Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,C:\ProgramData\sIAowgok\rSYkcwMw.exe,'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'rSYkcwMw.exe' = 'C:\ProgramData\sIAowgok\rSYkcwMw.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'GocwIYEU.exe' = '%HOMEPATH%\CaIocokM\GocwIYEU.exe'
- [<HKLM>\SYSTEM\ControlSet001\services\yoYkgMRX] 'Start' = '00000002'
- C:\ProgramData\Package Cache\{6c95b50e-cb5a-4a1f-a7b4-8a6004f8dd6a}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{615bc16d-60f5-482e-91b3-b51d8130963b}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{01db25f3-1b76-4d97-88c8-1c90634d88fb}\vcredist_x86.exe
- C:\ProgramData\Package Cache\{2af972c7-13b0-4978-92a8-fee26a4fb4e9}\vcredist_x86.exe
- hidden files
- file extensions
- User Account Control (UAC)
- 'C:\ProgramData\ZQIIosos\XiskIEYE.exe'
- 'C:\ProgramData\sIAowgok\rSYkcwMw.exe'
- '%HOMEPATH%\CaIocokM\GocwIYEU.exe'
- '<SYSTEM32>\conhost.exe' /c "<Current directory>\<Virus name>"
- '<SYSTEM32>\wbem\wmiprvse.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
- '<SYSTEM32>\conhost.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
- '<SYSTEM32>\reg.exe' /pid=0xbb8 /log
- '<SYSTEM32>\conhost.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
- '<SYSTEM32>\reg.exe' /c ""%TEMP%\IusMAYwk.bat" "<Full path to virus>""
- '<SYSTEM32>\conhost.exe' /c ""%TEMP%\NuoAcokM.bat" "<Full path to virus>""
- '<SYSTEM32>\conhost.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
- '<SYSTEM32>\reg.exe' 0xa54 cscript.exe
- '<SYSTEM32>\reg.exe' /c "<Current directory>\<Virus name>"
- '<SYSTEM32>\conhost.exe' /c ""%TEMP%\UggoYcoI.bat" "<Full path to virus>""
- '<SYSTEM32>\cscript.exe' <LS_APPDATA>\Temp/file.vbs
- '<SYSTEM32>\conhost.exe'
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
- '<SYSTEM32>\reg.exe' 0xb58 wmpnscfg.exe
- '<SYSTEM32>\reg.exe' /c ""%TEMP%\NwAwYUUw.bat" "<Full path to virus>""
- '<SYSTEM32>\reg.exe' /pid=0x8e0 /log
- '<SYSTEM32>\conhost.exe' <LS_APPDATA>\Temp/file.vbs
- '<SYSTEM32>\cscript.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
- '<SYSTEM32>\reg.exe'
- <Current directory>\wMsw.ico
- <Current directory>\GAcI.exe
- C:\RCXBC53.tmp
- <Current directory>\fmQk.ico
- <Current directory>\tUcS.exe
- C:\RCXBB0A.tmp
- <Current directory>\caws.ico
- <Current directory>\Sooa.exe
- C:\RCXC0F7.tmp
- <Current directory>\dIcA.ico
- <Current directory>\QYEm.exe
- C:\RCXBE86.tmp
- <Current directory>\vssM.ico
- <Current directory>\cUYc.ico
- %TEMP%\fYQkIYsU.bat
- <Current directory>\YMkE.exe
- %TEMP%\HUIUwoso.bat
- <Current directory>\UwMK.exe
- C:\RCXB108.tmp
- C:\RCXB389.tmp
- <Current directory>\KKAE.ico
- <Current directory>\ioIk.exe
- C:\RCXB983.tmp
- <Current directory>\dIcw.ico
- <Current directory>\kMIm.exe
- C:\RCXB4D1.tmp
- <Current directory>\NAQw.exe
