Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,C:\ProgramData\sIAowgok\rSYkcwMw.exe,'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rSYkcwMw.exe' = 'C:\ProgramData\sIAowgok\rSYkcwMw.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'GocwIYEU.exe' = '%HOMEPATH%\CaIocokM\GocwIYEU.exe'
- [<HKLM>\SYSTEM\ControlSet001\services\yoYkgMRX] 'Start' = '00000002'
- C:\ProgramData\Package Cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\vcredist_x86.exe
- hidden files
- file extensions
- User Account Control (UAC)
- 'C:\ProgramData\ZQIIosos\XiskIEYE.exe'
- 'C:\ProgramData\sIAowgok\rSYkcwMw.exe'
- '%HOMEPATH%\CaIocokM\GocwIYEU.exe'
- '<SYSTEM32>\reg.exe' /c ""%TEMP%\OoEsQAEg.bat" "<Full path to virus>""
- '<SYSTEM32>\conhost.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
- '<SYSTEM32>\conhost.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
- '<SYSTEM32>\conhost.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
- '<SYSTEM32>\reg.exe' 0x5bc <Virus name>.exe
- '<SYSTEM32>\cscript.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
- '<SYSTEM32>\cscript.exe' /c ""%TEMP%\kMQIcgQQ.bat" "<Full path to virus>""
- '<SYSTEM32>\reg.exe' 0xe84 cscript.exe
- '<SYSTEM32>\reg.exe'
- '<SYSTEM32>\reg.exe' /c ""%TEMP%\BEggocUA.bat" "<Full path to virus>""
- '<SYSTEM32>\cscript.exe' <LS_APPDATA>\Temp/file.vbs
- '<SYSTEM32>\taskhost.exe' <LS_APPDATA>\Temp/file.vbs
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
- '<SYSTEM32>\conhost.exe' /c ""%TEMP%\qcwgAEgs.bat" "<Full path to virus>""
- '<SYSTEM32>\conhost.exe'
- '<SYSTEM32>\conhost.exe' <LS_APPDATA>\Temp/file.vbs
- '<SYSTEM32>\reg.exe' /pid=0xa58 /log
- '<SYSTEM32>\conhost.exe' /c "<Current directory>\<Virus name>"
- <Current directory>\jwog.exe
- C:\RCXA8A3.tmp
- <Current directory>\Iwoc.ico
- <Current directory>\HkoG.exe
- C:\RCXA690.tmp
- <Current directory>\mKIE.ico
- <Current directory>\MwUG.exe
- C:\RCXAE40.tmp
- <Current directory>\gicE.ico
- <Current directory>\VkEY.exe
- C:\RCXAC0E.tmp
- <Current directory>\JaEY.ico
- <Current directory>\dYMU.exe
- <Current directory>\AwEI.exe
- C:\RCXA17E.tmp
- <Current directory>\gqQc.ico
- C:\RCX9FE7.tmp
- %TEMP%\MyIMYUok.bat
- <Current directory>\RukU.ico
- %TEMP%\BEggocUA.bat
- <Current directory>\nIEa.exe
- C:\RCXA586.tmp
- <Current directory>\qCkI.ico
- <Current directory>\NgUo.exe
- C:\RCXA3DF.tmp
- <Current directory>\ESAU.ico
- C:\RCXB6DE.tmp
- <Current directory>\SeoE.ico
- <Current directory>\NgUu.exe
- %TEMP%\LQcowQsE.bat
- <Current directory>\mmAI.ico
- <Current directory>\IkUU.exe
- C:\RCXB855.tmp
- C:\RCXBAF5.tmp
- <Current directory>\WwIA.ico
- <Current directory>\JkwE.exe
- %TEMP%\jmQkEkkI.bat
- <Current directory>\gisw.ico
- <Current directory>\hwwA.exe
- C:\RCXB100.tmp
- <Current directory>\fIcs.ico
- <Current directory>\kAcw.exe
- C:\RCXAFC7.tmp
- <Current directory>\RGIg.ico
- <Current directory>\vgYE.exe
- C:\RCXB1FB.tmp
- <Current directory>\ssss.ico
- <Current directory>\BEke.exe
- C:\RCXB4F9.tmp
- <Current directory>\tsMs.ico
- <Current directory>\LIsS.exe
- C:\RCXB324.tmp
- <Current directory>\vssQ.exe
- C:\RCX8960.tmp
- <Current directory>\MqME.ico
- <Current directory>\oEEG.exe
- C:\RCX87C9.tmp
- <Current directory>\iMgA.ico
- %TEMP%\zgEUYYIE.bat
- <Current directory>\zwgc.exe
- C:\RCX8D48.tmp
- %TEMP%\OoEsQAEg.bat
- <Current directory>\CwcM.exe
- C:\RCX8B54.tmp
- <Current directory>\OUEc.ico
- <Current directory>\rSUw.ico
- <Current directory>\VMsq.exe
- C:\RCX83B1.tmp
- <Current directory>\vaMU.ico
