '<SYSTEM32>\conhost.exe'
- '<SYSTEM32>\conhost.exe' <LS_APPDATA>\Temp/file.vbs
- '<SYSTEM32>\conhost.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
- '<SYSTEM32>\conhost.exe' /c ""%TEMP%\AyUsowIQ.bat" "<Full path to virus>""
- <Current directory>\RIAU.exe
- C:\RCX521D.tmp
- <Current directory>\POgw.ico
- <Current directory>\qIIY.exe
- C:\RCX50C5.tmp
- <Current directory>\wyII.ico
- <Current directory>\sQcO.exe
- C:\RCX554A.tmp
- <Current directory>\LKIo.ico
- <Current directory>\ugUc.exe
- C:\RCX547E.tmp
- <Current directory>\foYM.ico
- <Current directory>\aUom.exe
- <Current directory>\gGMs.ico
- <Current directory>\CgIO.exe
- C:\RCX4953.tmp
- <Current directory>\Uewc.ico
- <Current directory>\hAgw.exe
- C:\RCX4829.tmp
- <Current directory>\oYgg.ico
- <Current directory>\AcwS.exe
- %TEMP%\XMwkwssw.bat
- <Current directory>\HEky.exe
- C:\RCX4E73.tmp
- C:\RCX4BD3.tmp
- %TEMP%\pusUMMgg.bat
- <Current directory>\SiIk.ico
- C:\RCX6087.tmp
- <Current directory>\lmcs.ico
- <Current directory>\NcQK.exe
- %TEMP%\OCwoEoII.bat
- <Current directory>\IAUs.ico
- <Current directory>\DoAY.exe
- C:\RCX61EF.tmp
- <Current directory>\RAEo.ico
- <Current directory>\jkkC.exe
- C:\RCX651C.tmp
- <Current directory>\RCMM.ico
- <Current directory>\LcMS.exe
- C:\RCX6318.tmp
- C:\RCX5E25.tmp
- C:\RCX580A.tmp
- <Current directory>\YQAo.ico
- <Current directory>\Yksc.exe
- C:\RCX56F1.tmp
- <Current directory>\deYI.ico
- <Current directory>\lEIm.exe
- C:\RCX58F5.tmp
- <Current directory>\DukE.ico
- %TEMP%\gSIwkEMA.bat
- <Current directory>\kgoE.exe
- <Current directory>\mIEk.ico
- <Current directory>\DoYS.exe
- C:\RCX5C8F.tmp
- C:\RCX2C92.tmp
- <Current directory>\xaYo.ico
- <Current directory>\dcAS.exe
- C:\RCX2ACD.tmp
- <Current directory>\AogU.ico
- <Current directory>\xQYG.exe
- C:\RCX2FAF.tmp
- <Current directory>\ZIcs.ico
- <Current directory>\BgMS.exe
- C:\RCX329D.tmp
- <Current directory>\lAgc.ico
- <Current directory>\OksM.exe
- C:\RCX3184.tmp
- <Current directory>\XQUS.exe
- <Current directory>\IakE.ico
- <Current directory>\lUwG.exe
- C:\RCX25EA.tmp
- %TEMP%\QUQMEIAQ.bat
- <Current directory>\fUwa.exe
- C:\RCX2482.tmp
- <Current directory>\VSQE.ico
- <Current directory>\kgoU.exe
- C:\RCX2907.tmp
- <Current directory>\cKQY.ico
- <Current directory>\ogca.exe
- C:\RCX2703.tmp
- <Current directory>\myMw.ico
- <Current directory>\oEYY.ico
- <Current directory>\LsgA.exe
- C:\RCX4124.tmp
- <Current directory>\LEAE.ico
- <Current directory>\xIwi.exe
- C:\RCX3F5F.tmp
- <Current directory>\BiIc.ico
- <Current directory>\IkgK.exe
- C:\RCX4635.tmp
- <Current directory>\hkAM.ico
- <Current directory>\HUMg.exe
- C:\RCX4386.tmp
- <Current directory>\yCkE.ico
- C:\RCX3DF7.tmp
- <Current directory>\XWEc.ico
- %TEMP%\zwQgkEsY.bat
- <Current directory>\rQIU.exe
- <Current directory>\bKMk.ico
- <Current directory>\fEIk.exe
- C:\RCX34FF.tmp
- C:\RCX37BE.tmp
- C:\RCX3B96.tmp
- <Current directory>\dckc.ico
- <Current directory>\jsgg.exe
- <Current directory>\Lccg.ico
- <Current directory>\UEsy.exe
- %TEMP%\sgkMgIgw.bat
- <Current directory>\xkUO.exe
- C:\RCX8DD8.tmp
- <Current directory>\tYgw.ico
- <Current directory>\jsYc.exe
- C:\RCX8CDD.tmp
- <Current directory>\vEcQ.ico
- <Current directory>\xkkA.exe
- C:\RCX9182.tmp
- <Current directory>\QSAo.ico
- <Current directory>\GosO.exe
- C:\RCX902A.tmp
- <Current directory>\NGMM.ico
- <Current directory>\asEO.exe
- <Current directory>\Hack.ico
- %TEMP%\PgIYQgAE.bat