- <Current directory>\FEEe.exe
- C:\RCXCB97.tmp
- <Current directory>\dukQ.ico
- <Current directory>\ykgM.exe
- C:\RCXC9A3.tmp
- <Current directory>\FyMQ.ico
- <Current directory>\qkYe.exe
- C:\RCXCEF3.tmp
- <Current directory>\OwcQ.ico
- <Current directory>\bEQW.exe
- C:\RCXCD4D.tmp
- <Current directory>\pmcA.ico
- <Current directory>\kAoc.exe
- C:\RCXC3A7.tmp
- <Current directory>\Yegs.ico
- <Current directory>\TIks.exe
- C:\RCXC25E.tmp
- <Current directory>\sgUU.ico
- <Current directory>\ZUwA.exe
- C:\RCXC53E.tmp
- C:\RCXC6D4.tmp
- <Current directory>\CmIw.ico
- %TEMP%\IusMAYwk.bat
- <Current directory>\iUIM.ico
- %TEMP%\XgAMMMwI.bat
- <Current directory>\REQC.exe
- C:\RCX966A.tmp
- <Current directory>\mUMY.ico
- <Current directory>\TcEM.exe
- C:\RCX9486.tmp
- <Current directory>\AQso.ico
- <Current directory>\gosy.exe
- C:\RCX9830.tmp
- C:\RCX9A82.tmp
- <Current directory>\eoYg.ico
- <Current directory>\nMos.exe
- <Current directory>\Sakk.ico
- %TEMP%\jyIEAcME.bat
- <Current directory>\FwIi.exe
- <Current directory>\iUQo.exe
- C:\RCX90FA.tmp
- <Current directory>\nCIY.ico
- <Current directory>\zEQG.exe
- C:\RCX8EF6.tmp
- <Current directory>\dyEM.ico
- <Current directory>\aogs.exe
- C:\RCX937C.tmp
- <Current directory>\DuII.ico
- <Current directory>\gAsQ.exe
- C:\RCX91C6.tmp
- <Current directory>\sYAI.ico
- <Current directory>\MAkS.exe
- C:\RCX9C66.tmp
- <Current directory>\pMoM.ico
- <Current directory>\icEw.exe
- C:\RCXA9E4.tmp
- <Current directory>\jUYM.ico
- <Current directory>\qAIe.exe
- C:\RCXA8E9.tmp
- <Current directory>\ouQs.ico
- <Current directory>\TYIk.exe
- C:\RCXAF91.tmp
- <Current directory>\xIoQ.ico
- <Current directory>\AwYQ.exe
- C:\RCXACB2.tmp
- <Current directory>\ikQo.ico
- C:\RCX9F73.tmp
- <Current directory>\KwQg.ico
- <Current directory>\RsYe.exe
- <Current directory>\mmIc.ico
- <Current directory>\bUwE.exe
- %TEMP%\kwgcggws.bat
- C:\RCXA223.tmp
- <Current directory>\wyMc.ico
- <Current directory>\CIUY.exe
- C:\RCXA58E.tmp
- <Current directory>\LksU.ico
- <Current directory>\KAUK.exe
- C:\RCXA426.tmp
- <Current directory>\aoYY.exe
- C:\RCXF704.tmp
- <Current directory>\PaUs.ico
- <Current directory>\skgU.exe
- C:\RCXF56D.tmp
- <Current directory>\fIsM.ico
- <Current directory>\CEoy.exe
- C:\RCXFBF5.tmp
- <Current directory>\KoEk.ico
- <Current directory>\HoQk.exe
- C:\RCXF946.tmp
- <Current directory>\YkgY.ico
- <Current directory>\iQcs.exe
- C:\RCXEF52.tmp
- <Current directory>\JEok.ico
- <Current directory>\isAG.exe
- C:\RCXEDCB.tmp
- <Current directory>\koYE.ico
- <Current directory>\ZEIY.exe
- C:\RCXF108.tmp
- %TEMP%\NuoAcokM.bat
- C:\RCXF389.tmp
- <Current directory>\OGcM.ico
- %TEMP%\LyUMoQsU.bat
- <Current directory>\JGMY.ico
- <Current directory>\sokw.exe
- C:\RCXFD2E.tmp
- %TEMP%\XOowIoAs.bat
- <Current directory>\GEwW.exe