- <Current directory>\QAMY.exe
- C:\RCX82A7.tmp
- <Current directory>\jKYs.ico
- <Current directory>\jQAo.exe
- C:\RCX8652.tmp
- <Current directory>\CqUI.ico
- <Current directory>\qcUe.exe
- C:\RCX84DB.tmp
- <Current directory>\SgwU.ico
- <Current directory>\DwYI.exe
- C:\RCX996F.tmp
- <Current directory>\hogg.ico
- <Current directory>\nwEO.exe
- C:\RCX96DF.tmp
- <Current directory>\iEwY.ico
- <Current directory>\mMwM.exe
- C:\RCX9DF3.tmp
- <Current directory>\WuAM.ico
- <Current directory>\CgsU.exe
- C:\RCX9B25.tmp
- <Current directory>\iMkY.ico
- <Current directory>\qIsk.exe
- <Current directory>\vCoM.ico
- <Current directory>\BcAu.exe
- C:\RCX9066.tmp
- <Current directory>\jkEU.ico
- <Current directory>\hAYU.exe
- C:\RCX8F2D.tmp
- <Current directory>\BuwI.ico
- <Current directory>\dgQw.exe
- C:\RCX942F.tmp
- <Current directory>\UKUU.ico
- <Current directory>\fIoU.exe
- C:\RCX919F.tmp
- <Current directory>\SEkc.ico
- C:\RCXE151.tmp
- <Current directory>\WcQY.ico
- %TEMP%\uCIYgYUo.bat
- C:\RCXE028.tmp
- <Current directory>\xekM.ico
- <Current directory>\BEse.exe
- <Current directory>\REoE.exe
- C:\RCXE4DC.tmp
- %TEMP%\qQAUYIcw.bat
- <Current directory>\wCkg.ico
- C:\RCXE355.tmp
- <Current directory>\HoIY.ico
- <Current directory>\igAe.exe
- <Current directory>\tgMq.exe
- C:\RCXDB16.tmp
- <Current directory>\qGYw.ico
- <Current directory>\RwIw.exe
- C:\RCXD9BE.tmp
- <Current directory>\nyso.ico
- <Current directory>\ScwK.exe
- C:\RCXDE34.tmp
- <Current directory>\XkcU.ico
- <Current directory>\TsYO.exe
- C:\RCXDCEB.tmp
- <Current directory>\HIoE.ico
- <Current directory>\FMIk.exe
- C:\RCXEF0F.tmp
- <Current directory>\jmUI.ico
- <Current directory>\Pksm.exe
- C:\RCXEDD6.tmp
- <Current directory>\hCUA.ico
- <Current directory>\yAYS.exe
- C:\RCXEFDB.tmp
- <Current directory>\RmEM.ico
- <Current directory>\HoQM.exe
- C:\RCXF327.tmp
- <Current directory>\bccI.ico
- <Current directory>\fQYI.exe
- C:\RCXF1C0.tmp
- <Current directory>\wIYM.exe
- C:\RCXE8B5.tmp
- <Current directory>\sSco.ico
- <Current directory>\zUwW.exe
- C:\RCXE71E.tmp
- <Current directory>\iUwM.ico
- <Current directory>\YQEy.exe
- C:\RCXECDC.tmp
- <Current directory>\cGIA.ico
- <Current directory>\lQgM.exe
- C:\RCXEAD8.tmp
- <Current directory>\Tqsw.ico
- <Current directory>\AYEw.exe
- <Current directory>\hYoU.ico
- <Current directory>\hYQm.exe
- C:\RCXC558.tmp
- <Current directory>\kWkg.ico
- <Current directory>\gwUk.exe
- C:\RCXC400.tmp
- <Current directory>\BSsw.ico
- <Current directory>\JMEW.exe
- C:\RCXC9AE.tmp
- <Current directory>\dqUY.ico
- <Current directory>\jYEO.exe
- C:\RCXC73D.tmp
- <Current directory>\fqMw.ico
- C:\RCXBDF4.tmp
- <Current directory>\zyAI.ico
- <Current directory>\NgEK.exe
- C:\RCXBC3E.tmp
- <Current directory>\OkIA.ico
- <Current directory>\KwgQ.exe
- C:\RCXBF8A.tmp
- <Current directory>\UqIg.ico
- <Current directory>\qUoC.exe
- C:\RCXC353.tmp
- <Current directory>\PMIQ.ico
- <Current directory>\dwUc.exe
- C:\RCXC1FB.tmp
- <Current directory>\QQUk.ico
- <Current directory>\icgm.exe
- C:\RCXD603.tmp
- <Current directory>\CGcY.ico
- <Current directory>\lYki.exe
- C:\RCXD3E0.tmp
- <Current directory>\oYog.ico
- <Current directory>\DkUm.exe
- C:\RCXD901.tmp
- <Current directory>\hoAY.ico
- <Current directory>\nsIA.exe
- C:\RCXD74C.tmp
- <Current directory>\awAM.ico
- <Current directory>\SUEm.exe
- %TEMP%\WwYQsgYQ.bat
- C:\RCXCD29.tmp
- <Current directory>\kAUM.exe
- C:\RCXCBD1.tmp
- <Current directory>\gwAc.ico
- <Current directory>\Tmkc.ico
- %TEMP%\kMQIcgQQ.bat
