Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,C:\ProgramData\sIAowgok\rSYkcwMw.exe,'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rSYkcwMw.exe' = 'C:\ProgramData\sIAowgok\rSYkcwMw.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'GocwIYEU.exe' = '%HOMEPATH%\CaIocokM\GocwIYEU.exe'
- [<HKLM>\SYSTEM\ControlSet001\services\yoYkgMRX] 'Start' = '00000002'
- C:\ProgramData\Package Cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\vcredist_x86.exe
- hidden files
- file extensions
- User Account Control (UAC)
- 'C:\ProgramData\ZQIIosos\XiskIEYE.exe'
- 'C:\ProgramData\sIAowgok\rSYkcwMw.exe'
- '%HOMEPATH%\CaIocokM\GocwIYEU.exe'
- '<SYSTEM32>\reg.exe' /pid=0x828 /log
- '<SYSTEM32>\conhost.exe' /c "<Current directory>\<Virus name>"
- '<SYSTEM32>\conhost.exe' /c ""%TEMP%\zyUAgowI.bat" "<Full path to virus>""
- '<SYSTEM32>\conhost.exe' <LS_APPDATA>\Temp/file.vbs
- '<SYSTEM32>\reg.exe' 0x92c <Virus name>.exe
- '<SYSTEM32>\reg.exe' /pid=0x944 /log
- '<SYSTEM32>\conhost.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
- '<SYSTEM32>\conhost.exe' /c ""%TEMP%\zikQQgMM.bat" "<Full path to virus>""
- '<SYSTEM32>\conhost.exe' /c ""%TEMP%\UUMwUQoQ.bat" "<Full path to virus>""
- '<SYSTEM32>\cscript.exe' 0xb38 cscript.exe
- '<SYSTEM32>\cscript.exe' /c "<Current directory>\<Virus name>"
- '<SYSTEM32>\reg.exe' /pid=0x774 /log
- '<SYSTEM32>\cscript.exe' 0x238 <Virus name>.exe
- '<SYSTEM32>\reg.exe' 0x774 cscript.exe
- '<SYSTEM32>\reg.exe' /c ""%TEMP%\rosIoMks.bat" "<Full path to virus>""
- '<SYSTEM32>\conhost.exe'
- '<SYSTEM32>\conhost.exe' /c ""%TEMP%\ooUQgcEM.bat" "<Full path to virus>""
- '<SYSTEM32>\reg.exe'
- '<SYSTEM32>\cscript.exe' <LS_APPDATA>\Temp/file.vbs
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
- '<SYSTEM32>\reg.exe' /pid=0x140 /log
- '<SYSTEM32>\reg.exe' /pid=0x844 /log
- '<SYSTEM32>\reg.exe' /c "<Current directory>\<Virus name>"
- '<SYSTEM32>\conhost.exe' /c ""%TEMP%\BiAYcQAc.bat" "<Full path to virus>""
- '<SYSTEM32>\reg.exe' <LS_APPDATA>\Temp/file.vbs
- '<SYSTEM32>\taskhost.exe'
- '<SYSTEM32>\conhost.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
- C:\RCXBEDE.tmp
- <Current directory>\pkcw.ico
- <Current directory>\FgQk.exe
- C:\RCXBE22.tmp
- <Current directory>\rWUo.ico
- <Current directory>\zEMo.exe
- C:\RCXC279.tmp
- <Current directory>\Ccwo.ico
- <Current directory>\WEYW.exe
- C:\RCXC130.tmp
- <Current directory>\wusE.ico
- <Current directory>\GIMI.exe
- <Current directory>\JYAu.exe
- <Current directory>\sgEi.exe
- C:\RCXB6DF.tmp
- <Current directory>\GCUs.ico
- <Current directory>\MYMC.exe
- C:\RCXB5B5.tmp
- <Current directory>\HeYo.ico
- <Current directory>\zcks.exe
- C:\RCXBB34.tmp
- <Current directory>\uWUs.ico
- <Current directory>\CoIk.exe
- C:\RCXBA59.tmp
- <Current directory>\ruQo.ico
- <Current directory>\lMIc.exe
- C:\RCXD006.tmp
- <Current directory>\DeMo.ico
- <Current directory>\owYE.exe
- C:\RCXCDA4.tmp
- <Current directory>\cmsE.ico
- <Current directory>\EAIo.exe
- C:\RCXD314.tmp
- <Current directory>\bYIw.ico
- <Current directory>\QcEE.exe
- C:\RCXD1AC.tmp
- <Current directory>\GcoQ.ico
- <Current directory>\DYYA.ico
- C:\RCXC71C.tmp
- %TEMP%\QYAQwQco.bat
- <Current directory>\dOQk.ico
- C:\RCXC5B4.tmp
- <Current directory>\RkUM.ico
- <Current directory>\zUgs.exe
- <Current directory>\XEAo.ico
- <Current directory>\JQIW.exe
- C:\RCXCBEF.tmp
- <Current directory>\xMcc.exe
- C:\RCXCA0A.tmp
- %TEMP%\zyUAgowI.bat
- C:\RCX9F2E.tmp
- <Current directory>\DsME.ico