- C:\RCX993.tmp
- <Current directory>\eUUu.exe
- C:\RCX703.tmp
- <Current directory>\bSQk.ico
- <Current directory>\tiIE.ico
- <Current directory>\soUg.ico
- <Current directory>\tcIq.exe
- C:\RCXD6C.tmp
- <Current directory>\fMsc.exe
- %TEMP%\VWkcskog.bat
- C:\RCXB1A.tmp
- <Current directory>\HoAk.ico
- <Current directory>\jUYE.exe
- C:\RCX136.tmp
- <Current directory>\fWIE.ico
- <Current directory>\xYoK.exe
- C:\RCXFFFD.tmp
- <Current directory>\riQo.ico
- <Current directory>\EscG.exe
- C:\RCX4E0.tmp
- <Current directory>\WMgE.ico
- <Current directory>\qQgi.exe
- C:\RCX2AD.tmp
- <Current directory>\HIYQ.ico
- <Current directory>\GSAo.ico
- <Current directory>\ucMU.exe
- C:\RCXD918.tmp
- <Current directory>\KmEk.ico
- <Current directory>\Acws.exe
- C:\RCXD733.tmp
- <Current directory>\aWMc.ico
- %TEMP%\JcIcMAMw.bat
- <Current directory>\fUwC.exe
- C:\RCXDC55.tmp
- <Current directory>\iUwW.exe
- C:\RCXDADD.tmp
- <Current directory>\ycMw.ico
- C:\RCXD1F1.tmp
- <Current directory>\BQsM.ico
- <Current directory>\psAG.exe
- C:\RCXD00D.tmp
- <Current directory>\EqcQ.ico
- <Current directory>\KoQI.exe
- C:\RCXD2BD.tmp
- <Current directory>\BcQM.ico
- <Current directory>\HcgS.exe
- C:\RCXD5DB.tmp
- <Current directory>\liIk.ico
- <Current directory>\DEEE.exe
- C:\RCXD4D1.tmp
- <Current directory>\jsUM.ico
- <Current directory>\AIUo.exe
- C:\RCXE87B.tmp
- <Current directory>\QYAI.ico
- <Current directory>\DgUS.exe
- C:\RCXE6F4.tmp
- <Current directory>\tUoU.ico
- <Current directory>\PwMS.exe
- C:\RCXEB89.tmp
- <Current directory>\mkAo.ico
- <Current directory>\dQci.exe
- C:\RCXE9D3.tmp
- <Current directory>\doME.ico
- <Current directory>\uQgE.exe
- <Current directory>\gOMo.ico
- <Current directory>\WsUm.exe
- C:\RCXE156.tmp
- <Current directory>\SkwI.exe
- %TEMP%\UggoYcoI.bat
- C:\RCXDF90.tmp
- <Current directory>\GeAA.ico
- <Current directory>\bUgI.exe
- C:\RCXE473.tmp
- <Current directory>\wYUU.ico
- <Current directory>\Roge.exe
- C:\RCXE32B.tmp
- <Current directory>\cuUk.ico
- C:\RCX2CFB.tmp
- <Current directory>\oiUQ.ico
- <Current directory>\eUoi.exe
- %TEMP%\YYgQksgo.bat
- <Current directory>\JMcU.ico
- <Current directory>\xsoi.exe
- C:\RCX2E34.tmp
- <Current directory>\vwkQ.ico
- <Current directory>\lwUK.exe
- C:\RCX30F4.tmp
- <Current directory>\bWMs.ico
- <Current directory>\ToQI.exe
- C:\RCX2FBB.tmp
- <Current directory>\sUEE.ico
- <Current directory>\UEIu.exe
- C:\RCX2598.tmp
- <Current directory>\EssY.ico
- <Current directory>\xoYa.exe
- C:\RCX24DC.tmp
- <Current directory>\pmoI.ico
- %TEMP%\nqAwMcYU.bat
- <Current directory>\RkMG.exe
- C:\RCX2A0D.tmp
- <Current directory>\QQoS.exe
- C:\RCX2857.tmp
- <Current directory>\MMAQ.ico
- <Current directory>\wEwc.ico
- <Current directory>\pwcg.exe
- %TEMP%\ccEokwso.bat
- C:\RCX3FE8.tmp