- <Current directory>\xQgS.exe
- C:\RCX874F.tmp
- <Current directory>\oMAo.exe
- C:\RCX84BF.tmp
- <Current directory>\ygkg.ico
- <Current directory>\mwYM.ico
- <Current directory>\pgcM.ico
- <Current directory>\okgi.exe
- C:\RCX8BC4.tmp
- <Current directory>\pAEa.exe
- C:\RCX8A1D.tmp
- %TEMP%\huAQcUAs.bat
- <Current directory>\IgUy.exe
- C:\RCX9CFE.tmp
- <Current directory>\TIwE.ico
- <Current directory>\nscy.exe
- C:\RCX9A5E.tmp
- <Current directory>\SQwY.ico
- <Current directory>\EwAW.exe
- <Current directory>\kYYa.exe
- C:\RCX9FBE.tmp
- <Current directory>\NYYA.ico
- %TEMP%\xIgUooAQ.bat
- C:\RCX9EC3.tmp
- <Current directory>\xgoM.ico
- <Current directory>\Wgcc.ico
- C:\RCX9490.tmp
- <Current directory>\isQo.ico
- <Current directory>\xIwU.exe
- C:\RCX92EA.tmp
- <Current directory>\tuMo.ico
- <Current directory>\tUAG.exe
- C:\RCX96D2.tmp
- <Current directory>\LwUY.ico
- <Current directory>\fsQY.exe
- C:\RCX9906.tmp
- <Current directory>\jUAE.ico
- <Current directory>\ygYS.exe
- C:\RCX97EC.tmp
- C:\RCX6EF1.tmp
- <Current directory>\ECUQ.ico
- %TEMP%\VMsYYUoU.bat
- C:\RCX6D1C.tmp
- <Current directory>\Wsoo.ico
- <Current directory>\RsQQ.exe
- <Current directory>\nUsg.exe
- %TEMP%\xwYUEcIc.bat
- C:\RCX72DA.tmp
- <Current directory>\tmAc.ico
- C:\RCX7088.tmp
- <Current directory>\Jucg.ico
- <Current directory>\zwgO.exe
- <Current directory>\kUse.exe
- <Current directory>\fygo.ico
- <Current directory>\zwwW.exe
- C:\RCX6878.tmp
- <Current directory>\Bkgs.ico
- <Current directory>\PAwy.exe
- C:\RCX6684.tmp
- <Current directory>\Augs.ico
- <Current directory>\eMYg.exe
- C:\RCX6B95.tmp
- <Current directory>\bsMI.ico
- <Current directory>\XUMq.exe
- C:\RCX69EF.tmp
- <Current directory>\xgwk.ico
- <Current directory>\XakI.ico
- <Current directory>\nUUO.exe
- C:\RCX8049.tmp
- <Current directory>\jGkc.ico
- <Current directory>\GIMy.exe
- C:\RCX7E07.tmp
- <Current directory>\RsQo.ico
- <Current directory>\rcEe.exe
- C:\RCX8357.tmp
- <Current directory>\wwIU.ico
- <Current directory>\VowI.exe
- C:\RCX81EF.tmp
- <Current directory>\BwMQ.ico
- C:\RCX7CBE.tmp
- <Current directory>\oUwi.exe
- C:\RCX75D8.tmp
- <Current directory>\TiIE.ico
- <Current directory>\qcEe.exe
- C:\RCX7461.tmp
- <Current directory>\UKgs.ico
- <Current directory>\cwoC.exe
- C:\RCX7A7C.tmp
- <Current directory>\ugMg.ico
- <Current directory>\JMIW.exe
- C:\RCX777E.tmp
- <Current directory>\weYU.ico
- <Current directory>\cUAa.exe
- <Current directory>\euIY.ico
- <Current directory>\qIoQ.exe
- C:\RCXBA0E.tmp
- <Current directory>\yEsY.ico
- <Current directory>\Qgcc.exe
- C:\RCXB75F.tmp
- <Current directory>\EiEM.ico
- <Current directory>\hQYy.exe
- C:\RCXBFDA.tmp
- <Current directory>\KaIo.ico
- <Current directory>\AAYq.exe
- C:\RCXBDE6.tmp
- <Current directory>\kYAM.ico
- %TEMP%\wSwQMMAk.bat
- <Current directory>\yGMA.ico
- <Current directory>\vEkE.exe
- C:\RCXAA61.tmp
- <Current directory>\QasA.ico
- <Current directory>\gEIO.exe
- C:\RCXA744.tmp
- <Current directory>\UyAw.ico
- <Current directory>\GQsQ.ico
- <Current directory>\Qwwc.exe
- C:\RCXB442.tmp
- <Current directory>\ZoUK.exe
- C:\RCXB03C.tmp
- %TEMP%\MCkoYcAU.bat
- <Current directory>\WAMe.exe
- C:\RCXCDC5.tmp
- <Current directory>\Vigo.ico
- <Current directory>\LcAM.exe
- C:\RCXCA99.tmp
- <Current directory>\QkEo.ico
- <Current directory>\CcUY.exe
- C:\RCXD1DC.tmp
- <Current directory>\VIIE.ico
- <Current directory>\Yksk.exe
- C:\RCXCF5C.tmp
- <Current directory>\rEsU.ico