- <Current directory>\vcQw.exe
- C:\RCX9D78.tmp
- <Current directory>\zWYA.ico
- <Current directory>\rgsW.exe
- C:\RCXA27A.tmp
- <Current directory>\IooI.ico
- <Current directory>\hEQE.exe
- C:\RCXA112.tmp
- <Current directory>\aycw.ico
- <Current directory>\xgoQ.exe
- <Current directory>\asEE.exe
- C:\RCX94CE.tmp
- <Current directory>\MOYg.ico
- %TEMP%\jMkkcAcU.bat
- <Current directory>\kogQ.ico
- %TEMP%\JQIEwsgY.bat
- <Current directory>\EMwc.exe
- <Current directory>\OIwC.exe
- C:\RCX9AD8.tmp
- <Current directory>\Zckc.ico
- <Current directory>\rEcC.exe
- C:\RCX98A6.tmp
- <Current directory>\IUYg.ico
- C:\RCXAC50.tmp
- <Current directory>\rwwo.ico
- <Current directory>\DQIy.exe
- <Current directory>\yIoA.ico
- <Current directory>\bUkm.exe
- %TEMP%\MQoEscMo.bat
- <Current directory>\QcYG.exe
- C:\RCXB48C.tmp
- <Current directory>\FEoA.ico
- C:\RCXB0B4.tmp
- %TEMP%\aaEMMYYE.bat
- <Current directory>\riUw.ico
- C:\RCXAAE8.tmp
- C:\RCXA559.tmp
- <Current directory>\ogIc.ico
- <Current directory>\bMYY.exe
- C:\RCXA3E2.tmp
- <Current directory>\RSoY.ico
- <Current directory>\dcoa.exe
- C:\RCXAA0D.tmp
- <Current directory>\XAcw.ico
- <Current directory>\OcoM.exe
- C:\RCXA818.tmp
- <Current directory>\UIEA.ico
- <Current directory>\rssk.exe
- <Current directory>\yAEu.exe
- C:\RCXF808.tmp
- <Current directory>\ZCUU.ico
- <Current directory>\OUsY.exe
- C:\RCXF652.tmp
- <Current directory>\gqso.ico
- <Current directory>\AkIe.exe
- C:\RCXFBA2.tmp
- <Current directory>\BywI.ico
- <Current directory>\gYMs.exe
- C:\RCXF9DD.tmp
- <Current directory>\Xgoc.ico
- <Current directory>\JMcG.exe
- %TEMP%\UUMwUQoQ.bat
- <Current directory>\ZskI.ico
- <Current directory>\dEge.exe
- C:\RCXF24A.tmp
- <Current directory>\ZMAA.ico
- <Current directory>\asoG.exe
- C:\RCXF15F.tmp
- C:\RCXF42F.tmp
- <Current directory>\IIAM.ico
- <Current directory>\uoYS.exe
- <Current directory>\iIMU.ico
- <Current directory>\VUUs.exe
- %TEMP%\BWoQMMAI.bat
- <Current directory>\augc.ico
- <Current directory>\NEwQ.exe
- C:\RCX808.tmp
- <Current directory>\HykM.ico
- <Current directory>\ZoQG.exe
- C:\RCX6DF.tmp
- C:\RCX9DD.tmp
- <Current directory>\WYQI.ico
- <Current directory>\xMYc.exe
- <Current directory>\KacM.ico
- <Current directory>\cwkA.exe
- %TEMP%\wCAockAo.bat
- C:\RCX596.tmp
- C:\RCX101.tmp
- <Current directory>\yYgs.ico
- <Current directory>\NYMq.exe
- C:\RCXFD68.tmp
- <Current directory>\vWUA.ico
- <Current directory>\HEwU.exe
- C:\RCX3B1.tmp
- <Current directory>\FScw.ico
- <Current directory>\Vgkg.exe
- C:\RCX298.tmp
- <Current directory>\zuIE.ico
- <Current directory>\dUgC.exe
- <Current directory>\EQQM.ico
- %TEMP%\PYcwQoUQ.bat
- <Current directory>\VMMY.exe
- <Current directory>\tAoY.ico
- <Current directory>\IYUG.exe
- C:\RCXDBF0.tmp
- <Current directory>\VIAs.exe
- C:\RCXE19D.tmp
- <Current directory>\JKEU.ico
- C:\RCXDE42.tmp
- <Current directory>\wIYU.ico
- %TEMP%\zikQQgMM.bat
- C:\RCXDA78.tmp
- C:\RCXD651.tmp
- <Current directory>\Xcks.ico
- <Current directory>\wgwK.exe
- C:\RCXD42E.tmp
- <Current directory>\MuUc.ico
- <Current directory>\Swoa.exe
- C:\RCXD97E.tmp
- <Current directory>\tKYc.ico
- <Current directory>\SogE.exe
- C:\RCXD8D1.tmp
- <Current directory>\VyYU.ico
- <Current directory>\Gwwu.exe
- <Current directory>\AYgU.ico
- <Current directory>\dcsc.exe
- C:\RCXEE31.tmp
- <Current directory>\aSUA.ico
- <Current directory>\Vgwm.exe
- C:\RCXECBA.tmp
- <Current directory>\VUMc.ico