- <Current directory>\rYkS.exe
- C:\RCX3D77.tmp
- <Current directory>\IaYU.ico
- <Current directory>\wqMI.ico
- <Current directory>\wQoI.ico
- <Current directory>\IAIu.exe
- C:\RCX44DA.tmp
- <Current directory>\JosO.exe
- C:\RCX4297.tmp
- %TEMP%\sucAwMcY.bat
- <Current directory>\tYUY.exe
- C:\RCX375C.tmp
- <Current directory>\OowM.ico
- <Current directory>\cQUW.exe
- C:\RCX3539.tmp
- <Current directory>\MQIM.ico
- <Current directory>\GEoo.exe
- C:\RCX3BE0.tmp
- <Current directory>\OqMo.ico
- <Auxiliary element>
- C:\RCX3A1B.tmp
- <Current directory>\vQQA.ico
- <Current directory>\Vccg.exe
- C:\RCXA1F.tmp
- <Current directory>\AsUI.ico
- <Current directory>\aMoG.exe
- C:\RCX954.tmp
- <Current directory>\LiUY.ico
- <Current directory>\qIwq.exe
- C:\RCXC71.tmp
- C:\RCXE27.tmp
- <Current directory>\myQs.ico
- <Current directory>\iEgw.exe
- %TEMP%\file.vbs
- <Current directory>\ZosI.ico
- <Current directory>\acwG.exe
- C:\ProgramData\kaog.txt
- <SYSTEM32>\config\systemprofile\CaIocokM\GocwIYEU
- %TEMP%\DycIEckM.bat
- %HOMEPATH%\CaIocokM\GocwIYEU
- C:\ProgramData\sIAowgok\rSYkcwMw
- C:\ProgramData\ZQIIosos\XiskIEYE.exe
- <Current directory>\<Virus name>
- %TEMP%\aUkwgkEU.bat
- <Current directory>\IGos.ico
- <Current directory>\xIUa.exe
- <Current directory>\oEck.ico
- <Current directory>\EokQ.exe
- C:\RCX82A.tmp
- C:\RCX120E.tmp
- C:\RCX1ACA.tmp
- <Current directory>\wGwU.ico
- <Current directory>\JcUe.exe
- C:\RCX1953.tmp
- <Current directory>\oQco.ico
- <Current directory>\EUoC.exe
- C:\RCX1C9F.tmp
- <Current directory>\ikUw.ico
- <Current directory>\dUkM.exe
- C:\RCX23C2.tmp
- <Current directory>\IKAM.ico
- <Current directory>\Mooi.exe
- C:\RCX20E4.tmp
- C:\RCX154A.tmp
- <Current directory>\vOsY.ico
- %TEMP%\CAEQwQkw.bat
- <Current directory>\tOUE.ico
- %TEMP%\WmUwEosc.bat
- <Current directory>\oUYY.exe
- <Current directory>\qMQM.exe
- C:\RCX178D.tmp
- <Current directory>\owcg.ico
- <Current directory>\CUYK.exe
- C:\RCX1635.tmp
- <Current directory>\HgIE.ico
- <Current directory>\QAYy.exe
- C:\RCX76D8.tmp
- <Current directory>\mwkE.ico
- <Current directory>\RUou.exe
- C:\RCX7590.tmp
- <Current directory>\hsoE.ico
- <Current directory>\PwAu.exe
- C:\RCX79F5.tmp
- <Current directory>\WYEg.ico
- <Current directory>\SUcs.exe
- C:\RCX7D22.tmp
- <Current directory>\Uqgs.ico
- <Current directory>\NMwG.exe
- C:\RCX7BCA.tmp
- %TEMP%\QicwIwEI.bat
- %TEMP%\FWUEQoMw.bat
- <Current directory>\KuQA.ico
- <Current directory>\vyAg.ico
- <Current directory>\YAQC.exe
- C:\RCX6B8E.tmp
- <Current directory>\AYUM.exe
- C:\RCX73AB.tmp
- <Current directory>\NQgM.ico
- <Current directory>\RUkc.exe
- C:\RCX70FC.tmp
- <Current directory>\vSQw.ico
- <Current directory>\VQci.exe
- <Current directory>\WOog.ico
- <Current directory>\twcM.ico
- <Current directory>\EAgQ.exe
- C:\RCX8996.tmp