- <Current directory>\rIUS.exe
- %TEMP%\AyUsowIQ.bat
- <Current directory>\aIAa.exe
- C:\RCXC401.tmp
- <Current directory>\zkMQ.ico
- <Current directory>\IkoW.exe
- C:\RCXC1FD.tmp
- <Current directory>\FAwE.ico
- <Current directory>\CgMU.exe
- <Current directory>\gcQO.exe
- C:\RCXC866.tmp
- <Current directory>\qUoA.ico
- C:\RCXC5E6.tmp
- <Current directory>\bsIo.ico
- %TEMP%\eYkoMAYM.bat
- C:\RCX6643.tmp
- <Current directory>\pcoI.ico
- <Current directory>\RQkM.exe
- C:\RCX6162.tmp
- <Current directory>\OSos.ico
- <Current directory>\PkgK.exe
- C:\RCX696F.tmp
- <Current directory>\HAYk.ico
- <Current directory>\mMoo.exe
- C:\RCX72C4.tmp
- <Current directory>\vGEo.ico
- <Current directory>\AMgm.exe
- C:\RCX6C9B.tmp
- <Current directory>\ukws.exe
- <SYSTEM32>\config\systemprofile\CaIocokM\GocwIYEU
- %TEMP%\AMcUMcAc.bat
- <Current directory>\<Virus name>
- %HOMEPATH%\CaIocokM\GocwIYEU
- C:\ProgramData\sIAowgok\rSYkcwMw
- C:\ProgramData\ZQIIosos\XiskIEYE.exe
- %TEMP%\pOEAAMIA.bat
- <Current directory>\yQQI.exe
- C:\RCX588B.tmp
- <Current directory>\CGcE.ico
- C:\ProgramData\kaog.txt
- %TEMP%\file.vbs
- <Current directory>\UsMA.ico
- <Current directory>\KQwk.ico
- <Current directory>\gUkM.exe
- C:\RCX9B40.tmp
- <Current directory>\GSsc.ico
- <Current directory>\Hswc.exe
- C:\RCX97F5.tmp
- <Auxiliary element>
- <Current directory>\POYA.ico
- <Current directory>\Wkgo.exe
- C:\RCXA31F.tmp
- <Current directory>\SKYc.ico
- <Current directory>\MMku.exe
- C:\RCX9F85.tmp
- C:\RCX8BA5.tmp
- <Current directory>\ksIi.exe
- C:\RCX78EC.tmp
- <Current directory>\rwAU.ico
- %TEMP%\SscYkEsM.bat
- <Current directory>\UuUo.ico
- %TEMP%\tQUUMEck.bat
- <Current directory>\JIoQ.exe
- C:\RCX879E.tmp
- <Current directory>\Gqww.ico
- <Current directory>\ZQoW.exe
- C:\RCX7DBE.tmp
- <Current directory>\rSYg.ico
- <Current directory>\hsgQ.exe
- <Current directory>\DKQY.ico
- %TEMP%\omYcQIAk.bat
- <Current directory>\OIsE.exe
- <Current directory>\UsAQ.ico
- <Current directory>\OsIg.exe
- C:\RCX87D.tmp
- C:\RCXAFE.tmp
- C:\RCXF14.tmp
- <Current directory>\IicI.ico
- <Current directory>\DkMo.exe
- %TEMP%\vSEYwUEE.bat
- <Current directory>\bSoA.ico
- <Current directory>\yYMc.exe
- C:\RCX5FD.tmp
- <Current directory>\AsIM.exe
- C:\RCX2CF.tmp
- <Current directory>\cwcU.ico
- <Current directory>\LUUs.exe
- C:\RCXFE7A.tmp
- <Current directory>\SOUc.ico
- <Current directory>\fEAO.exe
- C:\RCX495.tmp
- <Current directory>\EIYU.ico
- <Current directory>\ogYK.exe
- C:\RCX3BA.tmp
- <Current directory>\hUUo.ico
- <Current directory>\IwsC.exe
- <Current directory>\kooa.exe
- C:\RCX1C54.tmp
- <Current directory>\coIk.ico
- <Current directory>\uIog.exe
- C:\RCX1A7F.tmp
- <Current directory>\XOYE.ico
- <Current directory>\nAQS.exe
- <Current directory>\XgAa.exe
- C:\RCX20C9.tmp
- <Current directory>\qCEM.ico
- C:\RCX1EE5.tmp
- <Current directory>\omMg.ico
- %TEMP%\fWYEUQkk.bat
- <Current directory>\DgEo.ico
- C:\RCX11C5.tmp
- <Current directory>\iCcE.ico
- <Current directory>\oAMg.exe
- C:\RCX10E9.tmp
- <Current directory>\wkkw.ico
- <Current directory>\vAoY.exe
- C:\RCX159C.tmp
- <Current directory>\sKEI.ico
- <Current directory>\AsMS.exe
- C:\RCX1966.tmp
- <Current directory>\Gook.ico
- <Current directory>\tkEK.exe
- C:\RCX17CF.tmp
- <Current directory>\mykI.ico
- <Current directory>\DIEG.exe
- C:\RCXDF1D.tmp
- %TEMP%\NyEkEoAE.bat
- <Current directory>\yMcG.exe
- C:\RCXDE22.tmp
- %TEMP%\mSMUwsYY.bat
