Technical Information
- <SYSTEM32>\tasks\firefox default browser agent 85b1c32918c7969d
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath @($env:UserProfile, $env:ProgramFiles) -Force
- %WINDIR%\explorer.exe
- toolspub2.exe
- %APPDATA%\rcfswcc
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-0gqd1.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-2dffn.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-lu1pa.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-p22qf.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-8pp7b.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-pgjnv.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-mff1v.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-t5p1q.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-nmnad.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-mjea5.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-ep6m6.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-tn0vr.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-0io9k.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-9vjee.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-mshh8.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-gh6d2.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-dfk35.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-pe2kv.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-n8cd3.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-l05ut.tmp
- %ProgramFiles(x86)%\xrecode3\install\unins000.dat
- %ProgramFiles(x86)%\xrecode3\is-6nhjd.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-hmmi0.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-m58pv.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-p6kmq.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-v02l7.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\plugins\internal\is-acvoi.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\plugins\internal\is-p2r5f.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-h8vgt.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-8u3m8.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-is4ro.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-7510a.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\lessmsi\is-5qsh9.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-4prrn.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-a6ifr.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-kp81n.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-atpm5.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-lhoo2.tmp
- %ProgramFiles(x86)%\xrecode3\xrecode3.exe
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-g0oh4.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-eqs89.tmp
- %TEMP%\is-atcjo.tmp\_isetup\_isdecmp.dll
- %TEMP%\is-atcjo.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-atcjo.tmp\_isetup\_setup64.tmp
- %TEMP%\is-atcjo.tmp\_isetup\_regdll.tmp
- %TEMP%\is-rp671.tmp\tuc3.tmp
- %TEMP%\latestx.exe
- %TEMP%\tuc3.exe
- %TEMP%\is-atcjo.tmp\_isetup\_iscrypt.dll
- %TEMP%\broom.exe
- %TEMP%\31839b57a4f11171d6abc8bbc4451ee4.exe
- %TEMP%\toolspub2.exe
- %TEMP%\c554.exe
- %TEMP%\installsetup9.exe
- %TEMP%\bd19.exe
- %TEMP%\27cc.exe
- %TEMP%\23e4.exe
- %TEMP%\ce4a.exe
- %ProgramFiles(x86)%\xrecode3\install\is-tjd5d.tmp
- %ProgramFiles(x86)%\xrecode3\stuff\is-ku4h0.tmp
- %ProgramFiles(x86)%\xrecode3\stuff\is-6u8b6.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-tonvn.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-37m2f.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-pmvcr.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-genbp.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-cti5q.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-369mm.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-0it7t.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-qaulp.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-7p73k.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-gko61.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-5onup.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-r0t8i.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-7u46c.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-7ffcp.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-kvtgn.tmp
- %ProgramFiles(x86)%\xrecode3\stuff\is-c5kab.tmp
- %ProgramFiles(x86)%\xrecode3\stuff\is-6refb.tmp
- %ProgramFiles(x86)%\xrecode3\bin\x86\is-n3v2c.tmp
- %TEMP%\1af4.exe
- %APPDATA%\rcfswcc
- %WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe
- %ProgramFiles(x86)%\xrecode3\stuff\date.txt
- %ProgramFiles(x86)%\xrecode3\stuff\tagsreplace.txt
- %ProgramFiles(x86)%\xrecode3\bin\x86\tak_deco_lib.dll
- %TEMP%\toolspub2.exe
- from %ProgramFiles(x86)%\xrecode3\install\is-tjd5d.tmp to %ProgramFiles(x86)%\xrecode3\install\unins000.exe
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-nmnad.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\rg_ebur128.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-mff1v.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\wavpackdll.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-pgjnv.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\libsoxr.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-8pp7b.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\libsox-3.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-p22qf.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\uchardet.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-lu1pa.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\utils.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-2dffn.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\libdtsdec.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-0gqd1.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\dsd2.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-t5p1q.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\libvorbis.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-pe2kv.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\sqlite3.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-n8cd3.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\lame_enc.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-l05ut.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\da.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-atpm5.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\daiso.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-kp81n.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\dstt.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-a6ifr.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\dsd2pcmt.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-4prrn.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\pcm2dsd.exe
