Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,C:\ProgramData\sIAowgok\rSYkcwMw.exe,'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rSYkcwMw.exe' = 'C:\ProgramData\sIAowgok\rSYkcwMw.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'GocwIYEU.exe' = '%HOMEPATH%\CaIocokM\GocwIYEU.exe'
- [<HKLM>\SYSTEM\ControlSet001\services\yoYkgMRX] 'Start' = '00000002'
- C:\ProgramData\Package Cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\vcredist_x86.exe
- hidden files
- file extensions
- User Account Control (UAC)
- 'C:\ProgramData\ZQIIosos\XiskIEYE.exe'
- 'C:\ProgramData\sIAowgok\rSYkcwMw.exe'
- '%HOMEPATH%\CaIocokM\GocwIYEU.exe'
- '<SYSTEM32>\reg.exe' /c "<Current directory>\<Virus name>"
- '<SYSTEM32>\conhost.exe'
- '<SYSTEM32>\conhost.exe' <LS_APPDATA>\Temp/file.vbs
- '<SYSTEM32>\reg.exe' 0x9ac <Virus name>.exe
- '<SYSTEM32>\conhost.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
- '<SYSTEM32>\reg.exe' /pid=0xa84 /log
- '<SYSTEM32>\reg.exe' 0xb64 cscript.exe
- '<SYSTEM32>\reg.exe' /pid=0x7d8 /log
- '<SYSTEM32>\conhost.exe' /c ""%TEMP%\tOQIwQgM.bat" "<Full path to virus>""
- '<SYSTEM32>\reg.exe' /c ""%TEMP%\duQAMkAQ.bat" "<Full path to virus>""
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
- '<SYSTEM32>\cscript.exe' <LS_APPDATA>\Temp/file.vbs
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
- '<SYSTEM32>\conhost.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
- '<SYSTEM32>\conhost.exe' /c "<Current directory>\<Virus name>"
- '<SYSTEM32>\conhost.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
- '<SYSTEM32>\cscript.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
- '<SYSTEM32>\reg.exe' 0x8a0 cscript.exe
- <Current directory>\xWMc.ico
- <Current directory>\lwAE.exe
- C:\RCXDBA5.tmp
- <Current directory>\IOcA.ico
- <Current directory>\EMcW.exe
- C:\RCXD9FF.tmp
- <Current directory>\esoM.ico
- <Current directory>\dUIc.exe
- C:\RCXE00B.tmp
- <Current directory>\IkMQ.ico
- <Current directory>\IUoG.exe
- C:\RCXDD0D.tmp
- <Current directory>\nyYU.ico
- <Current directory>\XwwW.exe
- %TEMP%\dcYwAEUA.bat
- C:\RCXD3C5.tmp
- <Current directory>\PgMS.exe
- C:\RCXD135.tmp
- <Current directory>\eAkw.ico
- <Current directory>\xEEc.ico
- %TEMP%\VcEMEEMk.bat
- <Current directory>\AUge.exe
- C:\RCXD7BD.tmp
- <Current directory>\PAgA.exe
- C:\RCXD4FE.tmp
- <Current directory>\vKsE.ico
- C:\RCXE973.tmp
- %TEMP%\OsocsgQw.bat
- <Current directory>\DkIg.ico
- C:\RCXE79E.tmp
- <Current directory>\okkg.ico
- <Current directory>\lcEI.exe
- <Current directory>\Tccg.exe
- <Current directory>\uIwi.exe
- C:\RCXEE65.tmp
- <Current directory>\pIYI.ico
- C:\RCXEC13.tmp
- %TEMP%\VSggAEMY.bat
- <Current directory>\fIYM.ico
- <Current directory>\ykQK.exe
- C:\RCXE28C.tmp
- <Current directory>\dkAs.ico
- <Current directory>\tsIC.exe
- C:\RCXE182.tmp
- <Current directory>\SeQo.ico
- <Current directory>\ZMcC.exe
- C:\RCXE607.tmp
- <Current directory>\YWcI.ico
- <Current directory>\bQAw.exe
- C:\RCXE442.tmp
- <Current directory>\lIcM.ico
- <Current directory>\pEQQ.exe
- <Current directory>\YacE.ico
- C:\RCXBC61.tmp
- <Current directory>\nIME.ico
- %TEMP%\NaEMoooY.bat
- C:\RCXBA3E.tmp
- <Current directory>\LaMQ.ico
- <Current directory>\bskG.exe
- <Current directory>\lkMs.exe
- <Current directory>\socW.exe
- C:\RCXC134.tmp
- <Current directory>\xAQs.ico
- C:\RCXBED2.tmp
- %TEMP%\REAgMwEA.bat
- <Current directory>\cIkI.ico
- <Current directory>\cAEY.exe
- C:\RCXB5A9.tmp
- <Current directory>\UyMs.ico
- <Current directory>\lUsE.exe
- C:\RCXB386.tmp