- <Current directory>\BEcU.exe
- C:\RCX8580.tmp
- %TEMP%\MmwcgYsE.bat
- <Current directory>\QegY.ico
- <Current directory>\vcgO.exe
- C:\RCX8C95.tmp
- <Current directory>\fUgY.ico
- <Current directory>\cAoe.exe
- C:\RCX8ADF.tmp
- <Current directory>\siwc.ico
- <Current directory>\nswA.exe
- C:\RCX807E.tmp
- <Current directory>\YAgY.ico
- <Current directory>\FIIE.exe
- C:\RCX7EC8.tmp
- <Current directory>\IsQU.ico
- <Current directory>\QoYK.exe
- %TEMP%\hYEcMEgg.bat
- C:\RCX8495.tmp
- <Current directory>\UWEk.ico
- C:\RCX82D0.tmp
- <Current directory>\GacA.ico
- <Current directory>\BkcI.exe
- <Current directory>\LMwE.exe
- C:\RCX5045.tmp
- <Current directory>\tyks.ico
- <Current directory>\JsQO.exe
- C:\RCX4EBE.tmp
- <Current directory>\DcUc.ico
- <Current directory>\TQgy.exe
- C:\RCX53EF.tmp
- <Current directory>\fEMM.ico
- <Current directory>\hYkq.exe
- C:\RCX51CC.tmp
- <Current directory>\eOQs.ico
- <Current directory>\DMEY.exe
- <Current directory>\cOUc.ico
- <Current directory>\gIsE.exe
- C:\RCX48B2.tmp
- <Current directory>\LuEo.ico
- <Current directory>\AAME.exe
- C:\RCX4779.tmp
- <Current directory>\IEUY.ico
- <Current directory>\XIUC.exe
- C:\RCX4C5C.tmp
- <Current directory>\xYsQ.ico
- <Current directory>\kUgM.exe
- C:\RCX4A68.tmp
- <Current directory>\Zeoc.ico
- C:\RCX5528.tmp
- C:\RCX63CD.tmp
- <Current directory>\suMM.ico
- <Current directory>\wcEe.exe
- C:\RCX5FF5.tmp
- <Current directory>\AogY.ico
- <Current directory>\bYkm.exe
- C:\RCX6554.tmp
- <Current directory>\HqYg.ico
- <Current directory>\IgQU.exe
- C:\RCX69F8.tmp
- <Current directory>\fcgU.ico
- <Current directory>\LcAC.exe
- C:\RCX6851.tmp
- %TEMP%\fqAYIcgw.bat
- <Current directory>\TWYc.ico
- <Current directory>\DkIs.exe
- <Current directory>\qIAU.ico
- <Current directory>\TAMy.exe
- C:\RCX5651.tmp
- %TEMP%\NwAwYUUw.bat
- C:\RCX5D26.tmp
- <Current directory>\duwI.ico
- <Current directory>\iQYu.exe
- C:\RCX5AC5.tmp
- <Current directory>\ycIk.ico
- <Current directory>\YEgi.exe
- <Current directory>\QYEm.exe
- <Current directory>\vssM.ico
- <Current directory>\GAcI.exe
- <Current directory>\caws.ico
- <Current directory>\NAQw.exe
- <Current directory>\sgUU.ico
- <Current directory>\Sooa.exe
- <Current directory>\dIcA.ico
- <Current directory>\wMsw.ico
- <Current directory>\dIcw.ico
- <Current directory>\kMIm.exe
- <Current directory>\cUYc.ico
- <Current directory>\YMkE.exe
- <Current directory>\fmQk.ico
- <Current directory>\tUcS.exe
- <Current directory>\KKAE.ico
- <Current directory>\ioIk.exe
- <Current directory>\qkYe.exe
- <Current directory>\pmcA.ico
- <Current directory>\FEEe.exe
- <Current directory>\dukQ.ico
- <Current directory>\bEQW.exe
- <Current directory>\EqcQ.ico
- <Current directory>\kAoc.exe
- <Current directory>\OwcQ.ico
- <Current directory>\FyMQ.ico
- <Current directory>\TIks.exe