- <Current directory>\JcAM.exe
- C:\RCXEFD8.tmp
- <Current directory>\eCsg.ico
- <Current directory>\bUgI.exe
- C:\RCXEF3B.tmp
- C:\RCXEB42.tmp
- <Current directory>\vMQU.exe
- C:\RCXE65F.tmp
- <Current directory>\aaUs.ico
- <Current directory>\oUQE.exe
- C:\RCXE41D.tmp
- <Current directory>\YckI.ico
- <Current directory>\tkci.exe
- C:\RCXE9EA.tmp
- <Current directory>\iMgI.ico
- <Current directory>\GMUM.exe
- C:\RCXE7A8.tmp
- <Current directory>\ECIM.ico
- C:\RCX93B4.tmp
- %TEMP%\gMIQsosM.bat
- <Current directory>\EYoM.exe
- C:\RCX32B5.tmp
- <Current directory>\vkUg.exe
- C:\RCX2F89.tmp
- <Current directory>\sMQA.ico
- <Current directory>\AscY.ico
- <Current directory>\QcAm.exe
- C:\RCX35B4.tmp
- <Current directory>\aUok.ico
- <Current directory>\qMwm.exe
- C:\RCX346B.tmp
- %TEMP%\dSUscEgc.bat
- <Current directory>\nsEy.exe
- C:\RCX272D.tmp
- <Current directory>\tksw.ico
- <Current directory>\MEES.exe
- C:\RCX2613.tmp
- <Current directory>\PIAU.ico
- <Current directory>\CIUi.exe
- C:\RCX2D47.tmp
- <Current directory>\kQkg.ico
- <Current directory>\gscY.exe
- C:\RCX2BD0.tmp
- <Current directory>\vQME.ico
- <Current directory>\ZQEQ.exe
- C:\RCX440C.tmp
- <Current directory>\dEEU.ico
- <Current directory>\GkMa.exe
- C:\RCX416C.tmp
- <Current directory>\fUQE.ico
- <Current directory>\icMo.exe
- C:\RCX471A.tmp
- <Current directory>\wQEU.ico
- <Current directory>\wgIQ.exe
- C:\RCX44E7.tmp
- <Current directory>\wKQU.ico
- <Current directory>\XeYY.ico
- <Current directory>\TKEI.ico
- <Current directory>\TYgm.exe
- C:\RCX3CD7.tmp
- <Current directory>\biAg.ico
- <Current directory>\VsYS.exe
- C:\RCX37E6.tmp
- <Current directory>\GgYk.ico
- <Current directory>\dkIi.exe
- C:\RCX3FF5.tmp
- <Current directory>\gOUw.ico
- <Current directory>\ogYe.exe
- C:\RCX3EBC.tmp
- <Current directory>\AAcO.exe
- C:\RCX1131.tmp
- <Current directory>\fkEg.ico
- <Current directory>\cEUG.exe
- C:\RCX1094.tmp
- <Current directory>\nYME.ico
- <Current directory>\jQQw.exe
- C:\RCX1355.tmp
- <Current directory>\AgsQ.ico
- <Current directory>\eQAm.exe
- C:\RCX11FD.tmp
- <Current directory>\CoUc.ico
- <Current directory>\aIEM.ico
- <SYSTEM32>\config\systemprofile\CaIocokM\GocwIYEU
- %TEMP%\ZeIoQIIk.bat
- <Current directory>\<Virus name>
- %HOMEPATH%\CaIocokM\GocwIYEU
- C:\ProgramData\sIAowgok\rSYkcwMw
- C:\ProgramData\ZQIIosos\XiskIEYE.exe
- <Current directory>\zIwk.ico
- <Current directory>\esUG.exe
- C:\RCXFB8.tmp
- C:\ProgramData\kaog.txt
- %TEMP%\lAoIQIko.bat
- %TEMP%\file.vbs
- <Current directory>\Gssu.exe
- C:\RCX1F0E.tmp
- <Current directory>\DOgk.ico
- <Current directory>\xUUw.ico
- C:\RCX1E42.tmp
- <Current directory>\siYQ.ico
- <Current directory>\eMcu.exe
- C:\RCX24BB.tmp
- <Current directory>\ISsA.ico
- <Current directory>\OIAA.exe
- C:\RCX219E.tmp
- <Current directory>\gOEY.ico
- C:\RCX1CEA.tmp
- <Current directory>\cEkw.ico
- <Current directory>\oMEy.exe
- C:\RCX18F2.tmp
- <Current directory>\IgQi.exe
- C:\RCX1587.tmp
- %TEMP%\IUgAwIIk.bat
- C:\RCX1AF6.tmp
- <Current directory>\kCoI.ico
- <Current directory>\qEsG.exe
- %TEMP%\UqAcEkEk.bat
- <Current directory>\yiUk.ico
- <Current directory>\Gwcq.exe
- %TEMP%\xCEkEAIU.bat
- <Current directory>\DEYc.exe
- C:\RCX7FAC.tmp
- <Current directory>\kGAI.ico
- <Current directory>\ZYoQ.exe
- C:\RCX7E54.tmp
- <Current directory>\OWog.ico
- <Current directory>\fIgu.exe
- C:\RCX82E9.tmp
- <Current directory>\NgwQ.ico
- <Current directory>\aEcc.exe
- C:\RCX8087.tmp
- <Current directory>\MyYM.ico