- <Current directory>\TwcE.exe
- C:\RCXD19E.tmp
- <Current directory>\EQkI.exe
- C:\RCXCEDF.tmp
- <Current directory>\XOMk.ico
- C:\RCX80E2.tmp
- C:\RCX2F1D.tmp
- <Current directory>\XMME.ico
- <Current directory>\Wook.exe
- <Auxiliary element>
- <Current directory>\bAcY.ico
- <Current directory>\tcsg.exe
- C:\RCX3085.tmp
- <Current directory>\QsUE.ico
- <Current directory>\LMcq.exe
- C:\RCX34DA.tmp
- <Current directory>\LOAE.ico
- <Current directory>\sYIo.exe
- C:\RCX32C7.tmp
- C:\RCX2855.tmp
- <Current directory>\kecs.ico
- <Current directory>\wQIm.exe
- C:\RCX24FA.tmp
- <Current directory>\USoU.ico
- <Current directory>\vsQK.exe
- C:\RCX297F.tmp
- <Current directory>\xggs.ico
- <Current directory>\TQkU.exe
- C:\RCX2E90.tmp
- <Current directory>\uwYg.ico
- <Current directory>\EEYM.exe
- C:\RCX2B73.tmp
- C:\RCX3D67.tmp
- <Current directory>\QYoo.ico
- <Current directory>\wQgy.exe
- C:\RCX3C5D.tmp
- <Current directory>\sMUU.ico
- <Current directory>\TIQm.exe
- C:\RCX3EC0.tmp
- <Current directory>\rokU.ico
- <Current directory>\DIoG.exe
- C:\RCX4566.tmp
- <Current directory>\uScU.ico
- <Current directory>\cEUc.exe
- C:\RCX42B7.tmp
- <Current directory>\wygA.ico
- <Current directory>\NEUY.exe
- %TEMP%\teocIQwI.bat
- <Current directory>\EgMw.ico
- <Current directory>\qAcE.exe
- C:\RCX36EE.tmp
- C:\RCX3875.tmp
- %TEMP%\BUYscQYs.bat
- <Current directory>\GAAQ.ico
- <Current directory>\NoYI.exe
- <Current directory>\QYIU.ico
- <Current directory>\fskY.exe
- C:\RCX3A3A.tmp
- <Current directory>\zcAs.exe
- C:\RCXEFF.tmp
- <Current directory>\qGQA.ico
- <Current directory>\EUsE.exe
- C:\RCXD2A.tmp
- <Current directory>\UqAI.ico
- <Current directory>\YkAW.exe
- C:\RCX13D2.tmp
- <Current directory>\poYM.ico
- <Current directory>\JckO.exe
- C:\RCX1151.tmp
- <Current directory>\dMow.ico
- <Current directory>\mYYO.exe
- C:\ProgramData\kaog.txt
- <SYSTEM32>\config\systemprofile\CaIocokM\GocwIYEU
- <Current directory>\kgwc.ico
- %HOMEPATH%\CaIocokM\GocwIYEU
- C:\ProgramData\sIAowgok\rSYkcwMw
- C:\ProgramData\ZQIIosos\XiskIEYE.exe
- %TEMP%\LewQcIUI.bat
- C:\RCXBA3.tmp
- <Current directory>\YuQU.ico
- %TEMP%\file.vbs
- <Current directory>\<Virus name>
- %TEMP%\pOIgIkQA.bat
- <Current directory>\WQcQ.exe
- <Current directory>\seog.ico
- <Current directory>\NIsq.exe
- C:\RCX2047.tmp
- <Current directory>\eyYQ.ico
- <Current directory>\bkwm.exe
- C:\RCX1EDF.tmp
- <Current directory>\DiUY.ico
- %TEMP%\pmIoIYAA.bat
- <Current directory>\kwYY.ico
- <Current directory>\YUwC.exe
- <Current directory>\yoAm.exe
- %TEMP%\nkYIMwAE.bat
- C:\RCX22A9.tmp
- C:\RCX18D3.tmp
- <Current directory>\wkYY.ico
- <Current directory>\bEAU.exe
- C:\RCX14FB.tmp
- <Current directory>\cSAA.ico
- <Current directory>\jkQc.exe
- C:\RCX19DD.tmp
- <Current directory>\xiEY.ico
- <Current directory>\TsUY.exe
- C:\RCX1C6E.tmp
- <Current directory>\qEgw.ico
- <Current directory>\AcUu.exe
- C:\RCX1B64.tmp
- <Current directory>\RsAq.exe
- C:\RCX6BC1.tmp
- <Current directory>\GuQk.ico
- <Current directory>\BEUK.exe
- C:\RCX6A4A.tmp
- <Current directory>\DiME.ico
- <Current directory>\yoYu.exe
- C:\RCX6DB6.tmp
- <Current directory>\XIgY.ico
- <Current directory>\TUoa.exe
- C:\RCX6CCB.tmp
- <Current directory>\SAYI.ico
- <Current directory>\PsAA.exe
- <Current directory>\IMUk.ico
- <Current directory>\FUgy.exe
- C:\RCX6595.tmp
- <Current directory>\XYgM.exe
- C:\RCX6392.tmp
- %TEMP%\qcwgAEgs.bat
- <Current directory>\beEE.ico
- <Current directory>\aEEO.exe
- C:\RCX69CC.tmp
- <Current directory>\nYEs.ico
