Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,C:\ProgramData\sIAowgok\rSYkcwMw.exe,'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rSYkcwMw.exe' = 'C:\ProgramData\sIAowgok\rSYkcwMw.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'GocwIYEU.exe' = '%HOMEPATH%\CaIocokM\GocwIYEU.exe'
- [<HKLM>\SYSTEM\ControlSet001\services\yoYkgMRX] 'Start' = '00000002'
- C:\ProgramData\Package Cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\vcredist_x86.exe
- hidden files
- file extensions
- User Account Control (UAC)
- 'C:\ProgramData\ZQIIosos\XiskIEYE.exe'
- 'C:\ProgramData\sIAowgok\rSYkcwMw.exe'
- '%HOMEPATH%\CaIocokM\GocwIYEU.exe'
- '<SYSTEM32>\reg.exe' /c ""%TEMP%\IiQoccUg.bat" "<Full path to virus>""
- '<SYSTEM32>\cscript.exe' /pid=0x574 /log
- '<SYSTEM32>\conhost.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
- '<SYSTEM32>\reg.exe' 0xf38 <Virus name>.exe
- '<SYSTEM32>\conhost.exe' /c "<Current directory>\<Virus name>"
- '<SYSTEM32>\conhost.exe' /c ""%TEMP%\zOUEQkEA.bat" "<Full path to virus>""
- '<SYSTEM32>\reg.exe' 0x9ec <Virus name>.exe
- '<SYSTEM32>\conhost.exe' /c ""%TEMP%\KEQEwoUY.bat" "<Full path to virus>""
- '<SYSTEM32>\conhost.exe' /c ""%TEMP%\DMIIQoMg.bat" "<Full path to virus>""
- '<SYSTEM32>\conhost.exe'
- '<SYSTEM32>\conhost.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
- '<SYSTEM32>\cscript.exe' <LS_APPDATA>\Temp/file.vbs
- '<SYSTEM32>\reg.exe' /c "<Current directory>\<Virus name>"
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
- '<SYSTEM32>\reg.exe' /pid=0x570 /log
- '<SYSTEM32>\taskhost.exe'
- '<SYSTEM32>\reg.exe' /pid=0xaf0 /log
- '<SYSTEM32>\conhost.exe' <LS_APPDATA>\Temp/file.vbs
- '<SYSTEM32>\conhost.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
- <Current directory>\esYO.exe
- C:\RCXB7ED.tmp
- <Current directory>\hgkY.ico
- <Current directory>\Hwga.exe
- C:\RCXB54D.tmp
- <Current directory>\oAIs.ico
- <Current directory>\sUEy.exe
- C:\RCXBB1A.tmp
- <Current directory>\AQUU.ico
- <Current directory>\sUEq.exe
- C:\RCXB964.tmp
- <Current directory>\EKYs.ico
- <Current directory>\BiIk.ico
- <Current directory>\Igwg.ico
- <Current directory>\UYMs.exe
- C:\RCXAF9F.tmp
- <Current directory>\cEIs.ico
- <Current directory>\KsEm.exe
- C:\RCXAC83.tmp
- <Current directory>\XAYY.ico
- <Current directory>\VEgM.exe
- C:\RCXB368.tmp
- <Current directory>\POMI.ico
- <Current directory>\uYAO.exe
- C:\RCXB23F.tmp
- <Current directory>\FogI.exe
- <Current directory>\LUga.exe
- C:\RCXCD97.tmp
- <Current directory>\RUgo.ico
- <Current directory>\PgwM.exe
- C:\RCXCC00.tmp
- <Current directory>\UgcQ.ico
- <Current directory>\dQYw.exe
- C:\RCXD46C.tmp
- <Current directory>\HcwQ.ico
- <Current directory>\OMci.exe
- C:\RCXCF9B.tmp
- <Current directory>\csYs.ico
- <Current directory>\iUgc.ico
- <Current directory>\KQkG.exe
- C:\RCXC5C6.tmp
- <Current directory>\zaQk.ico
- C:\RCXC42F.tmp
- <Current directory>\uQAM.ico
- %TEMP%\aCgcEEQs.bat
- <Current directory>\fKAU.ico
- <Current directory>\HIkq.exe
- C:\RCXCA0C.tmp
- <Current directory>\pYAI.exe
- C:\RCXC76C.tmp
- %TEMP%\KEQEwoUY.bat
- <Current directory>\mmQY.ico
- <Current directory>\PEEk.exe
- C:\RCX97CF.tmp
- <Current directory>\OOso.ico
- <Current directory>\ssgA.exe
- C:\RCX95FA.tmp
- <Current directory>\GMgY.ico
- <Current directory>\wYUU.exe
- C:\RCX9C34.tmp
- <Current directory>\JWsE.ico
- <Current directory>\sUkO.exe
- C:\RCX99A4.tmp
- C:\RCX94A2.tmp
- <Current directory>\bUgU.ico