- <Current directory>\cKQc.ico
- <Current directory>\hgQY.exe
- C:\RCXE363.tmp
- <Current directory>\oWQI.ico
- <Current directory>\hIsq.exe
- C:\RCXE20A.tmp
- <Current directory>\KOQY.ico
- C:\RCXD519.tmp
- <Current directory>\XWck.ico
- <Current directory>\HYIs.exe
- C:\RCXD3FF.tmp
- <Current directory>\CoEI.ico
- <Current directory>\CEgO.exe
- C:\RCXD6FE.tmp
- <Current directory>\ukkw.ico
- <Current directory>\RskC.exe
- C:\RCXDC5D.tmp
- <Current directory>\tkkk.ico
- <Current directory>\wYYw.exe
- C:\RCXD97E.tmp
- <Current directory>\zAkI.exe
- C:\RCXF4A7.tmp
- <Current directory>\pMAU.ico
- C:\RCXEF4A.tmp
- <Current directory>\bGAA.ico
- %TEMP%\OycQssAU.bat
- %TEMP%\zoMgYYAI.bat
- <Current directory>\dsAc.exe
- C:\RCXFAE1.tmp
- <Current directory>\fiQY.ico
- <Current directory>\FcMS.exe
- C:\RCXF7B4.tmp
- <Current directory>\pwMg.ico
- <Current directory>\TEAs.exe
- <Current directory>\bYkE.ico
- <Current directory>\osEI.exe
- C:\RCXEA47.tmp
- <Current directory>\Zcso.ico
- <Current directory>\rwEU.exe
- C:\RCXE6EC.tmp
- <Current directory>\zeks.ico
- <Current directory>\akQS.exe
- C:\RCXEC9A.tmp
- <Current directory>\Pcko.ico
- <Current directory>\RsUY.exe
- C:\RCXEB32.tmp
- <Current directory>\SWMk.ico
- <Current directory>\sQcO.exe
- <Current directory>\foYM.ico
- <Current directory>\RIAU.exe
- <Current directory>\POgw.ico
- <Current directory>\ugUc.exe
- <Current directory>\deYI.ico
- <Current directory>\aUom.exe
- <Current directory>\LKIo.ico
- <Current directory>\wyII.ico
- <Current directory>\AcwS.exe
- %TEMP%\pusUMMgg.bat
- <Current directory>\CgIO.exe
- <Current directory>\Uewc.ico
- <Current directory>\gGMs.ico
- <Current directory>\qIIY.exe
- <Current directory>\SiIk.ico
- <Current directory>\HEky.exe
- <Current directory>\lEIm.exe
- <Current directory>\RCMM.ico
- <Current directory>\LcMS.exe
- <Current directory>\lmcs.ico
- <Current directory>\NcQK.exe
- <Current directory>\Bkgs.ico
- <Current directory>\PAwy.exe
- <Current directory>\RAEo.ico
- <Current directory>\jkkC.exe
- <Current directory>\DoAY.exe
- <Current directory>\mIEk.ico
- <Current directory>\DoYS.exe
- <Current directory>\YQAo.ico
- <Current directory>\Yksc.exe
- <Current directory>\kgoE.exe
- <Current directory>\IAUs.ico
- %TEMP%\gSIwkEMA.bat
- <Current directory>\DukE.ico
- <Current directory>\oYgg.ico
- <Current directory>\lAgc.ico
- <Current directory>\OksM.exe
- <Current directory>\xaYo.ico
- <Current directory>\dcAS.exe
- <Current directory>\bKMk.ico
- <Current directory>\fEIk.exe
- <Current directory>\ZIcs.ico
- <Current directory>\BgMS.exe
- <Current directory>\xQYG.exe
- <Current directory>\ogca.exe
- <Current directory>\myMw.ico
- <Current directory>\lUwG.exe
- <Current directory>\VSQE.ico
- <Current directory>\XQUS.exe
- <Current directory>\AogU.ico
- <Current directory>\kgoU.exe
- <Current directory>\cKQY.ico
- %TEMP%\zwQgkEsY.bat
- <Current directory>\BiIc.ico
- <Current directory>\HUMg.exe
- <Current directory>\oEYY.ico
- <Current directory>\LsgA.exe
- <Current directory>\hkAM.ico
- <Current directory>\hAgw.exe
- <Current directory>\yCkE.ico
- <Current directory>\IkgK.exe
- <Current directory>\xIwi.exe
- %TEMP%\QUQMEIAQ.bat
- <Current directory>\Lccg.ico
- <Current directory>\XWEc.ico
- <Current directory>\rQIU.exe
- <Current directory>\jsgg.exe
- <Current directory>\LEAE.ico
- <Current directory>\UEsy.exe
- <Current directory>\dckc.ico
- <Current directory>\tYgw.ico
- <Current directory>\xkkA.exe