- <Current directory>\IgQQ.exe
- C:\RCX6864.tmp
- <Current directory>\RwIs.ico
- <Current directory>\YAQU.exe
- C:\RCX7A98.tmp
- <Current directory>\NCAo.ico
- C:\RCX7662.tmp
- %TEMP%\vOowEcoM.bat
- <Current directory>\xSAE.ico
- <Current directory>\XQcK.exe
- C:\RCX7E51.tmp
- <Current directory>\UiMk.ico
- <Current directory>\YEom.exe
- C:\RCX7C7C.tmp
- <Current directory>\Nacw.ico
- <Current directory>\DMQi.exe
- C:\RCX71DD.tmp
- <Current directory>\VkwU.ico
- <Current directory>\BgIc.exe
- C:\RCX6FBA.tmp
- <Current directory>\IkwI.ico
- <Current directory>\wskW.exe
- C:\RCX73E1.tmp
- %TEMP%\LaMAsEwY.bat
- <Current directory>\uwEY.ico
- <Current directory>\RIEg.exe
- <Current directory>\PccQ.ico
- <Current directory>\NEgC.exe
- C:\RCX7549.tmp
- <Current directory>\zUgI.exe
- C:\RCX4E80.tmp
- %TEMP%\PoQsooEk.bat
- <Current directory>\WgYY.exe
- C:\RCX4D47.tmp
- <Current directory>\rikc.ico
- <Current directory>\NIwI.ico
- <Current directory>\Magw.ico
- <Current directory>\lAgk.exe
- C:\RCX520B.tmp
- <Current directory>\eIYg.exe
- C:\RCX4FB9.tmp
- %TEMP%\AUQswcUw.bat
- <Current directory>\hCEY.ico
- <Current directory>\WIUM.exe
- C:\RCX474C.tmp
- <Current directory>\lGsQ.ico
- <Current directory>\BAUm.exe
- C:\RCX4680.tmp
- <Current directory>\SiYw.ico
- <Current directory>\jUEc.exe
- C:\RCX4A79.tmp
- <Current directory>\uyAg.ico
- <Current directory>\gAMM.exe
- C:\RCX47D9.tmp
- <Current directory>\SqAY.ico
- <Current directory>\yIgq.exe
- C:\RCX5E12.tmp
- <Current directory>\wYUM.ico
- <Current directory>\lcYW.exe
- C:\RCX5B73.tmp
- <Current directory>\PIAQ.ico
- <Current directory>\iUcY.exe
- C:\RCX61CC.tmp
- <Current directory>\ISUU.ico
- %TEMP%\lKQIUcEo.bat
- C:\RCX5F99.tmp
- <Current directory>\BMos.ico
- <Current directory>\RwYG.exe
- <Current directory>\WicQ.ico
- <Current directory>\kYYM.exe
- C:\RCX54FA.tmp
- <Current directory>\QosQ.ico
- <Current directory>\GcAa.exe
- C:\RCX53FF.tmp
- <Current directory>\uIAY.ico
- <Current directory>\rgQi.exe
- C:\RCX59BD.tmp
- <Current directory>\Bggo.ico
- <Current directory>\cswQ.exe
- C:\RCX573C.tmp
- <Current directory>\QOwM.ico
- <Current directory>\Iwoc.ico
- <Current directory>\MwUG.exe
- <Current directory>\mKIE.ico
- <Current directory>\jwog.exe
- <Current directory>\gicE.ico
- <Current directory>\VkEY.exe
- <Current directory>\JaEY.ico
- <Current directory>\dYMU.exe
- <Current directory>\HkoG.exe
- <Current directory>\AwEI.exe
- <Current directory>\gqQc.ico
- %TEMP%\MyIMYUok.bat
- <Current directory>\RukU.ico
- <Current directory>\nIEa.exe
- <Current directory>\qCkI.ico
- <Current directory>\NgUo.exe
- <Current directory>\ESAU.ico
- <Current directory>\IkUU.exe
- <Current directory>\SeoE.ico
- %TEMP%\LQcowQsE.bat
- <Current directory>\mmAI.ico
- <Current directory>\hwwA.exe
- <Current directory>\WwIA.ico
- <Current directory>\NgUu.exe
- <Current directory>\gisw.ico
- <Current directory>\BEke.exe
- %TEMP%\BEggocUA.bat
- <Current directory>\fIcs.ico
- <Current directory>\RGIg.ico
- <Current directory>\vgYE.exe
- <Current directory>\LIsS.exe
- <Current directory>\ssss.ico
- <Current directory>\kAcw.exe
- <Current directory>\tsMs.ico
- <Current directory>\CwcM.exe
- %TEMP%\zgEUYYIE.bat
- <Current directory>\vssQ.exe
- <Current directory>\MqME.ico
- <Current directory>\jkEU.ico
- <Current directory>\hAYU.exe
- <Current directory>\OUEc.ico
- <Current directory>\zwgc.exe
- <Current directory>\iMgA.ico
- <Current directory>\qcUe.exe
- <Current directory>\SgwU.ico
- <Current directory>\VMsq.exe