- <Current directory>\SMUQ.ico
- <Current directory>\FMQo.exe
- C:\RCXB898.tmp
- <Current directory>\fuYE.ico
- <Current directory>\tQQE.exe
- C:\RCXB6D3.tmp
- <Current directory>\oOQE.ico
- <Current directory>\EwAG.exe
- C:\RCXCCED.tmp
- <Current directory>\uQYU.ico
- <Current directory>\YsAm.exe
- C:\RCXCABA.tmp
- <Current directory>\fIMI.ico
- <Current directory>\OIQI.exe
- C:\RCXCDC8.tmp
- <Current directory>\DsMA.ico
- <Current directory>\vgEE.exe
- C:\RCXCF41.tmp
- <Current directory>\xmcs.ico
- <Current directory>\vQYm.exe
- C:\RCXCE65.tmp
- <Current directory>\MQEE.exe
- C:\RCXC451.tmp
- <Current directory>\xGMo.ico
- <Current directory>\EoAo.exe
- C:\RCXC2F9.tmp
- <Current directory>\KIAo.ico
- <Current directory>\pcsA.exe
- C:\RCXC8D6.tmp
- <Current directory>\YQsw.ico
- <Current directory>\EQIG.exe
- C:\RCXC6C2.tmp
- <Current directory>\suQs.ico
- <Current directory>\ZIIa.exe
- C:\RCX1444.tmp
- <Current directory>\BukA.ico
- <Current directory>\WwcI.exe
- C:\RCX125F.tmp
- <Current directory>\jUcI.ico
- <Current directory>\Wsci.exe
- %TEMP%\JKwgQgwg.bat
- C:\RCX18E7.tmp
- %TEMP%\oMEUMIwA.bat
- <Current directory>\nmkU.ico
- C:\RCX1657.tmp
- <Current directory>\zqEU.ico
- <Current directory>\icAW.exe
- <Current directory>\dYoE.exe
- C:\RCXD3E.tmp
- <Current directory>\JyEc.ico
- <Current directory>\XIIM.exe
- C:\RCXB69.tmp
- <Current directory>\tEwU.ico
- <Current directory>\XggS.exe
- C:\RCX10A9.tmp
- <Current directory>\iGoQ.ico
- <Current directory>\uYcg.exe
- C:\RCXF90.tmp
- <Current directory>\cuoo.ico
- <Current directory>\kwkO.exe
- C:\RCX23E5.tmp
- <Current directory>\GOAk.ico
- <Current directory>\aMMg.exe
- C:\RCX2210.tmp
- <Current directory>\AEIU.ico
- <Current directory>\LgMu.exe
- C:\RCX24F0.tmp
- <Current directory>\wsgY.ico
- <Current directory>\XksS.exe
- C:\RCX286B.tmp
- <Current directory>\LUQo.ico
- <Current directory>\ZsEg.exe
- C:\RCX25EA.tmp
- <Current directory>\mwEk.exe
- C:\RCX1CC0.tmp
- <Current directory>\Kuks.ico
- <Current directory>\FoQG.exe
- C:\RCX1BC6.tmp
- <Current directory>\neEc.ico
- <Current directory>\eEQo.exe
- C:\RCX1F90.tmp
- <Current directory>\Rwgc.ico
- <Current directory>\PYkI.exe
- C:\RCX1DBB.tmp
- <Current directory>\pOEU.ico
- <Current directory>\ZAQe.exe
- <Current directory>\DwUs.ico
- C:\RCXF879.tmp
- <Current directory>\yIkE.ico
- <Current directory>\hEEo.exe
- C:\RCXF656.tmp
- <Current directory>\xIMU.ico
- <Current directory>\WQYm.exe
- C:\RCXFA5D.tmp
- <Current directory>\FEwk.ico
- <Current directory>\WQsg.exe
- C:\RCXFCCF.tmp
- <Current directory>\WAkg.ico
- <Current directory>\XsoM.exe
- C:\RCXFBD5.tmp
- <Current directory>\xIks.exe
- C:\RCXF1FF.tmp
- <Current directory>\miUo.ico
- <Current directory>\PMYA.exe
- C:\RCXEFDC.tmp
- <Current directory>\ziwA.ico
- <Current directory>\awkE.exe
- C:\RCXF4AF.tmp
- <Current directory>\dUMg.ico
- <Current directory>\pYEG.exe
- C:\RCXF338.tmp
- <Current directory>\bYUo.ico
- <Current directory>\zMoS.exe
- C:\RCX5C9.tmp
- <Current directory>\pWEg.ico
- <Current directory>\PcMu.exe
- %TEMP%\tOQIwQgM.bat
- <Current directory>\okMY.ico
- <Current directory>\Ywke.exe
- C:\RCX77F.tmp
- <Current directory>\zqQE.ico
- <Current directory>\JcEM.exe
- C:\RCXAAC.tmp
- <Current directory>\dqgA.ico
- <Current directory>\UsUG.exe
- C:\RCX8A9.tmp
- <Current directory>\fyoY.ico
- <Current directory>\usoW.exe
- C:\RCX3B.tmp
- <Current directory>\JWwc.ico
- <Current directory>\mYMk.exe
- C:\RCXFE85.tmp
- %TEMP%\PeYMgAQk.bat
- <Current directory>\EYUU.ico
- <Current directory>\PEcy.exe