- <Current directory>\BYEI.exe
- C:\RCX901D.tmp
- <Current directory>\ZQYy.exe
- C:\RCX8D30.tmp
- %TEMP%\VgcooUYk.bat
- C:\RCX92FC.tmp
- <Current directory>\CcMU.ico
- <Current directory>\wYUI.exe
- %TEMP%\WCwwwoUU.bat
- <Current directory>\cQMA.ico
- <Current directory>\TkEY.exe
- <Current directory>\LYgY.ico
- C:\RCXA501.tmp
- <Current directory>\pago.ico
- %TEMP%\YscMcEcI.bat
- C:\RCXA37A.tmp
- <Current directory>\Jyog.ico
- <Current directory>\XwcG.exe
- <Current directory>\NUcu.exe
- %TEMP%\DMIIQoMg.bat
- C:\RCXA8E9.tmp
- <Current directory>\NwcM.exe
- C:\RCXA762.tmp
- <Current directory>\gMQc.ico
- <Current directory>\BQIk.exe
- <Current directory>\JgMW.exe
- C:\RCX9F62.tmp
- <Current directory>\zqgM.ico
- <Current directory>\HokU.exe
- C:\RCX9DCB.tmp
- <Current directory>\ZAcY.ico
- <Current directory>\bEoe.exe
- C:\RCXA195.tmp
- <Current directory>\iEcc.ico
- <Current directory>\tEgm.exe
- C:\RCXA08B.tmp
- <Current directory>\oaQA.ico
- <Current directory>\uYsK.exe
- C:\RCXFD46.tmp
- <Current directory>\DMoY.ico
- <Current directory>\ecYe.exe
- C:\RCXFBEE.tmp
- <Current directory>\yWMo.ico
- <Current directory>\BcIc.exe
- C:\RCXFFE7.tmp
- <Current directory>\gmYc.ico
- <Current directory>\AMQQ.exe
- C:\RCXFEDD.tmp
- <Current directory>\Pywk.ico
- %TEMP%\zOUEQkEA.bat
- C:\RCXF5B4.tmp
- <Current directory>\AyYI.ico
- <Current directory>\OUoA.exe
- C:\RCXF43D.tmp
- <Current directory>\XscI.ico
- <Current directory>\cQQu.exe
- <Current directory>\bwUc.exe
- C:\RCXF900.tmp
- <Current directory>\nOQU.ico
- C:\RCXF69F.tmp
- %TEMP%\ouEcQgkU.bat
- <Current directory>\EyAU.ico
- <Current directory>\kgcw.exe
- <Current directory>\eIYU.ico
- <Current directory>\jMsu.exe
- C:\RCXC1E.tmp
- <Current directory>\mqEg.ico
- <Current directory>\mUsQ.exe
- C:\RCXB72.tmp
- <Current directory>\BEUQ.ico
- <Current directory>\XwgU.exe
- C:\RCXFC8.tmp
- <Current directory>\LuEc.ico
- <Current directory>\qYUe.exe
- C:\RCXDB5.tmp
- C:\RCX9DB.tmp
- C:\RCX546.tmp
- <Current directory>\duMI.ico
- <Current directory>\QQYk.exe
- C:\RCX249.tmp
- <Current directory>\REwM.ico
- <Current directory>\doYY.exe
- C:\RCX8B2.tmp
- <Current directory>\cWYM.ico
- <Current directory>\FkIq.exe
- C:\RCX67F.tmp
- <Current directory>\GmEc.ico
- <Current directory>\HQIu.exe
- C:\RCXDEED.tmp
- <Current directory>\yssg.ico
- <Current directory>\BsAW.exe
- C:\RCXDC8C.tmp
- <Current directory>\YkUs.ico
- <Current directory>\kIwM.exe
- <Current directory>\Eckg.exe
- C:\RCXE1FB.tmp
- %TEMP%\FosMsQEM.bat
- %TEMP%\HoEoMMwY.bat
- C:\RCXE0A3.tmp
- <Current directory>\Fcgw.ico
- <Current directory>\fUIS.exe
- <Current directory>\tMoE.exe
- C:\RCXD826.tmp
- <Current directory>\qoso.ico
- <Current directory>\YUgy.exe
- C:\RCXD622.tmp
- <Current directory>\Hkcs.ico
- <Current directory>\vUki.exe
- C:\RCXDBB0.tmp
- <Current directory>\SEsY.ico
- <Current directory>\REow.exe
- C:\RCXDA87.tmp
- <Current directory>\wOsI.ico
- <Current directory>\wyYM.ico
- C:\RCXEEEC.tmp
- <Current directory>\eoog.ico
- <Current directory>\ZAUi.exe
- C:\RCXEE40.tmp
- <Current directory>\KKoo.ico
- <Current directory>\Wwkw.exe
- C:\RCXF14F.tmp
- <Current directory>\MOwA.ico
- <Current directory>\eAMS.exe
- C:\RCXF045.tmp
- <Current directory>\hSkw.ico
- <Current directory>\ZIUc.exe
- <Current directory>\aQcO.exe
- <Current directory>\wEkk.exe
- C:\RCXE90F.tmp
- <Current directory>\lkgg.ico
- <Current directory>\sIgA.exe
- C:\RCXE778.tmp