- <Current directory>\jKYs.ico
- <Current directory>\oEEG.exe
- %TEMP%\vOowEcoM.bat
- <Current directory>\jQAo.exe
- <Current directory>\CqUI.ico
- <Current directory>\mMwM.exe
- <Current directory>\iMkY.ico
- <Current directory>\DwYI.exe
- <Current directory>\hogg.ico
- <Current directory>\CgsU.exe
- %TEMP%\OoEsQAEg.bat
- <Current directory>\qIsk.exe
- <Current directory>\WuAM.ico
- <Current directory>\iEwY.ico
- <Current directory>\BuwI.ico
- <Current directory>\fIoU.exe
- <Current directory>\vCoM.ico
- <Current directory>\BcAu.exe
- <Current directory>\UKUU.ico
- <Current directory>\nwEO.exe
- <Current directory>\SEkc.ico
- <Current directory>\dgQw.exe
- <Current directory>\xekM.ico
- <Current directory>\BEse.exe
- <Current directory>\XkcU.ico
- <Current directory>\TsYO.exe
- %TEMP%\uCIYgYUo.bat
- <Current directory>\HoIY.ico
- <Current directory>\WcQY.ico
- <Current directory>\REoE.exe
- <Current directory>\FMIk.exe
- <Current directory>\nyso.ico
- <Current directory>\tgMq.exe
- <Current directory>\hoAY.ico
- <Current directory>\RwIw.exe
- <Current directory>\ScwK.exe
- <Current directory>\HIoE.ico
- %TEMP%\kMQIcgQQ.bat
- <Current directory>\qGYw.ico
- <Current directory>\hCUA.ico
- <Current directory>\yAYS.exe
- <Current directory>\cGIA.ico
- <Current directory>\lQgM.exe
- <Current directory>\bccI.ico
- <Current directory>\fQYI.exe
- <Current directory>\jmUI.ico
- <Current directory>\Pksm.exe
- <Current directory>\AYEw.exe
- <Current directory>\zUwW.exe
- <Current directory>\iUwM.ico
- <Current directory>\igAe.exe
- <Current directory>\wCkg.ico
- <Current directory>\YQEy.exe
- <Current directory>\Tqsw.ico
- <Current directory>\wIYM.exe
- <Current directory>\sSco.ico
- <Current directory>\hYoU.ico
- <Current directory>\hYQm.exe
- <Current directory>\kWkg.ico
- <Current directory>\gwUk.exe
- <Current directory>\fqMw.ico
- <Current directory>\JMEW.exe
- <Current directory>\BSsw.ico
- <Current directory>\jYEO.exe
- <Current directory>\qUoC.exe
- <Current directory>\KwgQ.exe
- <Current directory>\zyAI.ico
- <Current directory>\JkwE.exe
- <Current directory>\OkIA.ico
- <Current directory>\dwUc.exe
- <Current directory>\UqIg.ico
- <Current directory>\NgEK.exe
- <Current directory>\PMIQ.ico
- <Current directory>\QQUk.ico
- <Current directory>\icgm.exe
- <Current directory>\CGcY.ico
- <Current directory>\lYki.exe
- <Current directory>\awAM.ico
- <Current directory>\DkUm.exe
- <Current directory>\oYog.ico
- <Current directory>\nsIA.exe
- <Current directory>\TwcE.exe
- <Current directory>\gwAc.ico
- <Current directory>\SUEm.exe
- <Current directory>\dqUY.ico
- <Current directory>\kAUM.exe
- <Current directory>\EQkI.exe
- <Current directory>\XOMk.ico
- %TEMP%\WwYQsgYQ.bat
- <Current directory>\Tmkc.ico
- <Current directory>\LMcq.exe
- <Current directory>\EgMw.ico
- <Current directory>\sYIo.exe
- <Current directory>\QsUE.ico
- <Current directory>\NEUY.exe
- %TEMP%\teocIQwI.bat
- <Current directory>\qAcE.exe
- <Current directory>\wygA.ico
- <Current directory>\LOAE.ico
- <Current directory>\xggs.ico
- <Current directory>\TQkU.exe
- <Current directory>\uwYg.ico
- <Current directory>\EEYM.exe
- <Current directory>\XMME.ico
- <Current directory>\Wook.exe
- <Current directory>\bAcY.ico
- <Current directory>\tcsg.exe
- <Current directory>\DIoG.exe
- <Current directory>\lGsQ.ico
- <Current directory>\cEUc.exe
- <Current directory>\rokU.ico
- <Current directory>\WIUM.exe
- <Current directory>\SiYw.ico
- <Current directory>\BAUm.exe
- <Current directory>\hCEY.ico