- from %ProgramFiles(x86)%\xrecode3\bin\x86\lessmsi\is-5qsh9.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\lessmsi\lessmsi-v1.6.91.zip
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-7510a.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\d_writer.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-is4ro.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\libwebp.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-8u3m8.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\libwinpthread-1.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-h8vgt.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\sd.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\plugins\internal\is-p2r5f.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\plugins\internal\peak_scanner_plugin_c.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\plugins\internal\is-acvoi.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\plugins\internal\raw_decode_plugin_c.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-v02l7.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\copying
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-p6kmq.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\7z.exe
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-dfk35.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\mp3gain.exe
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-m58pv.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\takdec.exe
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-mjea5.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\optimfrog.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-tn0vr.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\opusenc.exe
- from %ProgramFiles(x86)%\xrecode3\stuff\is-ku4h0.tmp to %ProgramFiles(x86)%\xrecode3\stuff\date.txt
- from %ProgramFiles(x86)%\xrecode3\stuff\is-6u8b6.tmp to %ProgramFiles(x86)%\xrecode3\stuff\tagsreplace.txt
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-kvtgn.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\tak_deco_lib.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-7ffcp.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\avutil-58.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-7u46c.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\avfilter-9.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-r0t8i.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\swresample-4.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-5onup.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\bass.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-gko61.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\bass_aac.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-7p73k.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\bassalac.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-qaulp.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\bassape.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-0it7t.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\bassdsd.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-369mm.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\basscd.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-cti5q.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\bassflac.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-genbp.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\bassmix.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-pmvcr.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\bassopus.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-37m2f.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\basswma.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-tonvn.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\basswv.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-eqs89.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\bass_fx.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-n3v2c.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\bassmidi.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-g0oh4.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\bass_tta.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-lhoo2.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\copying.lgplv2.1
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-gh6d2.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\ff_helper.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-mshh8.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\gain_analysis.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-9vjee.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\libflac_dynamic.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-0io9k.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\libmp4v2.dll
- from %ProgramFiles(x86)%\xrecode3\bin\x86\is-ep6m6.tmp to %ProgramFiles(x86)%\xrecode3\bin\x86\bass_ofr.dll
- from %ProgramFiles(x86)%\xrecode3\is-6nhjd.tmp to %ProgramFiles(x86)%\xrecode3\xrecode3.exe
- %ProgramFiles(x86)%\xrecode3\stuff\date.txt
- %ProgramFiles(x86)%\xrecode3\stuff\tagsreplace.txt
- %ProgramFiles(x86)%\xrecode3\bin\x86\tak_deco_lib.dll
- '81.##.131.34':80
- '18#.#72.128.19':80
- '18#.#96.8.238':80
- http://18#.#72.128.19/newrock.exe
- http://18#.#96.8.238/NNaxff.exe
- http://81.##.131.34/fks/index.php
- ClassName: '' WindowName: 'f6bec5_XRE1212FlashFixClass_f6bec5'
- ClassName: 'msctls_updown32' WindowName: ''
- '%TEMP%\23e4.exe'
- '%TEMP%\27cc.exe'
- '%TEMP%\bd19.exe'
- '%TEMP%\c554.exe'
- '%TEMP%\installsetup9.exe'
- '%TEMP%\toolspub2.exe'
- '%TEMP%\ce4a.exe'
- '%TEMP%\31839b57a4f11171d6abc8bbc4451ee4.exe'
- '%TEMP%\broom.exe'
- '%TEMP%\tuc3.exe'
- '%TEMP%\latestx.exe'
- '%TEMP%\is-rp671.tmp\tuc3.tmp' /SL5="$10274,8423542,54272,%TEMP%\tuc3.exe"
- '%ProgramFiles(x86)%\xrecode3\xrecode3.exe' -i
- '%TEMP%\1af4.exe'
- '%ProgramFiles(x86)%\xrecode3\xrecode3.exe' -s
- '%WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe'
- '%WINDIR%\syswow64\schtasks.exe' /Query
- '%WINDIR%\syswow64\net.exe' helpmsg 1
- '%WINDIR%\syswow64\net1.exe' helpmsg 1