- <Current directory>\ywAQ.ico
- C:\RCX74EE.tmp
- <Current directory>\SQQw.ico
- <Current directory>\QgAe.exe
- C:\RCX72FA.tmp
- <Current directory>\eYgQ.ico
- <Current directory>\rAcq.exe
- <Current directory>\TAAm.exe
- C:\RCX79B1.tmp
- %TEMP%\rosIoMks.bat
- C:\RCX7750.tmp
- <Current directory>\TSIs.ico
- %TEMP%\egUQEEkQ.bat
- C:\RCX8CFD.tmp
- <Current directory>\DScY.ico
- <Current directory>\sgsK.exe
- C:\RCX8B18.tmp
- <Current directory>\lOIo.ico
- <Current directory>\Gsge.exe
- C:\RCX929A.tmp
- <Current directory>\eeII.ico
- <Current directory>\zMgm.exe
- C:\RCX9096.tmp
- <Current directory>\zKMQ.ico
- <Current directory>\PoIU.exe
- <Current directory>\kQEQ.exe
- <Current directory>\yQwI.exe
- C:\RCX86E1.tmp
- <Current directory>\OgwY.ico
- <Current directory>\xEco.exe
- C:\RCX84BE.tmp
- <Current directory>\SYMo.ico
- <Current directory>\rscq.exe
- C:\RCX8A0E.tmp
- <Current directory>\DaIQ.ico
- <Current directory>\sIEo.exe
- C:\RCX8877.tmp
- <Current directory>\gWUA.ico
- <Current directory>\UsIi.exe
- C:\RCX5775.tmp
- <Current directory>\KckI.ico
- <Current directory>\LEsS.exe
- C:\RCX562C.tmp
- <Current directory>\qcIU.ico
- <Current directory>\PMki.exe
- C:\RCX5C18.tmp
- <Current directory>\yyEw.ico
- <Current directory>\PQMg.exe
- C:\RCX5A43.tmp
- <Current directory>\nKkQ.ico
- <Current directory>\sOgo.ico
- <Current directory>\KmIo.ico
- <Current directory>\dcYW.exe
- C:\RCX4D63.tmp
- <Current directory>\FYYY.exe
- C:\RCX4B8E.tmp
- %TEMP%\ooUQgcEM.bat
- <Current directory>\tmcQ.ico
- <Current directory>\dcgA.exe
- C:\RCX530F.tmp
- <Current directory>\MUQM.ico
- <Current directory>\LscG.exe
- C:\RCX5198.tmp
- <Auxiliary element>
- <Current directory>\nAEc.ico
- <Current directory>\NgUs.exe
- <Current directory>\CcsI.ico
- <Current directory>\xskC.exe
- C:\RCX6947.tmp
- C:\RCX6FDE.tmp
- <Current directory>\rWgM.ico
- <Current directory>\JUEE.exe
- C:\RCX6C63.tmp
- <Current directory>\sQog.ico
- <Current directory>\eUAg.exe
- C:\RCX65FB.tmp
- <Current directory>\rQoM.exe
- C:\RCX5FC2.tmp
- <Current directory>\UOww.ico
- <Current directory>\eEsC.exe
- C:\RCX5DBE.tmp
- <Current directory>\pEYk.ico
- %TEMP%\BiAYcQAc.bat
- <Current directory>\mWAQ.ico
- <Current directory>\lUce.exe
- %TEMP%\yqQYcYwI.bat
- <Current directory>\Ggsq.exe
- C:\RCX636B.tmp
- <Current directory>\wusE.ico
- <Current directory>\GIMI.exe
- <Current directory>\pkcw.ico
- <Current directory>\FgQk.exe
- %TEMP%\aaEMMYYE.bat
- <Current directory>\RkUM.ico
- <Current directory>\Ccwo.ico
- <Current directory>\WEYW.exe
- <Current directory>\ruQo.ico
- <Current directory>\zcks.exe
- <Current directory>\GCUs.ico
- <Current directory>\CoIk.exe
- <Current directory>\rWUo.ico
- <Current directory>\zEMo.exe
- <Current directory>\uWUs.ico
- <Current directory>\JYAu.exe
- <Current directory>\zUgs.exe
- <Current directory>\QcEE.exe
- <Current directory>\GcoQ.ico
- <Current directory>\lMIc.exe
- <Current directory>\DeMo.ico
- <Current directory>\yAEu.exe
- <Current directory>\MuUc.ico
- <Current directory>\EAIo.exe
- <Current directory>\bYIw.ico
- <Current directory>\xMcc.exe
- <Current directory>\XEAo.ico
- %TEMP%\QYAQwQco.bat
- <Current directory>\dOQk.ico
- <Current directory>\owYE.exe
- <Current directory>\cmsE.ico
- <Current directory>\JQIW.exe
- <Current directory>\DYYA.ico
- <Current directory>\aycw.ico
- <Current directory>\xgoQ.exe
- <Current directory>\DsME.ico
- <Current directory>\vcQw.exe
- <Current directory>\RSoY.ico