- <Current directory>\AakU.ico
- <Current directory>\xwMA.exe
- C:\RCXED84.tmp
- <Current directory>\peIo.ico
- <Current directory>\RQEO.exe
- C:\RCXEB51.tmp
- <Current directory>\HkwA.ico
- <Current directory>\nIws.ico
- <Current directory>\JMka.exe
- C:\RCX3F05.tmp
- <Current directory>\GkEu.exe
- C:\RCX3D10.tmp
- %TEMP%\GAYgwYwg.bat
- <Current directory>\EccA.ico
- <Current directory>\xIIq.exe
- C:\RCX4280.tmp
- <Current directory>\KgAc.ico
- <Current directory>\nEQw.exe
- C:\RCX40BA.tmp
- %TEMP%\wIMgAgQs.bat
- <Current directory>\HkQS.exe
- C:\RCX36D6.tmp
- <Current directory>\WUwg.ico
- <Current directory>\nIAG.exe
- C:\RCX34A4.tmp
- <Current directory>\rksM.ico
- <Current directory>\tEAA.exe
- C:\RCX3B4B.tmp
- <Current directory>\Sioo.ico
- <Current directory>\CMgk.exe
- C:\RCX38F9.tmp
- <Current directory>\GoUA.ico
- <Current directory>\emsA.ico
- C:\RCX4D5F.tmp
- <Current directory>\Aokc.ico
- <Current directory>\oUgQ.exe
- C:\RCX4BD8.tmp
- <Current directory>\MSws.ico
- <Current directory>\JUso.exe
- C:\RCX5166.tmp
- <Current directory>\cisc.ico
- <Current directory>\nsMy.exe
- C:\RCX504C.tmp
- <Current directory>\HGUs.ico
- <Current directory>\vYMO.exe
- <Current directory>\gogY.exe
- <Current directory>\KAoy.exe
- C:\RCX48D8.tmp
- <Current directory>\Fugs.ico
- <Current directory>\PgEG.exe
- C:\RCX459C.tmp
- <Current directory>\kyok.ico
- <Current directory>\mkky.exe
- C:\RCX4B4A.tmp
- <Current directory>\nUME.ico
- <Current directory>\wwIi.exe
- C:\RCX4A9E.tmp
- <Current directory>\QkUM.ico
- <Current directory>\AYEG.exe
- C:\RCX200F.tmp
- <Current directory>\nMcY.ico
- <Current directory>\gEAy.exe
- C:\RCX1D41.tmp
- <Current directory>\gQQw.ico
- <Current directory>\EAkq.exe
- C:\RCX2474.tmp
- <Current directory>\vmAU.ico
- <Current directory>\rIMw.exe
- C:\RCX21F4.tmp
- <Current directory>\XGEo.ico
- <Current directory>\lmgs.ico
- <SYSTEM32>\config\systemprofile\CaIocokM\GocwIYEU
- %TEMP%\dMEcIAIw.bat
- <Current directory>\<Virus name>
- %HOMEPATH%\CaIocokM\GocwIYEU
- C:\ProgramData\sIAowgok\rSYkcwMw
- C:\ProgramData\ZQIIosos\XiskIEYE.exe
- <Current directory>\DoAQ.ico
- <Current directory>\fgUi.exe
- C:\RCX1BC9.tmp
- %TEMP%\JGUUkQkc.bat
- C:\ProgramData\kaog.txt
- %TEMP%\file.vbs
- <Current directory>\hEUS.exe
- <Current directory>\yUsg.exe
- C:\RCX3166.tmp
- <Current directory>\xIoM.ico
- <Current directory>\mwQU.exe
- C:\RCX2E97.tmp
- <Current directory>\fsws.ico
- <Current directory>\AAco.exe
- C:\RCX33A9.tmp
- <Current directory>\CQEM.ico
- <Current directory>\pIwg.exe
- C:\RCX3260.tmp
- <Current directory>\pQQo.ico
- <Current directory>\rYwY.ico
- <Current directory>\dUIc.exe
- C:\RCX2937.tmp
- %TEMP%\eOcUAsAE.bat
- C:\RCX25DC.tmp
- %TEMP%\ekEgQogk.bat
- <Current directory>\Yakk.ico
- <Current directory>\EWgI.ico
- <Current directory>\OUUK.exe
- C:\RCX2D4F.tmp
- <Current directory>\kIME.ico
- <Current directory>\BQsM.exe
- C:\RCX2AAF.tmp
- <Current directory>\OuoI.ico
- <Current directory>\XkQO.exe
- C:\RCX7A6F.tmp
- <Current directory>\rEcY.exe
- %TEMP%\mecccoYw.bat
- C:\RCX786C.tmp
- %TEMP%\IiQoccUg.bat
- <Current directory>\wIkU.ico
- <Current directory>\TUEe.exe
- <Current directory>\KmYw.ico
- <Current directory>\GcwM.exe
- C:\RCX7C25.tmp
- <Current directory>\yEYw.ico
- <Current directory>\XEYA.ico
- <Current directory>\rAUi.exe
- C:\RCX71A5.tmp
- <Current directory>\HAss.ico
- <Current directory>\toMc.exe
- C:\RCX700E.tmp
- <Current directory>\FyYc.ico