- C:\RCX3E5.tmp
- <Current directory>\bSgw.ico
- <Current directory>\uQIi.exe
- C:\RCX25E.tmp
- <Current directory>\mUkO.exe
- C:\RCX5BC9.tmp
- <Current directory>\rCcA.ico
- <Current directory>\PMoU.exe
- C:\RCX58FA.tmp
- <Current directory>\HiwE.ico
- <Current directory>\ugAy.exe
- C:\RCX630B.tmp
- <Current directory>\dGYM.ico
- <Current directory>\HsgM.exe
- C:\RCX605C.tmp
- <Current directory>\VUAk.ico
- <Current directory>\AEUA.exe
- <Current directory>\LQEA.ico
- <Current directory>\ksES.exe
- C:\RCX4F18.tmp
- <Current directory>\RQwM.ico
- <Current directory>\NkEW.exe
- C:\RCX4B02.tmp
- <Current directory>\wyUE.ico
- <Current directory>\BkIq.exe
- C:\RCX561C.tmp
- <Current directory>\oUYw.ico
- <Current directory>\dgYG.exe
- C:\RCX52A2.tmp
- <Current directory>\dKEI.ico
- <Current directory>\AAYu.exe
- C:\RCX6F8F.tmp
- <Current directory>\SmYE.ico
- <Current directory>\wQwk.exe
- C:\RCX6CC1.tmp
- <Current directory>\oAsI.ico
- <Current directory>\oEUI.exe
- C:\RCX7358.tmp
- <Current directory>\lKIs.ico
- <Current directory>\xYMU.exe
- C:\RCX7135.tmp
- <Current directory>\viwU.ico
- <Current directory>\oYoC.exe
- C:\RCX660A.tmp
- <Current directory>\NEsE.ico
- <Current directory>\xgIs.exe
- C:\RCX64E0.tmp
- <Current directory>\NAAM.ico
- <Current directory>\uswA.exe
- C:\RCX67CF.tmp
- C:\RCX6AEC.tmp
- %TEMP%\KEookMMs.bat
- <Current directory>\GGgc.ico
- %TEMP%\HiUUUsYY.bat
- <Current directory>\TqQk.ico
- <Current directory>\rcsE.exe
- C:\RCX4862.tmp
- <Current directory>\pkEa.exe
- C:\RCX19D8.tmp
- <Current directory>\Hucw.ico
- <Current directory>\LIQg.exe
- C:\RCXE72.tmp
- <Current directory>\OmoY.ico
- <Current directory>\acIm.exe
- C:\RCX2002.tmp
- <Current directory>\VsIw.ico
- <Current directory>\uwMc.exe
- C:\RCX1D33.tmp
- <Current directory>\UgMs.ico
- <Current directory>\qQcw.exe
- <SYSTEM32>\config\systemprofile\CaIocokM\GocwIYEU
- C:\ProgramData\kaog.txt
- %TEMP%\uIAoogoY.bat
- %HOMEPATH%\CaIocokM\GocwIYEU
- C:\ProgramData\sIAowgok\rSYkcwMw
- C:\ProgramData\ZQIIosos\XiskIEYE.exe
- <Current directory>\<Virus name>
- <Current directory>\vgAy.exe
- C:\RCXBA3.tmp
- <Current directory>\DWEY.ico
- %TEMP%\wiUUAoIo.bat
- %TEMP%\file.vbs
- <Current directory>\QMwc.ico
- <Current directory>\CYMw.exe
- C:\RCX3B07.tmp
- <Current directory>\MGok.ico
- <Current directory>\GYEA.exe
- C:\RCX37EA.tmp
- <Current directory>\ReIE.ico
- <Current directory>\FAwU.exe
- C:\RCX4381.tmp
- <Current directory>\WMIQ.ico
- <Current directory>\LEAs.exe
- C:\RCX3E81.tmp
- <Current directory>\tIIw.ico
- <Current directory>\mcwm.exe
- C:\RCX2AAE.tmp
- <Current directory>\noEM.ico
- <Current directory>\GMIa.exe
- C:\RCX23DA.tmp
- <Current directory>\mKQI.ico
- <Current directory>\bsss.exe
- C:\RCX2F8F.tmp
- C:\RCX32F9.tmp
- %TEMP%\DqYQssIY.bat
- <Current directory>\TIok.ico
- <Current directory>\MMUA.ico
- %TEMP%\yyEsgQsw.bat
- <Current directory>\doQU.exe
- <Current directory>\QqoI.ico
- <Current directory>\GAsa.exe
- C:\RCX9F7E.tmp
- <Current directory>\ZYks.ico
- <Current directory>\AwUE.exe
- C:\RCX9E65.tmp
- <Current directory>\VIYQ.ico
- <Current directory>\JgUI.exe
- C:\RCXA1E1.tmp
- <Current directory>\mgog.ico
- <Current directory>\bEsc.exe
- C:\RCXA0A8.tmp
- <Current directory>\OEcc.ico
- C:\RCX977E.tmp
- <Current directory>\POMY.ico
- <Current directory>\yMQI.exe
- C:\RCX954B.tmp
- <Current directory>\scsw.ico
- <Current directory>\Askk.exe
- C:\RCX9B17.tmp
- <Current directory>\huIs.ico
- <Current directory>\VwkE.exe
- C:\RCX9DA8.tmp
- <Current directory>\ZOoo.ico