- <Current directory>\iUIM.ico
- <Current directory>\ZUwA.exe
- <Current directory>\Yegs.ico
- <Current directory>\CmIw.ico
- <Current directory>\ykgM.exe
- <Current directory>\REQC.exe
- %TEMP%\XgAMMMwI.bat
- <Current directory>\UwMK.exe
- <Current directory>\Sakk.ico
- <Current directory>\FwIi.exe
- <Current directory>\TcEM.exe
- %TEMP%\jyIEAcME.bat
- <Current directory>\mmIc.ico
- <Current directory>\bUwE.exe
- <Current directory>\eoYg.ico
- <Current directory>\nMos.exe
- <Current directory>\mUMY.ico
- <Current directory>\sYAI.ico
- <Current directory>\MAkS.exe
- <Current directory>\nCIY.ico
- <Current directory>\aogs.exe
- <Current directory>\AQso.ico
- <Current directory>\gosy.exe
- <Current directory>\DuII.ico
- <Current directory>\gAsQ.exe
- <Current directory>\AwYQ.exe
- <Current directory>\ikQo.ico
- <Current directory>\icEw.exe
- <Current directory>\ouQs.ico
- %TEMP%\HUIUwoso.bat
- <Current directory>\xIoQ.ico
- <Current directory>\TYIk.exe
- %TEMP%\kwgcggws.bat
- <Current directory>\pMoM.ico
- <Current directory>\LksU.ico
- <Current directory>\KAUK.exe
- <Current directory>\KwQg.ico
- <Current directory>\RsYe.exe
- <Current directory>\jUYM.ico
- <Current directory>\qAIe.exe
- <Current directory>\wyMc.ico
- <Current directory>\CIUY.exe
- <Current directory>\aoYY.exe
- <Current directory>\PaUs.ico
- <Current directory>\skgU.exe
- <Current directory>\fIsM.ico
- <Current directory>\iQcs.exe
- <Current directory>\KoEk.ico
- <Current directory>\CEoy.exe
- <Current directory>\YkgY.ico
- <Current directory>\OGcM.ico
- <Current directory>\ZEIY.exe
- <Current directory>\JEok.ico
- <Current directory>\dQci.exe
- <Current directory>\koYE.ico
- <Current directory>\JGMY.ico
- <Current directory>\sokw.exe
- <Current directory>\isAG.exe
- %TEMP%\LyUMoQsU.bat
- %TEMP%\NuoAcokM.bat
- %TEMP%\XOowIoAs.bat
- <Current directory>\WMgE.ico
- <Current directory>\eUUu.exe
- <Current directory>\tiIE.ico
- <Current directory>\fMsc.exe
- <Current directory>\bSQk.ico
- <Current directory>\GEwW.exe
- <Current directory>\EscG.exe
- <Current directory>\xYoK.exe
- <Current directory>\HoAk.ico
- <Current directory>\HoQk.exe
- <Current directory>\fWIE.ico
- <Current directory>\qQgi.exe
- <Current directory>\HIYQ.ico
- <Current directory>\jUYE.exe
- <Current directory>\riQo.ico
- <Current directory>\mkAo.ico
- %TEMP%\IusMAYwk.bat
- <Current directory>\aWMc.ico
- <Current directory>\GSAo.ico
- <Current directory>\ucMU.exe
- <Current directory>\fUwC.exe
- %TEMP%\JcIcMAMw.bat
- <Current directory>\iUwW.exe
- <Current directory>\ycMw.ico
- <Current directory>\Acws.exe
- <Current directory>\psAG.exe
- <Current directory>\liIk.ico
- <Current directory>\KoQI.exe
- <Current directory>\BQsM.ico
- <Current directory>\HcgS.exe
- <Current directory>\KmEk.ico
- <Current directory>\DEEE.exe