- <Current directory>\dcoa.exe
- <Current directory>\IooI.ico
- <Current directory>\hEQE.exe
- <Current directory>\IUYg.ico
- <Current directory>\OIwC.exe
- <Current directory>\MOYg.ico
- <Current directory>\rEcC.exe
- <Current directory>\zWYA.ico
- <Current directory>\rgsW.exe
- <Current directory>\Zckc.ico
- <Current directory>\asEE.exe
- <Current directory>\ogIc.ico
- <Current directory>\riUw.ico
- <Current directory>\QcYG.exe
- <Current directory>\rwwo.ico
- <Current directory>\DQIy.exe
- <Current directory>\HeYo.ico
- <Current directory>\sgEi.exe
- <Current directory>\FEoA.ico
- <Current directory>\MYMC.exe
- <Current directory>\rssk.exe
- <Current directory>\XAcw.ico
- <Current directory>\bMYY.exe
- <Current directory>\UIEA.ico
- <Current directory>\bUkm.exe
- %TEMP%\MQoEscMo.bat
- <Current directory>\OcoM.exe
- <Current directory>\yIoA.ico
- <Current directory>\AkIe.exe
- <Current directory>\ZCUU.ico
- <Current directory>\uoYS.exe
- <Current directory>\gqso.ico
- <Current directory>\JMcG.exe
- <Current directory>\BywI.ico
- <Current directory>\OUsY.exe
- <Current directory>\Xgoc.ico
- <Current directory>\ZskI.ico
- <Current directory>\dEge.exe
- <Current directory>\ZMAA.ico
- <Current directory>\asoG.exe
- %TEMP%\BWoQMMAI.bat
- <Current directory>\IIAM.ico
- <Current directory>\iIMU.ico
- <Current directory>\VUUs.exe
- <Current directory>\gYMs.exe
- %TEMP%\UUMwUQoQ.bat
- <Current directory>\augc.ico
- <Current directory>\HykM.ico
- <Current directory>\ZoQG.exe
- <Current directory>\cwkA.exe
- %TEMP%\wCAockAo.bat
- <Current directory>\NEwQ.exe
- <Current directory>\KacM.ico
- <Current directory>\yYgs.ico
- <Current directory>\NYMq.exe
- <Current directory>\vWUA.ico
- <Current directory>\HEwU.exe
- <Current directory>\FScw.ico
- <Current directory>\Vgkg.exe
- <Current directory>\zuIE.ico
- <Current directory>\dUgC.exe
- %TEMP%\PYcwQoUQ.bat
- <Current directory>\EQQM.ico
- <Current directory>\tAoY.ico
- <Current directory>\IYUG.exe
- <Current directory>\VIAs.exe
- <Current directory>\JKEU.ico
- <Current directory>\VMMY.exe
- <Current directory>\wIYU.ico
- <Current directory>\wgwK.exe
- %TEMP%\zyUAgowI.bat
- <Current directory>\Swoa.exe
- <Current directory>\Xcks.ico
- <Current directory>\tKYc.ico
- <Current directory>\SogE.exe
- <Current directory>\VyYU.ico
- <Current directory>\Gwwu.exe
- <Current directory>\oUQE.exe
- <Current directory>\AYgU.ico
- <Current directory>\dcsc.exe
- <Current directory>\Vgwm.exe
- %TEMP%\zikQQgMM.bat
- <Current directory>\VUMc.ico
- <Current directory>\JcAM.exe
- <Current directory>\eCsg.ico
- <Current directory>\bUgI.exe
- <Current directory>\aaUs.ico
- <Current directory>\GMUM.exe
- <Current directory>\YckI.ico
- <Current directory>\vMQU.exe
- <Current directory>\iMgI.ico
- <Current directory>\aSUA.ico
- <Current directory>\ECIM.ico
- <Current directory>\tkci.exe
- <Current directory>\EMwc.exe
- <Current directory>\QcAm.exe
- <Current directory>\biAg.ico
- <Current directory>\qMwm.exe
- <Current directory>\AscY.ico
- <Current directory>\TYgm.exe
- <Current directory>\gOUw.ico
- <Current directory>\VsYS.exe
- <Current directory>\TKEI.ico
- %TEMP%\dSUscEgc.bat
- <Current directory>\kQkg.ico
- <Current directory>\vQME.ico
- <Current directory>\CIUi.exe
- <Current directory>\EYoM.exe
- <Current directory>\aUok.ico
- <Current directory>\vkUg.exe
- <Current directory>\sMQA.ico
- <Current directory>\ogYe.exe
- %TEMP%\xCEkEAIU.bat
- <Current directory>\wQEU.ico