- <Current directory>\RgcQ.exe
- C:\RCX9CBD.tmp
- <Current directory>\QiEQ.ico
- <Current directory>\IkoY.exe
- C:\RCXAE26.tmp
- <Current directory>\cogA.ico
- <Current directory>\oQsI.exe
- C:\RCXAC51.tmp
- <Current directory>\UgAQ.ico
- <Current directory>\RQog.exe
- C:\RCXB134.tmp
- <Current directory>\EIYc.ico
- <Current directory>\GEoq.exe
- C:\RCXAFAD.tmp
- <Current directory>\fgsU.ico
- <Current directory>\pwME.exe
- %TEMP%\zaQwcsMM.bat
- C:\RCXA656.tmp
- <Current directory>\goAK.exe
- C:\RCXA3C5.tmp
- <Current directory>\mMUY.ico
- <Current directory>\keAQ.ico
- <Current directory>\ciwU.ico
- <Current directory>\UsgU.exe
- C:\RCXA964.tmp
- <Current directory>\qgok.exe
- C:\RCXA7BD.tmp
- %TEMP%\GQMcoQsI.bat
- <Current directory>\skYw.exe
- <Current directory>\DkUs.ico
- %TEMP%\UKUgMAIk.bat
- <Current directory>\uAcc.exe
- <Current directory>\mCYk.ico
- <Current directory>\Hscy.exe
- C:\RCX7E66.tmp
- C:\RCX80C7.tmp
- C:\RCX8319.tmp
- <Current directory>\psYw.ico
- <Current directory>\ssMS.exe
- %TEMP%\hOoQcAss.bat
- <Current directory>\GSoc.ico
- <Current directory>\scgi.exe
- C:\RCX7760.tmp
- <Current directory>\sSkM.ico
- <Current directory>\Pgoa.exe
- C:\RCX75E9.tmp
- <Current directory>\wQsw.ico
- <Current directory>\NYgU.exe
- C:\RCX78F7.tmp
- <Current directory>\pGAo.ico
- <Current directory>\rQcW.exe
- C:\RCX7C62.tmp
- <Current directory>\Nskc.ico
- <Current directory>\TUAA.exe
- C:\RCX7ACC.tmp
- C:\RCX9087.tmp
- <Current directory>\DSQk.ico
- <Current directory>\HwYM.exe
- <Auxiliary element>
- <Current directory>\rkMo.ico
- <Current directory>\DkMw.exe
- C:\RCX920E.tmp
- C:\RCX9309.tmp
- %TEMP%\duQAMkAQ.bat
- <Current directory>\eyYY.ico
- <Current directory>\TGoo.ico
- %TEMP%\pYEgsoQA.bat
- <Current directory>\akYY.exe
- C:\RCX879E.tmp
- <Current directory>\Tcsk.ico
- <Current directory>\cgAw.exe
- C:\RCX850D.tmp
- <Current directory>\fMgI.ico
- <Current directory>\cIom.exe
- C:\RCX8A2E.tmp
- <Current directory>\AsEw.ico
- <Current directory>\gwAQ.exe
- C:\RCX8E64.tmp
- <Current directory>\ookc.ico
- <Current directory>\OYcY.exe
- C:\RCX8B76.tmp
- <Current directory>\lwAE.exe
- <Current directory>\esoM.ico
- <Current directory>\EMcW.exe
- <Current directory>\xWMc.ico
- <Current directory>\dUIc.exe
- <Current directory>\IkMQ.ico
- <Current directory>\IUoG.exe
- <Current directory>\nyYU.ico
- <Current directory>\IOcA.ico
- <Current directory>\XwwW.exe
- %TEMP%\dcYwAEUA.bat
- <Current directory>\PgMS.exe
- <Current directory>\eAkw.ico
- <Current directory>\vKsE.ico
- <Current directory>\AUge.exe
- <Current directory>\xEEc.ico
- <Current directory>\PAgA.exe
- %TEMP%\OsocsgQw.bat
- <Current directory>\DkIg.ico
- <Current directory>\okkg.ico
- <Current directory>\lcEI.exe
- <Current directory>\uIwi.exe
- <Current directory>\pIYI.ico
- <Current directory>\Tccg.exe
- <Current directory>\fIYM.ico
- <Current directory>\bQAw.exe
- <Current directory>\ykQK.exe
- <Current directory>\dkAs.ico
- <Current directory>\tsIC.exe
- <Current directory>\SeQo.ico
- <Current directory>\pEQQ.exe
- <Current directory>\YWcI.ico
- <Current directory>\ZMcC.exe
- <Current directory>\lIcM.ico
- <Current directory>\nIME.ico
- <Current directory>\lkMs.exe
- <Current directory>\bskG.exe
- %TEMP%\NaEMoooY.bat
- <Current directory>\xAQs.ico
- <Current directory>\EoAo.exe
- <Current directory>\cIkI.ico
- <Current directory>\socW.exe
- <Current directory>\LaMQ.ico
- <Current directory>\UyMs.ico
- <Current directory>\FMQo.exe
- <Current directory>\SMUQ.ico