- <Current directory>\zYcw.exe
- C:\RCX76D5.tmp
- <Current directory>\KcQI.ico
- <Current directory>\EAcm.exe
- C:\RCX73B8.tmp
- C:\RCX7DEB.tmp
- <Current directory>\oYsy.exe
- C:\RCX86E6.tmp
- <Current directory>\CgME.ico
- <Current directory>\OAIO.exe
- C:\RCX84F2.tmp
- <Current directory>\IGcY.ico
- <Current directory>\MgsI.exe
- C:\RCX8AFD.tmp
- <Current directory>\fwos.ico
- <Current directory>\HQwi.exe
- C:\RCX8957.tmp
- <Current directory>\QeUw.ico
- <Current directory>\sCYY.ico
- <Current directory>\VSsw.ico
- <Current directory>\LsQy.exe
- C:\RCX8108.tmp
- <Current directory>\NacA.ico
- <Current directory>\osQY.exe
- C:\RCX7F52.tmp
- <Current directory>\zkUA.ico
- <Current directory>\pIUo.exe
- C:\RCX83A9.tmp
- <Current directory>\scIE.ico
- <Current directory>\FIsO.exe
- C:\RCX8232.tmp
- <Current directory>\guss.ico
- <Current directory>\pUMS.exe
- C:\RCX5D00.tmp
- <Current directory>\YUAA.ico
- <Current directory>\VoUC.exe
- C:\RCX5A32.tmp
- <Current directory>\Esgo.ico
- <Current directory>\AgkW.exe
- C:\RCX60C9.tmp
- <Current directory>\JMoA.ico
- <Current directory>\BcEM.exe
- C:\RCX5ED5.tmp
- <Auxiliary element>
- <Current directory>\OcMq.exe
- C:\RCX533C.tmp
- %TEMP%\BikYkkgk.bat
- C:\RCX5203.tmp
- <Current directory>\BcgQ.ico
- %TEMP%\JycIgAsE.bat
- <Current directory>\DiUk.ico
- <Current directory>\xcoC.exe
- C:\RCX588B.tmp
- <Current directory>\UMMs.ico
- <Current directory>\OksO.exe
- C:\RCX559E.tmp
- <Current directory>\NIck.ico
- <Current directory>\ckMs.ico
- <Current directory>\WcsU.exe
- C:\RCX69A5.tmp
- <Current directory>\DyUw.ico
- <Current directory>\YcUI.exe
- C:\RCX684D.tmp
- <Current directory>\WWwM.ico
- <Current directory>\oEMu.exe
- C:\RCX6EE5.tmp
- <Current directory>\LkUQ.ico
- <Current directory>\tQcS.exe
- C:\RCX6DAC.tmp
- C:\RCX66D6.tmp
- <Current directory>\nUEg.exe
- C:\RCX6271.tmp
- <Current directory>\lmAk.ico
- <Current directory>\EYgM.exe
- C:\RCX61E3.tmp
- <Current directory>\Isgw.ico
- <Current directory>\lYYU.ico
- <Current directory>\EYcU.exe
- %TEMP%\vgQAMQQU.bat
- <Current directory>\gUcm.exe
- C:\RCX64F1.tmp
- %TEMP%\BSEsYYIo.bat
- <Current directory>\hgkY.ico
- <Current directory>\sUEq.exe
- <Current directory>\oAIs.ico
- <Current directory>\esYO.exe
- %TEMP%\DMIIQoMg.bat
- <Current directory>\AQUU.ico
- <Current directory>\EKYs.ico
- <Current directory>\sUEy.exe
- <Current directory>\POMI.ico
- <Current directory>\uYAO.exe
- <Current directory>\Igwg.ico
- <Current directory>\UYMs.exe
- <Current directory>\BiIk.ico
- <Current directory>\Hwga.exe
- <Current directory>\XAYY.ico
- <Current directory>\VEgM.exe
- <Current directory>\FogI.exe
- <Current directory>\LUga.exe
- <Current directory>\RUgo.ico
- <Current directory>\PgwM.exe
- <Current directory>\UgcQ.ico
- <Current directory>\dQYw.exe
- <Current directory>\HcwQ.ico
- <Current directory>\OMci.exe
- <Current directory>\csYs.ico
- %TEMP%\aCgcEEQs.bat
- <Current directory>\zaQk.ico
- <Current directory>\uQAM.ico
- <Current directory>\KQkG.exe
- <Current directory>\HIkq.exe
- <Current directory>\iUgc.ico
- <Current directory>\pYAI.exe
- <Current directory>\fKAU.ico
- <Current directory>\JWsE.ico
- <Current directory>\sUkO.exe
- <Current directory>\mmQY.ico
- <Current directory>\PEEk.exe
- <Current directory>\LYgY.ico
- <Current directory>\HokU.exe
- <Current directory>\GMgY.ico
- <Current directory>\wYUU.exe
- <Current directory>\cQMA.ico
- <Current directory>\TkEY.exe