- <Current directory>\uScU.ico
- <Current directory>\GAAQ.ico
- <Current directory>\NoYI.exe
- <Current directory>\QYIU.ico
- <Current directory>\fskY.exe
- <Current directory>\QYoo.ico
- <Current directory>\wQgy.exe
- <Current directory>\sMUU.ico
- <Current directory>\TIQm.exe
- <Current directory>\poYM.ico
- <Current directory>\JckO.exe
- <Current directory>\dMow.ico
- <Current directory>\mYYO.exe
- <Current directory>\wkYY.ico
- <Current directory>\bEAU.exe
- <Current directory>\cSAA.ico
- <Current directory>\jkQc.exe
- <Current directory>\YkAW.exe
- <Current directory>\WQcQ.exe
- <Current directory>\YuQU.ico
- %TEMP%\LewQcIUI.bat
- <Current directory>\kgwc.ico
- <Current directory>\zcAs.exe
- <Current directory>\qGQA.ico
- <Current directory>\EUsE.exe
- <Current directory>\UqAI.ico
- <Current directory>\kwYY.ico
- <Current directory>\YUwC.exe
- <Current directory>\DiUY.ico
- <Current directory>\yoAm.exe
- <Current directory>\kecs.ico
- <Current directory>\wQIm.exe
- <Current directory>\USoU.ico
- <Current directory>\vsQK.exe
- %TEMP%\nkYIMwAE.bat
- <Current directory>\xiEY.ico
- <Current directory>\TsUY.exe
- <Current directory>\qEgw.ico
- <Current directory>\AcUu.exe
- <Current directory>\seog.ico
- <Current directory>\NIsq.exe
- <Current directory>\eyYQ.ico
- <Current directory>\bkwm.exe
- <Current directory>\XIgY.ico
- <Current directory>\TUoa.exe
- <Current directory>\SAYI.ico
- <Current directory>\PsAA.exe
- %TEMP%\qcwgAEgs.bat
- <Current directory>\VkwU.ico
- <Current directory>\IkwI.ico
- <Current directory>\wskW.exe
- <Current directory>\yoYu.exe
- <Current directory>\aEEO.exe
- <Current directory>\nYEs.ico
- <Current directory>\IgQQ.exe
- <Current directory>\RwIs.ico
- <Current directory>\RsAq.exe
- <Current directory>\GuQk.ico
- <Current directory>\BEUK.exe
- <Current directory>\DiME.ico
- <Current directory>\DMQi.exe
- <Current directory>\UiMk.ico
- <Current directory>\XQcK.exe
- <Current directory>\Nacw.ico
- <Current directory>\QAMY.exe
- <Current directory>\rSUw.ico
- <Current directory>\YEom.exe
- <Current directory>\vaMU.ico
- <Current directory>\NCAo.ico
- <Current directory>\NEgC.exe
- %TEMP%\LaMAsEwY.bat
- <Current directory>\BgIc.exe
- <Current directory>\PccQ.ico
- <Current directory>\xSAE.ico
- <Current directory>\YAQU.exe
- <Current directory>\uwEY.ico
- <Current directory>\RIEg.exe
- <Current directory>\lAgk.exe
- <Current directory>\QosQ.ico
- <Current directory>\eIYg.exe
- <Current directory>\Magw.ico
- <Current directory>\kYYM.exe
- <Current directory>\uIAY.ico
- <Current directory>\GcAa.exe
- <Current directory>\WicQ.ico
- <Current directory>\NIwI.ico
- <Current directory>\jUEc.exe
- <Current directory>\uyAg.ico
- <Current directory>\gAMM.exe
- <Current directory>\SqAY.ico
- <Current directory>\zUgI.exe
- %TEMP%\PoQsooEk.bat
- <Current directory>\WgYY.exe
- <Current directory>\rikc.ico
- %TEMP%\lKQIUcEo.bat
- <Current directory>\ISUU.ico
- <Current directory>\BMos.ico
- <Current directory>\RwYG.exe
- <Current directory>\FUgy.exe
- <Current directory>\beEE.ico
- <Current directory>\XYgM.exe
- <Current directory>\IMUk.ico
- <Current directory>\iUcY.exe
- <Current directory>\rgQi.exe
- <Current directory>\Bggo.ico
- <Current directory>\cswQ.exe
- <Current directory>\QOwM.ico
- <Current directory>\yIgq.exe
- <Current directory>\wYUM.ico
- <Current directory>\lcYW.exe
- <Current directory>\PIAQ.ico
- from C:\RCXAC0E.tmp to <Current directory>\MwUG.exe
- from C:\RCXA8A3.tmp to <Current directory>\jwog.exe