- <Current directory>\wKQU.ico
- <Current directory>\icMo.exe
- <Current directory>\dcYW.exe
- <Current directory>\MUQM.ico
- <Current directory>\FYYY.exe
- <Current directory>\KmIo.ico
- <Current directory>\XeYY.ico
- <Current directory>\GkMa.exe
- <Current directory>\GgYk.ico
- <Current directory>\dkIi.exe
- <Current directory>\dEEU.ico
- <Current directory>\wgIQ.exe
- <Current directory>\fUQE.ico
- <Current directory>\ZQEQ.exe
- <Current directory>\jQQw.exe
- <Current directory>\AgsQ.ico
- <Current directory>\eQAm.exe
- <Current directory>\CoUc.ico
- <Current directory>\cEkw.ico
- <Current directory>\oMEy.exe
- <Current directory>\IgQi.exe
- %TEMP%\IUgAwIIk.bat
- <Current directory>\esUG.exe
- <Current directory>\aIEM.ico
- %TEMP%\ZeIoQIIk.bat
- <Current directory>\zIwk.ico
- <Current directory>\AAcO.exe
- <Current directory>\fkEg.ico
- <Current directory>\cEUG.exe
- <Current directory>\nYME.ico
- <Current directory>\yiUk.ico
- <Current directory>\ISsA.ico
- <Current directory>\MEES.exe
- <Current directory>\gOEY.ico
- <Current directory>\eMcu.exe
- <Current directory>\tksw.ico
- <Current directory>\gscY.exe
- <Current directory>\PIAU.ico
- <Current directory>\nsEy.exe
- <Current directory>\qEsG.exe
- <Current directory>\xUUw.ico
- <Current directory>\Gwcq.exe
- <Current directory>\kCoI.ico
- <Current directory>\DOgk.ico
- <Current directory>\OIAA.exe
- <Current directory>\siYQ.ico
- <Current directory>\Gssu.exe
- <Current directory>\MyYM.ico
- <Current directory>\fIgu.exe
- <Current directory>\kGAI.ico
- <Current directory>\aEcc.exe
- <Current directory>\SYMo.ico
- <Current directory>\yQwI.exe
- <Current directory>\NgwQ.ico
- <Current directory>\xEco.exe
- <Current directory>\TSIs.ico
- <Current directory>\TAAm.exe
- %TEMP%\BiAYcQAc.bat
- %TEMP%\egUQEEkQ.bat
- <Current directory>\OWog.ico
- <Current directory>\DEYc.exe
- <Current directory>\ywAQ.ico
- <Current directory>\ZYoQ.exe
- <Current directory>\OgwY.ico
- <Current directory>\zKMQ.ico
- <Current directory>\PoIU.exe
- <Current directory>\sgsK.exe
- %TEMP%\rosIoMks.bat
- %TEMP%\JQIEwsgY.bat
- <Current directory>\kogQ.ico
- <Current directory>\eeII.ico
- <Current directory>\zMgm.exe
- <Current directory>\rscq.exe
- <Current directory>\DaIQ.ico
- <Current directory>\sIEo.exe
- <Current directory>\gWUA.ico
- <Current directory>\Gsge.exe
- <Current directory>\DScY.ico
- <Current directory>\kQEQ.exe
- <Current directory>\lOIo.ico
- <Current directory>\PMki.exe
- <Current directory>\yyEw.ico
- <Current directory>\PQMg.exe
- <Current directory>\nKkQ.ico
- <Current directory>\pEYk.ico
- <Current directory>\rQoM.exe
- <Current directory>\eEsC.exe
- %TEMP%\ooUQgcEM.bat
- <Current directory>\dcgA.exe
- <Current directory>\sOgo.ico
- <Current directory>\LscG.exe
- <Current directory>\tmcQ.ico
- <Current directory>\UsIi.exe
- <Current directory>\KckI.ico
- <Current directory>\LEsS.exe
- <Current directory>\qcIU.ico
- %TEMP%\yqQYcYwI.bat
- <Current directory>\rWgM.ico
- <Current directory>\JUEE.exe
- <Current directory>\sQog.ico
- <Current directory>\eUAg.exe
- <Current directory>\SQQw.ico
- <Current directory>\QgAe.exe
- <Current directory>\eYgQ.ico
- <Current directory>\rAcq.exe
- <Current directory>\mWAQ.ico
- <Current directory>\lUce.exe
- <Current directory>\UOww.ico
- <Current directory>\Ggsq.exe
- <Current directory>\nAEc.ico
- <Current directory>\NgUs.exe
- <Current directory>\CcsI.ico
- <Current directory>\xskC.exe
- from C:\RCXC130.tmp to <Current directory>\FgQk.exe