- <Current directory>\BYEI.exe
- %TEMP%\IiQoccUg.bat
- <Current directory>\OOso.ico
- <Current directory>\ssgA.exe
- <Current directory>\CcMU.ico
- <Current directory>\wYUI.exe
- <Current directory>\ZAcY.ico
- <Current directory>\NwcM.exe
- %TEMP%\YscMcEcI.bat
- <Current directory>\XwcG.exe
- <Current directory>\pago.ico
- <Current directory>\cEIs.ico
- <Current directory>\KsEm.exe
- <Current directory>\gMQc.ico
- <Current directory>\NUcu.exe
- <Current directory>\tEgm.exe
- <Current directory>\oaQA.ico
- <Current directory>\JgMW.exe
- <Current directory>\zqgM.ico
- <Current directory>\BQIk.exe
- <Current directory>\Jyog.ico
- <Current directory>\bEoe.exe
- <Current directory>\iEcc.ico
- <Current directory>\ecYe.exe
- <Current directory>\yWMo.ico
- <Current directory>\bwUc.exe
- <Current directory>\nOQU.ico
- <Current directory>\AMQQ.exe
- <Current directory>\Pywk.ico
- <Current directory>\uYsK.exe
- <Current directory>\DMoY.ico
- <Current directory>\XscI.ico
- <Current directory>\cQQu.exe
- <Current directory>\MOwA.ico
- <Current directory>\eAMS.exe
- %TEMP%\ouEcQgkU.bat
- <Current directory>\EyAU.ico
- <Current directory>\AyYI.ico
- <Current directory>\OUoA.exe
- <Current directory>\BcIc.exe
- <Current directory>\mqEg.ico
- <Current directory>\mUsQ.exe
- <Current directory>\cWYM.ico
- <Current directory>\FkIq.exe
- <Current directory>\LuEc.ico
- <Current directory>\qYUe.exe
- <Current directory>\eIYU.ico
- <Current directory>\jMsu.exe
- <Current directory>\REwM.ico
- <Current directory>\doYY.exe
- <Current directory>\gmYc.ico
- <Current directory>\kgcw.exe
- <Current directory>\GmEc.ico
- <Current directory>\HQIu.exe
- <Current directory>\duMI.ico
- <Current directory>\QQYk.exe
- <Current directory>\YkUs.ico
- <Current directory>\kIwM.exe
- <Current directory>\fUIS.exe
- %TEMP%\KEQEwoUY.bat
- %TEMP%\HoEoMMwY.bat
- <Current directory>\Fcgw.ico
- <Current directory>\yssg.ico
- <Current directory>\BsAW.exe
- <Current directory>\tMoE.exe
- <Current directory>\qoso.ico
- <Current directory>\YUgy.exe
- <Current directory>\Hkcs.ico
- <Current directory>\vUki.exe
- <Current directory>\SEsY.ico
- <Current directory>\REow.exe
- <Current directory>\wOsI.ico
- <Current directory>\Eckg.exe
- <Current directory>\KKoo.ico
- <Current directory>\Wwkw.exe
- <Current directory>\peIo.ico
- <Current directory>\aQcO.exe
- <Current directory>\hSkw.ico
- <Current directory>\ZIUc.exe
- <Current directory>\eoog.ico
- <Current directory>\ZAUi.exe
- <Current directory>\AakU.ico
- <Current directory>\wEkk.exe
- <Current directory>\wyYM.ico
- <Current directory>\sIgA.exe
- <Current directory>\HkwA.ico
- <Current directory>\xwMA.exe
- <Current directory>\lkgg.ico
- <Current directory>\RQEO.exe
- <Current directory>\EccA.ico
- <Current directory>\xIIq.exe
- <Current directory>\KgAc.ico
- <Current directory>\nEQw.exe
- <Current directory>\kyok.ico
- <Current directory>\KAoy.exe
- <Current directory>\emsA.ico
- <Current directory>\PgEG.exe
- <Current directory>\tEAA.exe
- %TEMP%\wIMgAgQs.bat
- <Current directory>\CMgk.exe
- <Current directory>\GoUA.ico
- <Current directory>\nIws.ico
- <Current directory>\JMka.exe
- <Current directory>\Sioo.ico
- <Current directory>\GkEu.exe
- <Current directory>\Fugs.ico
- <Current directory>\vYMO.exe
- <Current directory>\cisc.ico
- <Current directory>\oUgQ.exe
- <Current directory>\HGUs.ico
- <Current directory>\BcgQ.ico
- <Current directory>\OcMq.exe