- <Current directory>\vEcQ.ico
- <Current directory>\xkUO.exe
- <Current directory>\QSAo.ico
- <Current directory>\GosO.exe
- <Current directory>\NGMM.ico
- <Current directory>\asEO.exe
- <Current directory>\jsYc.exe
- %TEMP%\PgIYQgAE.bat
- <Current directory>\mwYM.ico
- <Current directory>\ygkg.ico
- <Current directory>\xQgS.exe
- <Current directory>\okgi.exe
- <Current directory>\Hack.ico
- <Current directory>\pAEa.exe
- <Current directory>\pgcM.ico
- <Current directory>\tuMo.ico
- %TEMP%\huAQcUAs.bat
- <Current directory>\TIwE.ico
- <Current directory>\SQwY.ico
- <Current directory>\IgUy.exe
- <Current directory>\xgoM.ico
- <Current directory>\kYYa.exe
- <Current directory>\EwAW.exe
- %TEMP%\xIgUooAQ.bat
- <Current directory>\nscy.exe
- <Current directory>\xIwU.exe
- <Current directory>\jUAE.ico
- <Current directory>\tUAG.exe
- <Current directory>\isQo.ico
- <Current directory>\fsQY.exe
- <Current directory>\Wgcc.ico
- <Current directory>\ygYS.exe
- <Current directory>\LwUY.ico
- <Current directory>\oMAo.exe
- <Current directory>\ECUQ.ico
- <Current directory>\nUsg.exe
- <Current directory>\Wsoo.ico
- <Current directory>\RsQQ.exe
- <Current directory>\zwgO.exe
- <Current directory>\tmAc.ico
- %TEMP%\VMsYYUoU.bat
- <Current directory>\Jucg.ico
- %TEMP%\OCwoEoII.bat
- <Current directory>\Augs.ico
- <Current directory>\XUMq.exe
- <Current directory>\fygo.ico
- <Current directory>\zwwW.exe
- <Current directory>\bsMI.ico
- <Current directory>\kUse.exe
- <Current directory>\xgwk.ico
- <Current directory>\eMYg.exe
- <Current directory>\qcEe.exe
- <Current directory>\nUUO.exe
- <Current directory>\RsQo.ico
- <Current directory>\GIMy.exe
- <Current directory>\XakI.ico
- <Current directory>\rcEe.exe
- <Current directory>\wwIU.ico
- <Current directory>\VowI.exe
- <Current directory>\BwMQ.ico
- <Current directory>\jGkc.ico
- <Current directory>\TiIE.ico
- <Current directory>\cwoC.exe
- <Current directory>\UKgs.ico
- <Current directory>\oUwi.exe
- <Current directory>\ugMg.ico
- <Current directory>\JMIW.exe
- <Current directory>\weYU.ico
- <Current directory>\cUAa.exe
- <Current directory>\KaIo.ico
- <Current directory>\IkoW.exe
- <Current directory>\kYAM.ico
- <Current directory>\hQYy.exe
- <Current directory>\zkMQ.ico
- <Current directory>\CgMU.exe
- <Current directory>\FAwE.ico
- <Current directory>\aIAa.exe
- <Current directory>\AAYq.exe
- <Current directory>\Qwwc.exe
- <Current directory>\yEsY.ico
- %TEMP%\MCkoYcAU.bat
- <Current directory>\GQsQ.ico
- <Current directory>\qIoQ.exe
- <Current directory>\EiEM.ico
- <Current directory>\Qgcc.exe
- <Current directory>\euIY.ico
- <Current directory>\bsIo.ico
- <Current directory>\Yksk.exe
- <Current directory>\CoEI.ico
- <Current directory>\rIUS.exe
- <Current directory>\VIIE.ico
- <Current directory>\HYIs.exe
- <Current directory>\tkkk.ico
- <Current directory>\CEgO.exe
- <Current directory>\XWck.ico
- <Current directory>\rEsU.ico
- <Current directory>\qUoA.ico
- <Current directory>\LcAM.exe
- <Current directory>\gcQO.exe
- %TEMP%\eYkoMAYM.bat
- <Current directory>\Vigo.ico
- <Current directory>\CcUY.exe
- <Current directory>\QkEo.ico
- <Current directory>\WAMe.exe
- <Current directory>\ZoUK.exe
- <Current directory>\HAYk.ico
- <Current directory>\mMoo.exe
- <Current directory>\vGEo.ico
- <Current directory>\AMgm.exe
- <Current directory>\ksIi.exe
- <Current directory>\rwAU.ico
- %TEMP%\SscYkEsM.bat
- <Current directory>\UuUo.ico