- <Current directory>\cAEY.exe
- <Current directory>\fuYE.ico
- <Current directory>\tQQE.exe
- <Current directory>\oOQE.ico
- <Current directory>\EwAG.exe
- <Current directory>\YsAm.exe
- <Current directory>\xmcs.ico
- <Current directory>\OIQI.exe
- <Current directory>\uQYU.ico
- <Current directory>\vgEE.exe
- <Current directory>\YacE.ico
- <Current directory>\vQYm.exe
- <Current directory>\DsMA.ico
- <Current directory>\fIMI.ico
- <Current directory>\xGMo.ico
- <Current directory>\pcsA.exe
- <Current directory>\KIAo.ico
- <Current directory>\MQEE.exe
- <Current directory>\YQsw.ico
- <Current directory>\EQIG.exe
- <Current directory>\suQs.ico
- <Current directory>\ZIIa.exe
- <Current directory>\Wsci.exe
- %TEMP%\tOQIwQgM.bat
- <Current directory>\uYcg.exe
- <Current directory>\jUcI.ico
- %TEMP%\JKwgQgwg.bat
- <Current directory>\zqEU.ico
- <Current directory>\BukA.ico
- <Current directory>\WwcI.exe
- <Current directory>\iGoQ.ico
- <Current directory>\tEwU.ico
- <Current directory>\dYoE.exe
- <Current directory>\DwUs.ico
- <Current directory>\XIIM.exe
- <Current directory>\cuoo.ico
- <Current directory>\kwkO.exe
- <Current directory>\JyEc.ico
- <Current directory>\XggS.exe
- <Current directory>\AEIU.ico
- <Current directory>\LgMu.exe
- <Current directory>\Rwgc.ico
- <Current directory>\PYkI.exe
- <Current directory>\LUQo.ico
- <Current directory>\ZsEg.exe
- <Current directory>\GOAk.ico
- <Current directory>\aMMg.exe
- <Current directory>\ZAQe.exe
- <Current directory>\FoQG.exe
- <Current directory>\neEc.ico
- <Current directory>\icAW.exe
- <Current directory>\nmkU.ico
- <Current directory>\eEQo.exe
- <Current directory>\pOEU.ico
- <Current directory>\mwEk.exe
- <Current directory>\Kuks.ico
- <Current directory>\yIkE.ico
- <Current directory>\hEEo.exe
- <Current directory>\xIMU.ico
- <Current directory>\WQYm.exe
- <Current directory>\FEwk.ico
- <Current directory>\WQsg.exe
- <Current directory>\WAkg.ico
- <Current directory>\XsoM.exe
- <Current directory>\pYEG.exe
- <Current directory>\xIks.exe
- <Current directory>\miUo.ico
- <Current directory>\PMYA.exe
- <Current directory>\ziwA.ico
- <Current directory>\zMoS.exe
- <Current directory>\dUMg.ico
- <Current directory>\awkE.exe
- <Current directory>\bYUo.ico
- <Current directory>\pWEg.ico
- <Current directory>\PcMu.exe
- <Current directory>\okMY.ico
- <Current directory>\Ywke.exe
- <Current directory>\zqQE.ico
- <Current directory>\JcEM.exe
- <Current directory>\dqgA.ico
- <Current directory>\UsUG.exe
- <Current directory>\PEcy.exe
- <Current directory>\fyoY.ico
- <Current directory>\usoW.exe
- <Current directory>\JWwc.ico
- <Current directory>\mYMk.exe
- <Current directory>\uQIi.exe
- <Current directory>\EYUU.ico
- %TEMP%\PeYMgAQk.bat
- <Current directory>\bSgw.ico
- <Current directory>\AEUA.exe
- <Current directory>\dGYM.ico
- <Current directory>\ugAy.exe
- <Current directory>\VUAk.ico
- <Current directory>\uswA.exe
- <Current directory>\NEsE.ico
- <Current directory>\HsgM.exe
- <Current directory>\NAAM.ico
- <Current directory>\rCcA.ico
- <Current directory>\dKEI.ico
- <Current directory>\BkIq.exe
- <Current directory>\wyUE.ico
- <Current directory>\dgYG.exe
- <Current directory>\HiwE.ico
- <Current directory>\mUkO.exe
- <Current directory>\oUYw.ico
- <Current directory>\PMoU.exe
- <Current directory>\oYoC.exe
- <Current directory>\lKIs.ico
- <Current directory>\oEUI.exe
- <Current directory>\viwU.ico
- <Current directory>\NYgU.exe
- <Current directory>\sSkM.ico
- <Current directory>\xYMU.exe
- <Current directory>\wQsw.ico