- <Current directory>\nsMy.exe
- %TEMP%\JycIgAsE.bat
- <Current directory>\mkky.exe
- <Current directory>\nUME.ico
- <Current directory>\wwIi.exe
- <Current directory>\QkUM.ico
- <Current directory>\JUso.exe
- <Current directory>\Aokc.ico
- <Current directory>\gogY.exe
- <Current directory>\MSws.ico
- <Current directory>\EAkq.exe
- <Current directory>\vmAU.ico
- <Current directory>\rIMw.exe
- <Current directory>\XGEo.ico
- <Current directory>\Yakk.ico
- <Current directory>\dUIc.exe
- <Current directory>\hEUS.exe
- %TEMP%\ekEgQogk.bat
- <Current directory>\fgUi.exe
- <Current directory>\lmgs.ico
- %TEMP%\dMEcIAIw.bat
- <Current directory>\DoAQ.ico
- <Current directory>\AYEG.exe
- <Current directory>\nMcY.ico
- <Current directory>\gEAy.exe
- <Current directory>\gQQw.ico
- <Current directory>\kIME.ico
- <Current directory>\AAco.exe
- <Current directory>\CQEM.ico
- <Current directory>\pIwg.exe
- <Current directory>\pQQo.ico
- <Current directory>\HkQS.exe
- <Current directory>\WUwg.ico
- <Current directory>\nIAG.exe
- <Current directory>\rksM.ico
- <Current directory>\OUUK.exe
- <Current directory>\rYwY.ico
- <Current directory>\BQsM.exe
- <Current directory>\EWgI.ico
- <Current directory>\yUsg.exe
- <Current directory>\xIoM.ico
- <Current directory>\mwQU.exe
- <Current directory>\fsws.ico
- <Current directory>\GcwM.exe
- <Current directory>\wIkU.ico
- <Current directory>\XkQO.exe
- <Current directory>\KmYw.ico
- <Current directory>\osQY.exe
- <Current directory>\VSsw.ico
- <Current directory>\TUEe.exe
- <Current directory>\NacA.ico
- <Current directory>\FyYc.ico
- <Current directory>\zYcw.exe
- <Current directory>\KcQI.ico
- <Current directory>\EAcm.exe
- %TEMP%\mecccoYw.bat
- <Current directory>\OuoI.ico
- <Current directory>\yEYw.ico
- <Current directory>\rEcY.exe
- <Current directory>\LsQy.exe
- <Current directory>\QeUw.ico
- <Current directory>\MgsI.exe
- <Current directory>\CgME.ico
- <Current directory>\HQwi.exe
- %TEMP%\VgcooUYk.bat
- <Current directory>\bUgU.ico
- <Current directory>\fwos.ico
- <Current directory>\ZQYy.exe
- <Current directory>\zkUA.ico
- <Current directory>\pIUo.exe
- <Current directory>\scIE.ico
- <Current directory>\FIsO.exe
- <Current directory>\IGcY.ico
- <Current directory>\oYsy.exe
- <Current directory>\sCYY.ico
- <Current directory>\OAIO.exe
- <Current directory>\Esgo.ico
- <Current directory>\AgkW.exe
- <Current directory>\JMoA.ico
- <Current directory>\BcEM.exe
- <Current directory>\Isgw.ico
- <Current directory>\nUEg.exe
- <Current directory>\NIck.ico
- <Current directory>\EYgM.exe
- <Current directory>\DiUk.ico
- <Current directory>\xcoC.exe
- <Current directory>\UMMs.ico
- <Current directory>\OksO.exe
- <Current directory>\guss.ico
- <Current directory>\pUMS.exe
- <Current directory>\YUAA.ico
- <Current directory>\VoUC.exe
- <Current directory>\lmAk.ico
- <Current directory>\WWwM.ico
- <Current directory>\oEMu.exe
- <Current directory>\LkUQ.ico
- <Current directory>\tQcS.exe
- <Current directory>\XEYA.ico
- <Current directory>\rAUi.exe
- <Current directory>\HAss.ico
- <Current directory>\toMc.exe
- <Current directory>\lYYU.ico
- <Current directory>\EYcU.exe
- <Current directory>\gUcm.exe
- %TEMP%\BSEsYYIo.bat
- <Current directory>\ckMs.ico
- <Current directory>\WcsU.exe
- <Current directory>\DyUw.ico
- <Current directory>\YcUI.exe
- from C:\RCXB964.tmp to <Current directory>\sUEq.exe
- from C:\RCXBB1A.tmp to <Current directory>\sUEy.exe