- <Current directory>\RQkM.exe
- <Current directory>\yQQI.exe
- <Current directory>\CGcE.ico
- %TEMP%\AMcUMcAc.bat
- <Current directory>\UsMA.ico
- <Current directory>\PkgK.exe
- <Current directory>\pcoI.ico
- <Current directory>\ukws.exe
- <Current directory>\OSos.ico
- <Current directory>\JIoQ.exe
- <Current directory>\Wkgo.exe
- <Current directory>\QasA.ico
- <Current directory>\MMku.exe
- <Current directory>\POYA.ico
- <Current directory>\vEkE.exe
- <Current directory>\UyAw.ico
- <Current directory>\gEIO.exe
- <Current directory>\yGMA.ico
- <Current directory>\SKYc.ico
- <Current directory>\Gqww.ico
- <Current directory>\ZQoW.exe
- <Current directory>\rSYg.ico
- <Current directory>\hsgQ.exe
- <Current directory>\KQwk.ico
- <Current directory>\gUkM.exe
- <Current directory>\GSsc.ico
- <Current directory>\Hswc.exe
- <Current directory>\yYMc.exe
- <Current directory>\IicI.ico
- <Current directory>\OIsE.exe
- <Current directory>\bSoA.ico
- <Current directory>\vAoY.exe
- <Current directory>\iCcE.ico
- <Current directory>\DkMo.exe
- <Current directory>\wkkw.ico
- <Current directory>\DKQY.ico
- <Current directory>\IwsC.exe
- <Current directory>\EIYU.ico
- <Current directory>\fEAO.exe
- <Current directory>\hUUo.ico
- <Current directory>\OsIg.exe
- %TEMP%\omYcQIAk.bat
- <Current directory>\ogYK.exe
- <Current directory>\UsAQ.ico
- <Current directory>\oAMg.exe
- <Current directory>\omMg.ico
- <Current directory>\XgAa.exe
- <Current directory>\nAQS.exe
- %TEMP%\fWYEUQkk.bat
- %TEMP%\vSEYwUEE.bat
- <Current directory>\IakE.ico
- <Current directory>\qCEM.ico
- <Current directory>\fUwa.exe
- <Current directory>\coIk.ico
- <Current directory>\sKEI.ico
- <Current directory>\AsMS.exe
- <Current directory>\Gook.ico
- <Current directory>\tkEK.exe
- <Current directory>\XOYE.ico
- <Current directory>\kooa.exe
- <Current directory>\DgEo.ico
- <Current directory>\uIog.exe
- <Current directory>\cwcU.ico
- <Current directory>\cKQc.ico
- <Current directory>\hgQY.exe
- <Current directory>\oWQI.ico
- <Current directory>\hIsq.exe
- <Current directory>\bYkE.ico
- <Current directory>\osEI.exe
- <Current directory>\Zcso.ico
- <Current directory>\rwEU.exe
- <Current directory>\DIEG.exe
- <Current directory>\RskC.exe
- %TEMP%\AyUsowIQ.bat
- <Current directory>\wYYw.exe
- <Current directory>\ukkw.ico
- %TEMP%\NyEkEoAE.bat
- <Current directory>\mykI.ico
- <Current directory>\KOQY.ico
- <Current directory>\yMcG.exe
- <Current directory>\zeks.ico
- <Current directory>\pwMg.ico
- <Current directory>\dsAc.exe
- <Current directory>\pMAU.ico
- <Current directory>\FcMS.exe
- <Current directory>\SOUc.ico
- <Current directory>\AsIM.exe
- <Current directory>\fiQY.ico
- <Current directory>\LUUs.exe
- %TEMP%\mSMUwsYY.bat
- <Current directory>\akQS.exe
- <Current directory>\Pcko.ico
- <Current directory>\RsUY.exe
- <Current directory>\SWMk.ico
- <Current directory>\bGAA.ico
- <Current directory>\zAkI.exe
- <Current directory>\TEAs.exe
- %TEMP%\OycQssAU.bat
- from C:\RCX554A.tmp to <Current directory>\aUom.exe
- from C:\RCX547E.tmp to <Current directory>\sQcO.exe
- from C:\RCX580A.tmp to <Current directory>\lEIm.exe
- from C:\RCX56F1.tmp to <Current directory>\ugUc.exe
- from C:\RCX4E73.tmp to <Current directory>\HEky.exe
- from C:\RCX4BD3.tmp to <Current directory>\AcwS.exe
- from C:\RCX521D.tmp to <Current directory>\RIAU.exe
- from C:\RCX50C5.tmp to <Current directory>\qIIY.exe
- from C:\RCX6318.tmp to <Current directory>\LcMS.exe