- <Current directory>\SmYE.ico
- <Current directory>\TqQk.ico
- <Current directory>\rcsE.exe
- <Current directory>\xgIs.exe
- %TEMP%\HiUUUsYY.bat
- <Current directory>\oAsI.ico
- <Current directory>\AAYu.exe
- <Current directory>\GGgc.ico
- <Current directory>\wQwk.exe
- <Current directory>\VsIw.ico
- <Current directory>\uwMc.exe
- <Current directory>\UgMs.ico
- <Current directory>\qQcw.exe
- <Current directory>\noEM.ico
- <Current directory>\GMIa.exe
- <Current directory>\mKQI.ico
- <Current directory>\bsss.exe
- <Current directory>\acIm.exe
- <Current directory>\vgAy.exe
- <Current directory>\DWEY.ico
- %TEMP%\uIAoogoY.bat
- <Current directory>\QMwc.ico
- <Current directory>\pkEa.exe
- <Current directory>\Hucw.ico
- <Current directory>\LIQg.exe
- <Current directory>\OmoY.ico
- <Current directory>\WMIQ.ico
- <Current directory>\LEAs.exe
- <Current directory>\tIIw.ico
- <Current directory>\mcwm.exe
- <Current directory>\LQEA.ico
- <Current directory>\ksES.exe
- <Current directory>\RQwM.ico
- <Current directory>\NkEW.exe
- <Current directory>\FAwU.exe
- <Current directory>\doQU.exe
- <Current directory>\TIok.ico
- %TEMP%\yyEsgQsw.bat
- <Current directory>\MMUA.ico
- <Current directory>\CYMw.exe
- <Current directory>\MGok.ico
- <Current directory>\GYEA.exe
- <Current directory>\ReIE.ico
- <Current directory>\VIYQ.ico
- <Current directory>\bEsc.exe
- <Current directory>\QqoI.ico
- <Current directory>\GAsa.exe
- <Current directory>\mgog.ico
- <Current directory>\goAK.exe
- <Current directory>\OEcc.ico
- <Current directory>\JgUI.exe
- <Current directory>\AwUE.exe
- <Current directory>\yMQI.exe
- <Current directory>\ZOoo.ico
- %TEMP%\duQAMkAQ.bat
- <Current directory>\POMY.ico
- <Current directory>\VwkE.exe
- <Current directory>\ZYks.ico
- <Current directory>\RgcQ.exe
- <Current directory>\huIs.ico
- <Current directory>\UgAQ.ico
- <Current directory>\GEoq.exe
- <Current directory>\QiEQ.ico
- <Current directory>\IkoY.exe
- <Current directory>\EIYc.ico
- <Current directory>\lUsE.exe
- <Current directory>\fgsU.ico
- <Current directory>\RQog.exe
- <Current directory>\oQsI.exe
- %TEMP%\zaQwcsMM.bat
- <Current directory>\keAQ.ico
- <Current directory>\mMUY.ico
- <Current directory>\pwME.exe
- <Current directory>\UsgU.exe
- <Current directory>\cogA.ico
- <Current directory>\qgok.exe
- <Current directory>\ciwU.ico
- <Current directory>\scgi.exe
- <Current directory>\psYw.ico
- <Current directory>\uAcc.exe
- <Current directory>\GSoc.ico
- <Current directory>\cIom.exe
- <Current directory>\Tcsk.ico
- <Current directory>\ssMS.exe
- <Current directory>\fMgI.ico
- <Current directory>\DkUs.ico
- <Current directory>\TUAA.exe
- <Current directory>\pGAo.ico
- <Current directory>\Pgoa.exe
- <Current directory>\Nskc.ico
- <Current directory>\Hscy.exe
- %TEMP%\UKUgMAIk.bat
- <Current directory>\rQcW.exe
- <Current directory>\mCYk.ico
- <Current directory>\TGoo.ico
- <Current directory>\akYY.exe
- <Current directory>\HwYM.exe
- %TEMP%\pYEgsoQA.bat
- <Current directory>\scsw.ico
- <Current directory>\Askk.exe
- <Current directory>\eyYY.ico
- <Current directory>\skYw.exe
- <Current directory>\DSQk.ico
- <Current directory>\OYcY.exe
- <Current directory>\AsEw.ico
- <Current directory>\cgAw.exe
- <Current directory>\ookc.ico
- <Current directory>\rkMo.ico
- <Current directory>\DkMw.exe
- <Current directory>\gwAQ.exe
- %TEMP%\hOoQcAss.bat
- from C:\RCXDD0D.tmp to <Current directory>\IUoG.exe
- from C:\RCXDBA5.tmp to <Current directory>\lwAE.exe
- from C:\RCXE182.tmp to <Current directory>\tsIC.exe