- from C:\RCXC42F.tmp to <Current directory>\FogI.exe
- from C:\RCXB7ED.tmp to <Current directory>\esYO.exe
- from C:\RCXB23F.tmp to <Current directory>\uYAO.exe
- from C:\RCXB368.tmp to <Current directory>\VEgM.exe
- from C:\RCXB54D.tmp to <Current directory>\Hwga.exe
- from C:\RCXC5C6.tmp to <Current directory>\KQkG.exe
- from C:\RCXCF9B.tmp to <Current directory>\OMci.exe
- from C:\RCXD46C.tmp to <Current directory>\dQYw.exe
- from C:\RCXD622.tmp to <Current directory>\YUgy.exe
- from C:\RCXCD97.tmp to <Current directory>\LUga.exe
- from C:\RCXC76C.tmp to <Current directory>\pYAI.exe
- from C:\RCXCA0C.tmp to <Current directory>\HIkq.exe
- from C:\RCXCC00.tmp to <Current directory>\PgwM.exe
- from C:\RCXAF9F.tmp to <Current directory>\UYMs.exe
- from C:\RCX99A4.tmp to <Current directory>\sUkO.exe
- from C:\RCX9C34.tmp to <Current directory>\wYUU.exe
- from C:\RCX9DCB.tmp to <Current directory>\HokU.exe
- from C:\RCX97CF.tmp to <Current directory>\PEEk.exe
- from C:\RCX92FC.tmp to <Current directory>\TkEY.exe
- from C:\RCX94A2.tmp to <Current directory>\wYUI.exe
- from C:\RCX95FA.tmp to <Current directory>\ssgA.exe
- from C:\RCX9F62.tmp to <Current directory>\JgMW.exe
- from C:\RCXA762.tmp to <Current directory>\NwcM.exe
- from C:\RCXA8E9.tmp to <Current directory>\NUcu.exe
- from C:\RCXAC83.tmp to <Current directory>\KsEm.exe
- from C:\RCXA501.tmp to <Current directory>\XwcG.exe
- from C:\RCXA08B.tmp to <Current directory>\tEgm.exe
- from C:\RCXA195.tmp to <Current directory>\bEoe.exe
- from C:\RCXA37A.tmp to <Current directory>\BQIk.exe
- from C:\RCXFD46.tmp to <Current directory>\uYsK.exe
- from C:\RCXFEDD.tmp to <Current directory>\AMQQ.exe
- from C:\RCXFFE7.tmp to <Current directory>\BcIc.exe
- from C:\RCXFBEE.tmp to <Current directory>\ecYe.exe
- from C:\RCXF5B4.tmp to <Current directory>\cQQu.exe
- from C:\RCXF69F.tmp to <Current directory>\OUoA.exe
- from C:\RCXF900.tmp to <Current directory>\bwUc.exe
- from C:\RCX249.tmp to <Current directory>\kgcw.exe
- from C:\RCXB72.tmp to <Current directory>\mUsQ.exe
- from C:\RCXC1E.tmp to <Current directory>\jMsu.exe
- from C:\RCXDB5.tmp to <Current directory>\qYUe.exe
- from C:\RCX9DB.tmp to <Current directory>\FkIq.exe
- from C:\RCX546.tmp to <Current directory>\doYY.exe
- from C:\RCX67F.tmp to <Current directory>\QQYk.exe
- from C:\RCX8B2.tmp to <Current directory>\HQIu.exe
- from C:\RCXF43D.tmp to <Current directory>\eAMS.exe
- from C:\RCXDEED.tmp to <Current directory>\kIwM.exe
- from C:\RCXE0A3.tmp to <Current directory>\BsAW.exe
- from C:\RCXE1FB.tmp to <Current directory>\Eckg.exe
- from C:\RCXDC8C.tmp to <Current directory>\fUIS.exe
- from C:\RCXD826.tmp to <Current directory>\tMoE.exe
- from C:\RCXDA87.tmp to <Current directory>\REow.exe
- from C:\RCXDBB0.tmp to <Current directory>\vUki.exe
- from C:\RCXE778.tmp to <Current directory>\sIgA.exe
- from C:\RCXEEEC.tmp to <Current directory>\Wwkw.exe
- from C:\RCXF045.tmp to <Current directory>\ZAUi.exe
- from C:\RCXF14F.tmp to <Current directory>\ZIUc.exe
- from C:\RCXEE40.tmp to <Current directory>\aQcO.exe
- from C:\RCXE90F.tmp to <Current directory>\wEkk.exe
- from C:\RCXEB51.tmp to <Current directory>\RQEO.exe
- from C:\RCXED84.tmp to <Current directory>\xwMA.exe
- from C:\RCX901D.tmp to <Current directory>\BYEI.exe
- from C:\RCX4280.tmp to <Current directory>\xIIq.exe
- from C:\RCX459C.tmp to <Current directory>\PgEG.exe
- from C:\RCX48D8.tmp to <Current directory>\KAoy.exe