- from C:\RCXC279.tmp to <Current directory>\GIMI.exe
- from C:\RCXC5B4.tmp to <Current directory>\WEYW.exe
- from C:\RCXBEDE.tmp to <Current directory>\zEMo.exe
- from C:\RCXBA59.tmp to <Current directory>\CoIk.exe
- from C:\RCXBB34.tmp to <Current directory>\zcks.exe
- from C:\RCXBE22.tmp to <Current directory>\JYAu.exe
- from C:\RCXC71C.tmp to <Current directory>\zUgs.exe
- from C:\RCXD1AC.tmp to <Current directory>\QcEE.exe
- from C:\RCXD314.tmp to <Current directory>\EAIo.exe
- from C:\RCXD42E.tmp to <Current directory>\yAEu.exe
- from C:\RCXD006.tmp to <Current directory>\lMIc.exe
- from C:\RCXCA0A.tmp to <Current directory>\xMcc.exe
- from C:\RCXCBEF.tmp to <Current directory>\JQIW.exe
- from C:\RCXCDA4.tmp to <Current directory>\owYE.exe
- from C:\RCXB6DF.tmp to <Current directory>\sgEi.exe
- from C:\RCXA112.tmp to <Current directory>\vcQw.exe
- from C:\RCXA27A.tmp to <Current directory>\xgoQ.exe
- from C:\RCXA3E2.tmp to <Current directory>\hEQE.exe
- from C:\RCX9F2E.tmp to <Current directory>\rgsW.exe
- from C:\RCX98A6.tmp to <Current directory>\rEcC.exe
- from C:\RCX9AD8.tmp to <Current directory>\OIwC.exe
- from C:\RCX9D78.tmp to <Current directory>\asEE.exe
- from C:\RCXA559.tmp to <Current directory>\dcoa.exe
- from C:\RCXB0B4.tmp to <Current directory>\DQIy.exe
- from C:\RCXB48C.tmp to <Current directory>\QcYG.exe
- from C:\RCXB5B5.tmp to <Current directory>\MYMC.exe
- from C:\RCXAC50.tmp to <Current directory>\bUkm.exe
- from C:\RCXA818.tmp to <Current directory>\bMYY.exe
- from C:\RCXAA0D.tmp to <Current directory>\rssk.exe
- from C:\RCXAAE8.tmp to <Current directory>\OcoM.exe
- from C:\RCXF808.tmp to <Current directory>\AkIe.exe
- from C:\RCXF9DD.tmp to <Current directory>\OUsY.exe
- from C:\RCXFBA2.tmp to <Current directory>\JMcG.exe
- from C:\RCXF652.tmp to <Current directory>\uoYS.exe
- from C:\RCXF15F.tmp to <Current directory>\asoG.exe
- from C:\RCXF24A.tmp to <Current directory>\dEge.exe
- from C:\RCXF42F.tmp to <Current directory>\VUUs.exe
- from C:\RCXFD68.tmp to <Current directory>\gYMs.exe
- from C:\RCX6DF.tmp to <Current directory>\ZoQG.exe
- from C:\RCX808.tmp to <Current directory>\NEwQ.exe
- from C:\RCX9DD.tmp to <Current directory>\cwkA.exe
- from C:\RCX596.tmp to <Current directory>\Vgkg.exe
- from C:\RCX101.tmp to <Current directory>\HEwU.exe
- from C:\RCX298.tmp to <Current directory>\NYMq.exe
- from C:\RCX3B1.tmp to <Current directory>\dUgC.exe
- from C:\RCXEFD8.tmp to <Current directory>\JcAM.exe
- from C:\RCXDBF0.tmp to <Current directory>\IYUG.exe
- from C:\RCXDE42.tmp to <Current directory>\VMMY.exe
- from C:\RCXE19D.tmp to <Current directory>\VIAs.exe
- from C:\RCXDA78.tmp to <Current directory>\SogE.exe
- from C:\RCXD651.tmp to <Current directory>\Swoa.exe
- from C:\RCXD8D1.tmp to <Current directory>\wgwK.exe
- from C:\RCXD97E.tmp to <Current directory>\Gwwu.exe
- from C:\RCXE41D.tmp to <Current directory>\oUQE.exe
- from C:\RCXECBA.tmp to <Current directory>\Vgwm.exe
- from C:\RCXEE31.tmp to <Current directory>\dcsc.exe
- from C:\RCXEF3B.tmp to <Current directory>\bUgI.exe
- from C:\RCXEB42.tmp to <Current directory>\Ocom.exe
- from C:\RCXE65F.tmp to <Current directory>\vMQU.exe
- from C:\RCXE7A8.tmp to <Current directory>\GMUM.exe
- from C:\RCXE9EA.tmp to <Current directory>\tkci.exe
- from C:\RCX35B4.tmp to <Current directory>\QcAm.exe
- from C:\RCX37E6.tmp to <Current directory>\VsYS.exe
- from C:\RCX3CD7.tmp to <Current directory>\TYgm.exe