- from C:\RCXE00B.tmp to <Current directory>\dUIc.exe
- from C:\RCXD4FE.tmp to <Current directory>\PAgA.exe
- from C:\RCXD3C5.tmp to <Current directory>\XwwW.exe
- from C:\RCXD9FF.tmp to <Current directory>\EMcW.exe
- from C:\RCXD7BD.tmp to <Current directory>\AUge.exe
- from C:\RCXEC13.tmp to <Current directory>\Tccg.exe
- from C:\RCXE973.tmp to <Current directory>\lcEI.exe
- from C:\RCXEFDC.tmp to <Current directory>\PMYA.exe
- from C:\RCXEE65.tmp to <Current directory>\uIwi.exe
- from C:\RCXE442.tmp to <Current directory>\ZMcC.exe
- from C:\RCXE28C.tmp to <Current directory>\ykQK.exe
- from C:\RCXE79E.tmp to <Current directory>\bQAw.exe
- from C:\RCXE607.tmp to <Current directory>\pEQQ.exe
- from C:\RCXC134.tmp to <Current directory>\socW.exe
- from C:\RCXBED2.tmp to <Current directory>\lkMs.exe
- from C:\RCXC451.tmp to <Current directory>\MQEE.exe
- from C:\RCXC2F9.tmp to <Current directory>\EoAo.exe
- from C:\RCXB898.tmp to <Current directory>\EwAG.exe
- from C:\RCXB6D3.tmp to <Current directory>\FMQo.exe
- from C:\RCXBC61.tmp to <Current directory>\bskG.exe
- from C:\RCXBA3E.tmp to <Current directory>\tQQE.exe
- from C:\RCXCE65.tmp to <Current directory>\vQYm.exe
- from C:\RCXCDC8.tmp to <Current directory>\YsAm.exe
- from C:\RCXD135.tmp to <Current directory>\PgMS.exe
- from C:\RCXCF41.tmp to <Current directory>\vgEE.exe
- from C:\RCXC8D6.tmp to <Current directory>\ZIIa.exe
- from C:\RCXC6C2.tmp to <Current directory>\pcsA.exe
- from C:\RCXCCED.tmp to <Current directory>\OIQI.exe
- from C:\RCXCABA.tmp to <Current directory>\EQIG.exe
- from C:\RCX1444.tmp to <Current directory>\Wsci.exe
- from C:\RCX125F.tmp to <Current directory>\uYcg.exe
- from C:\RCX18E7.tmp to <Current directory>\icAW.exe
- from C:\RCX1657.tmp to <Current directory>\WwcI.exe
- from C:\RCXD3E.tmp to <Current directory>\dYoE.exe
- from C:\RCXB69.tmp to <Current directory>\XIIM.exe
- from C:\RCX10A9.tmp to <Current directory>\kwkO.exe
- from C:\RCXF90.tmp to <Current directory>\XggS.exe
- from C:\RCX23E5.tmp to <Current directory>\LgMu.exe
- from C:\RCX2210.tmp to <Current directory>\PYkI.exe
- from C:\RCX25EA.tmp to <Current directory>\ZsEg.exe
- from C:\RCX24F0.tmp to <Current directory>\aMMg.exe
- from C:\RCX1CC0.tmp to <Current directory>\mwEk.exe
- from C:\RCX1BC6.tmp to <Current directory>\FoQG.exe
- from C:\RCX1F90.tmp to <Current directory>\ZAQe.exe
- from C:\RCX1DBB.tmp to <Current directory>\eEQo.exe
- from C:\RCXFA5D.tmp to <Current directory>\hEEo.exe
- from C:\RCXF879.tmp to <Current directory>\WQYm.exe
- from C:\RCXFCCF.tmp to <Current directory>\WQsg.exe
- from C:\RCXFBD5.tmp to <Current directory>\XsoM.exe
- from C:\RCXF338.tmp to <Current directory>\awkE.exe
- from C:\RCXF1FF.tmp to <Current directory>\xIks.exe
- from C:\RCXF656.tmp to <Current directory>\pYEG.exe
- from C:\RCXF4AF.tmp to <Current directory>\zMoS.exe
- from C:\RCX77F.tmp to <Current directory>\PcMu.exe
- from C:\RCX5C9.tmp to <Current directory>\Ywke.exe
- from C:\RCXAAC.tmp to <Current directory>\JcEM.exe
- from C:\RCX8A9.tmp to <Current directory>\UsUG.exe
- from C:\RCX3B.tmp to <Current directory>\usoW.exe
- from C:\RCXFE85.tmp to <Current directory>\mYMk.exe
- from C:\RCX3E5.tmp to <Current directory>\PEcy.exe
- from C:\RCX25E.tmp to <Current directory>\uQIi.exe
- from C:\RCXB5A9.tmp to <Current directory>\cAEY.exe
- from C:\RCX630B.tmp to <Current directory>\AEUA.exe
- from C:\RCX605C.tmp to <Current directory>\ugAy.exe
- from C:\RCX660A.tmp to <Current directory>\uswA.exe