- from C:\RCXAFC7.tmp to <Current directory>\VkEY.exe
- from C:\RCXAE40.tmp to <Current directory>\dYMU.exe
- from C:\RCXA3DF.tmp to <Current directory>\NgUo.exe
- from C:\RCXA17E.tmp to <Current directory>\AwEI.exe
- from C:\RCXA690.tmp to <Current directory>\HkoG.exe
- from C:\RCXA586.tmp to <Current directory>\nIEa.exe
- from C:\RCXB855.tmp to <Current directory>\NgUu.exe
- from C:\RCXB6DE.tmp to <Current directory>\IkUU.exe
- from C:\RCXBC3E.tmp to <Current directory>\JkwE.exe
- from C:\RCXBAF5.tmp to <Current directory>\hwwA.exe
- from C:\RCXB1FB.tmp to <Current directory>\kAcw.exe
- from C:\RCXB100.tmp to <Current directory>\vgYE.exe
- from C:\RCXB4F9.tmp to <Current directory>\BEke.exe
- from C:\RCXB324.tmp to <Current directory>\LIsS.exe
- from C:\RCX8B54.tmp to <Current directory>\CwcM.exe
- from C:\RCX8960.tmp to <Current directory>\vssQ.exe
- from C:\RCX8F2D.tmp to <Current directory>\hAYU.exe
- from C:\RCX8D48.tmp to <Current directory>\zwgc.exe
- from C:\RCX84DB.tmp to <Current directory>\qcUe.exe
- from C:\RCX83B1.tmp to <Current directory>\VMsq.exe
- from C:\RCX87C9.tmp to <Current directory>\oEEG.exe
- from C:\RCX8652.tmp to <Current directory>\jQAo.exe
- from C:\RCX9B25.tmp to <Current directory>\mMwM.exe
- from C:\RCX996F.tmp to <Current directory>\DwYI.exe
- from C:\RCX9FE7.tmp to <Current directory>\CgsU.exe
- from C:\RCX9DF3.tmp to <Current directory>\qIsk.exe
- from C:\RCX919F.tmp to <Current directory>\fIoU.exe
- from C:\RCX9066.tmp to <Current directory>\BcAu.exe
- from C:\RCX96DF.tmp to <Current directory>\nwEO.exe
- from C:\RCX942F.tmp to <Current directory>\dgQw.exe
- from C:\RCXE151.tmp to <Current directory>\BEse.exe
- from C:\RCXE028.tmp to <Current directory>\TsYO.exe
- from C:\RCXE4DC.tmp to <Current directory>\igAe.exe
- from C:\RCXE355.tmp to <Current directory>\REoE.exe
- from C:\RCXDB16.tmp to <Current directory>\tgMq.exe
- from C:\RCXD9BE.tmp to <Current directory>\RwIw.exe
- from C:\RCXDE34.tmp to <Current directory>\FMIk.exe
- from C:\RCXDCEB.tmp to <Current directory>\ScwK.exe
- from C:\RCXEF0F.tmp to <Current directory>\yAYS.exe
- from C:\RCXEDD6.tmp to <Current directory>\lQgM.exe
- from C:\RCXF1C0.tmp to <Current directory>\fQYI.exe
- from C:\RCXEFDB.tmp to <Current directory>\Pksm.exe
- from C:\RCXE8B5.tmp to <Current directory>\wIYM.exe
- from C:\RCXE71E.tmp to <Current directory>\zUwW.exe
- from C:\RCXECDC.tmp to <Current directory>\AYEw.exe
- from C:\RCXEAD8.tmp to <Current directory>\YQEy.exe
- from C:\RCXC558.tmp to <Current directory>\hYQm.exe
- from C:\RCXC400.tmp to <Current directory>\gwUk.exe
- from C:\RCXC9AE.tmp to <Current directory>\JMEW.exe
- from C:\RCXC73D.tmp to <Current directory>\jYEO.exe
- from C:\RCXBF8A.tmp to <Current directory>\NgEK.exe
- from C:\RCXBDF4.tmp to <Current directory>\KwgQ.exe
- from C:\RCXC353.tmp to <Current directory>\qUoC.exe
- from C:\RCXC1FB.tmp to <Current directory>\dwUc.exe
- from C:\RCXD603.tmp to <Current directory>\icgm.exe
- from C:\RCXD3E0.tmp to <Current directory>\lYki.exe
- from C:\RCXD901.tmp to <Current directory>\DkUm.exe
- from C:\RCXD74C.tmp to <Current directory>\nsIA.exe
- from C:\RCXCD29.tmp to <Current directory>\SUEm.exe
- from C:\RCXCBD1.tmp to <Current directory>\kAUM.exe
- from C:\RCXD19E.tmp to <Current directory>\TwcE.exe
- from C:\RCXCEDF.tmp to <Current directory>\EQkI.exe
- from C:\RCX34DA.tmp to <Current directory>\LMcq.exe
- from C:\RCX32C7.tmp to <Current directory>\sYIo.exe
- from C:\RCX3875.tmp to <Current directory>\NEUY.exe
- from C:\RCX36EE.tmp to <Current directory>\qAcE.exe