- from C:\RCX61EF.tmp to <Current directory>\NcQK.exe
- from C:\RCX6684.tmp to <Current directory>\PAwy.exe
- from C:\RCX651C.tmp to <Current directory>\jkkC.exe
- from C:\RCX5C8F.tmp to <Current directory>\DoYS.exe
- from C:\RCX58F5.tmp to <Current directory>\Yksc.exe
- from C:\RCX6087.tmp to <Current directory>\DoAY.exe
- from C:\RCX5E25.tmp to <Current directory>\kgoE.exe
- from C:\RCX4953.tmp to <Current directory>\CgIO.exe
- from C:\RCX3184.tmp to <Current directory>\OksM.exe
- from C:\RCX2FAF.tmp to <Current directory>\dcAS.exe
- from C:\RCX34FF.tmp to <Current directory>\fEIk.exe
- from C:\RCX329D.tmp to <Current directory>\BgMS.exe
- from C:\RCX2907.tmp to <Current directory>\kgoU.exe
- from C:\RCX2703.tmp to <Current directory>\ogca.exe
- from C:\RCX2C92.tmp to <Current directory>\xQYG.exe
- from C:\RCX2ACD.tmp to <Current directory>\XQUS.exe
- from C:\RCX4386.tmp to <Current directory>\HUMg.exe
- from C:\RCX4124.tmp to <Current directory>\LsgA.exe
- from C:\RCX4829.tmp to <Current directory>\hAgw.exe
- from C:\RCX4635.tmp to <Current directory>\IkgK.exe
- from C:\RCX3B96.tmp to <Current directory>\UEsy.exe
- from C:\RCX37BE.tmp to <Current directory>\rQIU.exe
- from C:\RCX3F5F.tmp to <Current directory>\xIwi.exe
- from C:\RCX3DF7.tmp to <Current directory>\jsgg.exe
- from C:\RCX902A.tmp to <Current directory>\xkkA.exe
- from C:\RCX8DD8.tmp to <Current directory>\xkUO.exe
- from C:\RCX92EA.tmp to <Current directory>\GosO.exe
- from C:\RCX9182.tmp to <Current directory>\asEO.exe
- from C:\RCX8A1D.tmp to <Current directory>\pAEa.exe
- from C:\RCX874F.tmp to <Current directory>\xQgS.exe
- from C:\RCX8CDD.tmp to <Current directory>\jsYc.exe
- from C:\RCX8BC4.tmp to <Current directory>\okgi.exe
- from C:\RCX9CFE.tmp to <Current directory>\IgUy.exe
- from C:\RCX9A5E.tmp to <Current directory>\nscy.exe
- from C:\RCX9FBE.tmp to <Current directory>\kYYa.exe
- from C:\RCX9EC3.tmp to <Current directory>\EwAW.exe
- from C:\RCX96D2.tmp to <Current directory>\xIwU.exe
- from C:\RCX9490.tmp to <Current directory>\tUAG.exe
- from C:\RCX9906.tmp to <Current directory>\fsQY.exe
- from C:\RCX97EC.tmp to <Current directory>\ygYS.exe
- from C:\RCX84BF.tmp to <Current directory>\oMAo.exe
- from C:\RCX7088.tmp to <Current directory>\nUsg.exe
- from C:\RCX6EF1.tmp to <Current directory>\RsQQ.exe
- from C:\RCX7461.tmp to <Current directory>\qcEe.exe
- from C:\RCX72DA.tmp to <Current directory>\zwgO.exe
- from C:\RCX69EF.tmp to <Current directory>\XUMq.exe
- from C:\RCX6878.tmp to <Current directory>\zwwW.exe
- from C:\RCX6D1C.tmp to <Current directory>\kUse.exe
- from C:\RCX6B95.tmp to <Current directory>\eMYg.exe
- from C:\RCX8049.tmp to <Current directory>\nUUO.exe
- from C:\RCX7E07.tmp to <Current directory>\GIMy.exe
- from C:\RCX8357.tmp to <Current directory>\rcEe.exe
- from C:\RCX81EF.tmp to <Current directory>\VowI.exe
- from C:\RCX777E.tmp to <Current directory>\cwoC.exe
- from C:\RCX75D8.tmp to <Current directory>\oUwi.exe
- from C:\RCX7CBE.tmp to <Current directory>\JMIW.exe
- from C:\RCX7A7C.tmp to <Current directory>\cUAa.exe
- from C:\RCXC1FD.tmp to <Current directory>\IkoW.exe
- from C:\RCXBFDA.tmp to <Current directory>\hQYy.exe
- from C:\RCXC5E6.tmp to <Current directory>\CgMU.exe
- from C:\RCXC401.tmp to <Current directory>\aIAa.exe
- from C:\RCXB75F.tmp to <Current directory>\Qgcc.exe
- from C:\RCXB442.tmp to <Current directory>\Qwwc.exe
- from C:\RCXBDE6.tmp to <Current directory>\AAYq.exe