- from C:\RCX64E0.tmp to <Current directory>\HsgM.exe
- from C:\RCX561C.tmp to <Current directory>\BkIq.exe
- from C:\RCX52A2.tmp to <Current directory>\dgYG.exe
- from C:\RCX5BC9.tmp to <Current directory>\mUkO.exe
- from C:\RCX58FA.tmp to <Current directory>\PMoU.exe
- from C:\RCX7358.tmp to <Current directory>\oYoC.exe
- from C:\RCX7135.tmp to <Current directory>\oEUI.exe
- from C:\RCX7760.tmp to <Current directory>\NYgU.exe
- from C:\RCX75E9.tmp to <Current directory>\xYMU.exe
- from C:\RCX6AEC.tmp to <Current directory>\rcsE.exe
- from C:\RCX67CF.tmp to <Current directory>\xgIs.exe
- from C:\RCX6F8F.tmp to <Current directory>\AAYu.exe
- from C:\RCX6CC1.tmp to <Current directory>\wQwk.exe
- from C:\RCX23DA.tmp to <Current directory>\uwMc.exe
- from C:\RCX2002.tmp to <Current directory>\qQcw.exe
- from C:\RCX2F8F.tmp to <Current directory>\GMIa.exe
- from C:\RCX2AAE.tmp to <Current directory>\bsss.exe
- from C:\RCXE72.tmp to <Current directory>\LIQg.exe
- from C:\RCXBA3.tmp to <Current directory>\vgAy.exe
- from C:\RCX1D33.tmp to <Current directory>\acIm.exe
- from C:\RCX19D8.tmp to <Current directory>\pkEa.exe
- from C:\RCX4862.tmp to <Current directory>\LEAs.exe
- from C:\RCX4381.tmp to <Current directory>\mcwm.exe
- from C:\RCX4F18.tmp to <Current directory>\ksES.exe
- from C:\RCX4B02.tmp to <Current directory>\NkEW.exe
- from C:\RCX37EA.tmp to <Current directory>\GYEA.exe
- from C:\RCX32F9.tmp to <Current directory>\doQU.exe
- from C:\RCX3E81.tmp to <Current directory>\FAwU.exe
- from C:\RCX3B07.tmp to <Current directory>\CYMw.exe
- from C:\RCXA0A8.tmp to <Current directory>\bEsc.exe
- from C:\RCX9F7E.tmp to <Current directory>\GAsa.exe
- from C:\RCXA3C5.tmp to <Current directory>\goAK.exe
- from C:\RCXA1E1.tmp to <Current directory>\JgUI.exe
- from C:\RCX9CBD.tmp to <Current directory>\RgcQ.exe
- from C:\RCX9B17.tmp to <Current directory>\yMQI.exe
- from C:\RCX9E65.tmp to <Current directory>\AwUE.exe
- from C:\RCX9DA8.tmp to <Current directory>\VwkE.exe
- from C:\RCXAFAD.tmp to <Current directory>\GEoq.exe
- from C:\RCXAE26.tmp to <Current directory>\IkoY.exe
- from C:\RCXB386.tmp to <Current directory>\lUsE.exe
- from C:\RCXB134.tmp to <Current directory>\RQog.exe
- from C:\RCXA7BD.tmp to <Current directory>\qgok.exe
- from C:\RCXA656.tmp to <Current directory>\pwME.exe
- from C:\RCXAC51.tmp to <Current directory>\oQsI.exe
- from C:\RCXA964.tmp to <Current directory>\UsgU.exe
- from C:\RCX8319.tmp to <Current directory>\scgi.exe
- from C:\RCX80C7.tmp to <Current directory>\uAcc.exe
- from C:\RCX879E.tmp to <Current directory>\cIom.exe
- from C:\RCX850D.tmp to <Current directory>\ssMS.exe
- from C:\RCX7ACC.tmp to <Current directory>\TUAA.exe
- from C:\RCX78F7.tmp to <Current directory>\Pgoa.exe
- from C:\RCX7E66.tmp to <Current directory>\Hscy.exe
- from C:\RCX7C62.tmp to <Current directory>\rQcW.exe
- from C:\RCX9309.tmp to <Current directory>\akYY.exe
- from C:\RCX920E.tmp to <Current directory>\HwYM.exe
- from C:\RCX977E.tmp to <Current directory>\Askk.exe
- from C:\RCX954B.tmp to <Current directory>\skYw.exe
- from C:\RCX8B76.tmp to <Current directory>\OYcY.exe
- from C:\RCX8A2E.tmp to <Current directory>\cgAw.exe
- from C:\RCX9087.tmp to <Current directory>\DkMw.exe
- from C:\RCX8E64.tmp to <Current directory>\gwAQ.exe
- DNS ASK dn#.##ftncsi.com
- DNS ASK google.com
- ClassName: '' WindowName: 'GocwIYEU.exe'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: 'Microsoft Windows'
- ClassName: 'Indicator' WindowName: ''
- ClassName: '' WindowName: 'rSYkcwMw.exe'