- from C:\RCX2E90.tmp to <Current directory>\TQkU.exe
- from C:\RCX2B73.tmp to <Current directory>\EEYM.exe
- from C:\RCX3085.tmp to <Current directory>\Wook.exe
- from C:\RCX2F1D.tmp to <Current directory>\tcsg.exe
- from C:\RCX4566.tmp to <Current directory>\DIoG.exe
- from C:\RCX42B7.tmp to <Current directory>\cEUc.exe
- from C:\RCX474C.tmp to <Current directory>\WIUM.exe
- from C:\RCX4680.tmp to <Current directory>\BAUm.exe
- from C:\RCX3C5D.tmp to <Current directory>\NoYI.exe
- from C:\RCX3A3A.tmp to <Current directory>\fskY.exe
- from C:\RCX3EC0.tmp to <Current directory>\wQgy.exe
- from C:\RCX3D67.tmp to <Current directory>\TIQm.exe
- from C:\RCX14FB.tmp to <Current directory>\JckO.exe
- from C:\RCX13D2.tmp to <Current directory>\mYYO.exe
- from C:\RCX19DD.tmp to <Current directory>\bEAU.exe
- from C:\RCX18D3.tmp to <Current directory>\jkQc.exe
- from C:\RCXD2A.tmp to <Current directory>\EUsE.exe
- from C:\RCXBA3.tmp to <Current directory>\WQcQ.exe
- from C:\RCX1151.tmp to <Current directory>\YkAW.exe
- from C:\RCXEFF.tmp to <Current directory>\zcAs.exe
- from C:\RCX24FA.tmp to <Current directory>\YUwC.exe
- from C:\RCX22A9.tmp to <Current directory>\yoAm.exe
- from C:\RCX297F.tmp to <Current directory>\wQIm.exe
- from C:\RCX2855.tmp to <Current directory>\vsQK.exe
- from C:\RCX1C6E.tmp to <Current directory>\TsUY.exe
- from C:\RCX1B64.tmp to <Current directory>\AcUu.exe
- from C:\RCX2047.tmp to <Current directory>\NIsq.exe
- from C:\RCX1EDF.tmp to <Current directory>\bkwm.exe
- from C:\RCX6DB6.tmp to <Current directory>\PsAA.exe
- from C:\RCX6CCB.tmp to <Current directory>\yoYu.exe
- from C:\RCX71DD.tmp to <Current directory>\wskW.exe
- from C:\RCX6FBA.tmp to <Current directory>\TUoa.exe
- from C:\RCX69CC.tmp to <Current directory>\aEEO.exe
- from C:\RCX6864.tmp to <Current directory>\IgQQ.exe
- from C:\RCX6BC1.tmp to <Current directory>\RsAq.exe
- from C:\RCX6A4A.tmp to <Current directory>\BEUK.exe
- from C:\RCX7E51.tmp to <Current directory>\DMQi.exe
- from C:\RCX7C7C.tmp to <Current directory>\XQcK.exe
- from C:\RCX82A7.tmp to <Current directory>\QAMY.exe
- from C:\RCX80E2.tmp to <Current directory>\YEom.exe
- from C:\RCX7549.tmp to <Current directory>\NEgC.exe
- from C:\RCX73E1.tmp to <Current directory>\BgIc.exe
- from C:\RCX7A98.tmp to <Current directory>\YAQU.exe
- from C:\RCX7662.tmp to <Current directory>\RIEg.exe
- from C:\RCX520B.tmp to <Current directory>\lAgk.exe
- from C:\RCX4FB9.tmp to <Current directory>\eIYg.exe
- from C:\RCX54FA.tmp to <Current directory>\kYYM.exe
- from C:\RCX53FF.tmp to <Current directory>\GcAa.exe
- from C:\RCX4A79.tmp to <Current directory>\jUEc.exe
- from C:\RCX47D9.tmp to <Current directory>\gAMM.exe
- from C:\RCX4E80.tmp to <Current directory>\zUgI.exe
- from C:\RCX4D47.tmp to <Current directory>\WgYY.exe
- from C:\RCX61CC.tmp to <Current directory>\RwYG.exe
- from C:\RCX5F99.tmp to <Current directory>\iUcY.exe
- from C:\RCX6595.tmp to <Current directory>\FUgy.exe
- from C:\RCX6392.tmp to <Current directory>\XYgM.exe
- from C:\RCX59BD.tmp to <Current directory>\rgQi.exe
- from C:\RCX573C.tmp to <Current directory>\cswQ.exe
- from C:\RCX5E12.tmp to <Current directory>\yIgq.exe
- from C:\RCX5B73.tmp to <Current directory>\lcYW.exe
- DNS ASK dn#.##ftncsi.com
- DNS ASK google.com
- ClassName: '' WindowName: 'GocwIYEU.exe'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: 'Microsoft Windows'
- ClassName: 'Indicator' WindowName: ''
- ClassName: '' WindowName: 'rSYkcwMw.exe'