- from C:\RCXBA0E.tmp to <Current directory>\qIoQ.exe
- from C:\RCXD3FF.tmp to <Current directory>\Yksk.exe
- from C:\RCXD1DC.tmp to <Current directory>\rIUS.exe
- from C:\RCXD6FE.tmp to <Current directory>\HYIs.exe
- from C:\RCXD519.tmp to <Current directory>\CEgO.exe
- from C:\RCXCA99.tmp to <Current directory>\LcAM.exe
- from C:\RCXC866.tmp to <Current directory>\gcQO.exe
- from C:\RCXCF5C.tmp to <Current directory>\CcUY.exe
- from C:\RCXCDC5.tmp to <Current directory>\WAMe.exe
- from C:\RCXB03C.tmp to <Current directory>\ZoUK.exe
- from C:\RCX72C4.tmp to <Current directory>\mMoo.exe
- from C:\RCX6C9B.tmp to <Current directory>\AMgm.exe
- from C:\RCX7DBE.tmp to <Current directory>\JIoQ.exe
- from C:\RCX78EC.tmp to <Current directory>\ksIi.exe
- from C:\RCX6162.tmp to <Current directory>\ukws.exe
- from C:\RCX588B.tmp to <Current directory>\yQQI.exe
- from C:\RCX696F.tmp to <Current directory>\RQkM.exe
- from C:\RCX6643.tmp to <Current directory>\PkgK.exe
- from C:\RCXA31F.tmp to <Current directory>\Wkgo.exe
- from C:\RCX9F85.tmp to <Current directory>\MMku.exe
- from C:\RCXAA61.tmp to <Current directory>\vEkE.exe
- from C:\RCXA744.tmp to <Current directory>\gEIO.exe
- from C:\RCX8BA5.tmp to <Current directory>\ZQoW.exe
- from C:\RCX879E.tmp to <Current directory>\hsgQ.exe
- from C:\RCX9B40.tmp to <Current directory>\gUkM.exe
- from C:\RCX97F5.tmp to <Current directory>\Hswc.exe
- from C:\RCX10E9.tmp to <Current directory>\DkMo.exe
- from C:\RCXF14.tmp to <Current directory>\yYMc.exe
- from C:\RCX159C.tmp to <Current directory>\oAMg.exe
- from C:\RCX11C5.tmp to <Current directory>\vAoY.exe
- from C:\RCX5FD.tmp to <Current directory>\ogYK.exe
- from C:\RCX495.tmp to <Current directory>\IwsC.exe
- from C:\RCXAFE.tmp to <Current directory>\OIsE.exe
- from C:\RCX87D.tmp to <Current directory>\OsIg.exe
- from C:\RCX20C9.tmp to <Current directory>\XgAa.exe
- from C:\RCX1EE5.tmp to <Current directory>\nAQS.exe
- from C:\RCX25EA.tmp to <Current directory>\lUwG.exe
- from C:\RCX2482.tmp to <Current directory>\fUwa.exe
- from C:\RCX1966.tmp to <Current directory>\AsMS.exe
- from C:\RCX17CF.tmp to <Current directory>\tkEK.exe
- from C:\RCX1C54.tmp to <Current directory>\kooa.exe
- from C:\RCX1A7F.tmp to <Current directory>\uIog.exe
- from C:\RCX3BA.tmp to <Current directory>\fEAO.exe
- from C:\RCXE363.tmp to <Current directory>\hgQY.exe
- from C:\RCXE20A.tmp to <Current directory>\hIsq.exe
- from C:\RCXEA47.tmp to <Current directory>\osEI.exe
- from C:\RCXE6EC.tmp to <Current directory>\rwEU.exe
- from C:\RCXDC5D.tmp to <Current directory>\RskC.exe
- from C:\RCXD97E.tmp to <Current directory>\wYYw.exe
- from C:\RCXDF1D.tmp to <Current directory>\DIEG.exe
- from C:\RCXDE22.tmp to <Current directory>\yMcG.exe
- from C:\RCXFAE1.tmp to <Current directory>\dsAc.exe
- from C:\RCXF7B4.tmp to <Current directory>\FcMS.exe
- from C:\RCX2CF.tmp to <Current directory>\AsIM.exe
- from C:\RCXFE7A.tmp to <Current directory>\LUUs.exe
- from C:\RCXEC9A.tmp to <Current directory>\akQS.exe
- from C:\RCXEB32.tmp to <Current directory>\RsUY.exe
- from C:\RCXF4A7.tmp to <Current directory>\zAkI.exe
- from C:\RCXEF4A.tmp to <Current directory>\TEAs.exe
- DNS ASK dn#.##ftncsi.com
- DNS ASK google.com
- ClassName: '' WindowName: 'Microsoft Windows'
- ClassName: '' WindowName: 'rSYkcwMw.exe'
- ClassName: '' WindowName: 'GocwIYEU.exe'
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''