- from C:\RCX40BA.tmp to <Current directory>\nEQw.exe
- from C:\RCX3B4B.tmp to <Current directory>\tEAA.exe
- from C:\RCX3D10.tmp to <Current directory>\GkEu.exe
- from C:\RCX3F05.tmp to <Current directory>\JMka.exe
- from C:\RCX4A9E.tmp to <Current directory>\wwIi.exe
- from C:\RCX5166.tmp to <Current directory>\vYMO.exe
- from C:\RCX5203.tmp to <Current directory>\nsMy.exe
- from C:\RCX533C.tmp to <Current directory>\OcMq.exe
- from C:\RCX504C.tmp to <Current directory>\oUgQ.exe
- from C:\RCX4B4A.tmp to <Current directory>\mkky.exe
- from C:\RCX4BD8.tmp to <Current directory>\gogY.exe
- from C:\RCX4D5F.tmp to <Current directory>\JUso.exe
- from C:\RCX38F9.tmp to <Current directory>\CMgk.exe
- from C:\RCX2474.tmp to <Current directory>\EAkq.exe
- from C:\RCX25DC.tmp to <Current directory>\hEUS.exe
- from C:\RCX2937.tmp to <Current directory>\dUIc.exe
- from C:\RCX21F4.tmp to <Current directory>\rIMw.exe
- from C:\RCX1BC9.tmp to <Current directory>\fgUi.exe
- from C:\RCX1D41.tmp to <Current directory>\gEAy.exe
- from C:\RCX200F.tmp to <Current directory>\AYEG.exe
- from C:\RCX2AAF.tmp to <Current directory>\BQsM.exe
- from C:\RCX33A9.tmp to <Current directory>\AAco.exe
- from C:\RCX34A4.tmp to <Current directory>\nIAG.exe
- from C:\RCX36D6.tmp to <Current directory>\HkQS.exe
- from C:\RCX3260.tmp to <Current directory>\pIwg.exe
- from C:\RCX2D4F.tmp to <Current directory>\OUUK.exe
- from C:\RCX2E97.tmp to <Current directory>\mwQU.exe
- from C:\RCX3166.tmp to <Current directory>\yUsg.exe
- from C:\RCX7C25.tmp to <Current directory>\GcwM.exe
- from C:\RCX7DEB.tmp to <Current directory>\TUEe.exe
- from C:\RCX7F52.tmp to <Current directory>\osQY.exe
- from C:\RCX7A6F.tmp to <Current directory>\XkQO.exe
- from C:\RCX73B8.tmp to <Current directory>\EAcm.exe
- from C:\RCX76D5.tmp to <Current directory>\zYcw.exe
- from C:\RCX786C.tmp to <Current directory>\rEcY.exe
- from C:\RCX8108.tmp to <Current directory>\LsQy.exe
- from C:\RCX8957.tmp to <Current directory>\HQwi.exe
- from C:\RCX8AFD.tmp to <Current directory>\MgsI.exe
- from C:\RCX8D30.tmp to <Current directory>\ZQYy.exe
- from C:\RCX86E6.tmp to <Current directory>\oYsy.exe
- from C:\RCX8232.tmp to <Current directory>\FIsO.exe
- from C:\RCX83A9.tmp to <Current directory>\pIUo.exe
- from C:\RCX84F2.tmp to <Current directory>\OAIO.exe
- from C:\RCX71A5.tmp to <Current directory>\rAUi.exe
- from C:\RCX5ED5.tmp to <Current directory>\BcEM.exe
- from C:\RCX60C9.tmp to <Current directory>\AgkW.exe
- from C:\RCX61E3.tmp to <Current directory>\EYgM.exe
- from C:\RCX5D00.tmp to <Current directory>\pUMS.exe
- from C:\RCX559E.tmp to <Current directory>\OksO.exe
- from C:\RCX588B.tmp to <Current directory>\xcoC.exe
- from C:\RCX5A32.tmp to <Current directory>\VoUC.exe
- from C:\RCX6271.tmp to <Current directory>\nUEg.exe
- from C:\RCX6DAC.tmp to <Current directory>\tQcS.exe
- from C:\RCX6EE5.tmp to <Current directory>\oEMu.exe
- from C:\RCX700E.tmp to <Current directory>\toMc.exe
- from C:\RCX69A5.tmp to <Current directory>\WcsU.exe
- from C:\RCX64F1.tmp to <Current directory>\gUcm.exe
- from C:\RCX66D6.tmp to <Current directory>\EYcU.exe
- from C:\RCX684D.tmp to <Current directory>\YcUI.exe
- DNS ASK dn#.##ftncsi.com
- DNS ASK google.com
- ClassName: '' WindowName: 'Microsoft Windows'
- ClassName: '' WindowName: 'GocwIYEU.exe'
- ClassName: '' WindowName: 'rSYkcwMw.exe'
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''