- from C:\RCX346B.tmp to <Current directory>\qMwm.exe
- from C:\RCX2D47.tmp to <Current directory>\CIUi.exe
- from C:\RCX2F89.tmp to <Current directory>\vkUg.exe
- from C:\RCX32B5.tmp to <Current directory>\EYoM.exe
- from C:\RCX3EBC.tmp to <Current directory>\ogYe.exe
- from C:\RCX471A.tmp to <Current directory>\icMo.exe
- from C:\RCX4B8E.tmp to <Current directory>\FYYY.exe
- from C:\RCX4D63.tmp to <Current directory>\dcYW.exe
- from C:\RCX44E7.tmp to <Current directory>\wgIQ.exe
- from C:\RCX3FF5.tmp to <Current directory>\dkIi.exe
- from C:\RCX416C.tmp to <Current directory>\GkMa.exe
- from C:\RCX440C.tmp to <Current directory>\ZQEQ.exe
- from C:\RCX2BD0.tmp to <Current directory>\gscY.exe
- from C:\RCX1355.tmp to <Current directory>\jQQw.exe
- from C:\RCX1587.tmp to <Current directory>\IgQi.exe
- from C:\RCX18F2.tmp to <Current directory>\oMEy.exe
- from C:\RCX11FD.tmp to <Current directory>\eQAm.exe
- from C:\RCXFB8.tmp to <Current directory>\esUG.exe
- from C:\RCX1094.tmp to <Current directory>\cEUG.exe
- from C:\RCX1131.tmp to <Current directory>\AAcO.exe
- from C:\RCX1AF6.tmp to <Current directory>\Gwcq.exe
- from C:\RCX24BB.tmp to <Current directory>\eMcu.exe
- from C:\RCX2613.tmp to <Current directory>\MEES.exe
- from C:\RCX272D.tmp to <Current directory>\nsEy.exe
- from C:\RCX219E.tmp to <Current directory>\OIAA.exe
- from C:\RCX1CEA.tmp to <Current directory>\qEsG.exe
- from C:\RCX1E42.tmp to <Current directory>\OMEy.exe
- from C:\RCX1F0E.tmp to <Current directory>\Gssu.exe
- from C:\RCX82E9.tmp to <Current directory>\fIgu.exe
- from C:\RCX84BE.tmp to <Current directory>\xEco.exe
- from C:\RCX86E1.tmp to <Current directory>\yQwI.exe
- from C:\RCX8087.tmp to <Current directory>\aEcc.exe
- from C:\RCX79B1.tmp to <Current directory>\TAAm.exe
- from C:\RCX7E54.tmp to <Current directory>\ZYoQ.exe
- from C:\RCX7FAC.tmp to <Current directory>\DEYc.exe
- from C:\RCX8877.tmp to <Current directory>\sIEo.exe
- from C:\RCX929A.tmp to <Current directory>\PoIU.exe
- from C:\RCX93B4.tmp to <Current directory>\zMgm.exe
- from C:\RCX94CE.tmp to <Current directory>\EMwc.exe
- from C:\RCX9096.tmp to <Current directory>\sgsK.exe
- from C:\RCX8A0E.tmp to <Current directory>\rscq.exe
- from C:\RCX8B18.tmp to <Current directory>\kQEQ.exe
- from C:\RCX8CFD.tmp to <Current directory>\Gsge.exe
- from C:\RCX7750.tmp to <Current directory>\QgAe.exe
- from C:\RCX5A43.tmp to <Current directory>\PQMg.exe
- from C:\RCX5C18.tmp to <Current directory>\PMki.exe
- from C:\RCX5DBE.tmp to <Current directory>\eEsC.exe
- from C:\RCX5775.tmp to <Current directory>\UsIi.exe
- from C:\RCX5198.tmp to <Current directory>\LscG.exe
- from C:\RCX530F.tmp to <Current directory>\dcgA.exe
- from C:\RCX562C.tmp to <Current directory>\LEsS.exe
- from C:\RCX5FC2.tmp to <Current directory>\rQoM.exe
- from C:\RCX6FDE.tmp to <Current directory>\eUAg.exe
- from C:\RCX72FA.tmp to <Current directory>\JUEE.exe
- from C:\RCX74EE.tmp to <Current directory>\rAcq.exe
- from C:\RCX6C63.tmp to <Current directory>\NgUs.exe
- from C:\RCX636B.tmp to <Current directory>\Ggsq.exe
- from C:\RCX65FB.tmp to <Current directory>\lUce.exe
- from C:\RCX6947.tmp to <Current directory>\xskC.exe
- DNS ASK dn#.##ftncsi.com
- DNS ASK google.com
- ClassName: '' WindowName: 'Microsoft Windows'
- ClassName: '' WindowName: 'GocwIYEU.exe'
- ClassName: '' WindowName: 'rSYkcwMw.exe'
- ClassName: 'Indicator' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''