- <Current directory>\BcQM.ico
- <Current directory>\AIUo.exe
- <Current directory>\QYAI.ico
- <Current directory>\DgUS.exe
- <Current directory>\tUoU.ico
- <Current directory>\uQgE.exe
- %TEMP%\UggoYcoI.bat
- <Current directory>\PwMS.exe
- <Current directory>\doME.ico
- <Current directory>\wYUU.ico
- <Current directory>\gOMo.ico
- <Current directory>\WsUm.exe
- <Current directory>\jsUM.ico
- <Current directory>\SkwI.exe
- <Current directory>\cuUk.ico
- <Current directory>\bUgI.exe
- <Current directory>\GeAA.ico
- <Current directory>\Roge.exe
- <Current directory>\iUQo.exe
- <Current directory>\lwUK.exe
- <Current directory>\wEwc.ico
- <Current directory>\ToQI.exe
- <Current directory>\vwkQ.ico
- <Current directory>\tYUY.exe
- <Current directory>\OowM.ico
- <Current directory>\cQUW.exe
- <Current directory>\MQIM.ico
- <Current directory>\bWMs.ico
- <Current directory>\MMAQ.ico
- <Current directory>\RkMG.exe
- <Current directory>\QQoS.exe
- %TEMP%\nqAwMcYU.bat
- <Current directory>\oiUQ.ico
- <Current directory>\eUoi.exe
- <Current directory>\JMcU.ico
- <Current directory>\xsoi.exe
- <Current directory>\wQoI.ico
- <Current directory>\IAIu.exe
- <Current directory>\wqMI.ico
- <Current directory>\JosO.exe
- <Current directory>\cOUc.ico
- <Current directory>\gIsE.exe
- <Current directory>\LuEo.ico
- <Current directory>\AAME.exe
- %TEMP%\ccEokwso.bat
- <Current directory>\Vccg.exe
- <Current directory>\OqMo.ico
- <Current directory>\GEoo.exe
- <Current directory>\vQQA.ico
- <Current directory>\pwcg.exe
- %TEMP%\YYgQksgo.bat
- <Current directory>\rYkS.exe
- <Current directory>\IaYU.ico
- <Current directory>\pmoI.ico
- <Current directory>\myQs.ico
- <Current directory>\iEgw.exe
- <Current directory>\ZosI.ico
- <Current directory>\acwG.exe
- %TEMP%\WmUwEosc.bat
- <Current directory>\vOsY.ico
- <Current directory>\tOUE.ico
- <Current directory>\oUYY.exe
- <Current directory>\aMoG.exe
- <Current directory>\EokQ.exe
- <Current directory>\IGos.ico
- %TEMP%\DycIEckM.bat
- <Current directory>\oEck.ico
- <Current directory>\qIwq.exe
- <Current directory>\AsUI.ico
- <Current directory>\xIUa.exe
- <Current directory>\LiUY.ico
- <Current directory>\ikUw.ico
- <Current directory>\dUkM.exe
- <Current directory>\IKAM.ico
- <Current directory>\Mooi.exe
- <Current directory>\sUEE.ico
- <Current directory>\UEIu.exe
- <Current directory>\EssY.ico
- <Current directory>\xoYa.exe
- <Current directory>\JcUe.exe
- <Current directory>\QAYy.exe
- <Current directory>\owcg.ico
- <Current directory>\qMQM.exe
- <Current directory>\HgIE.ico
- <Current directory>\EUoC.exe
- <Current directory>\wGwU.ico
- <Current directory>\CUYK.exe
- <Current directory>\oQco.ico
- <Current directory>\NMwG.exe
- <Current directory>\WYEg.ico
- <Current directory>\RUou.exe
- <Current directory>\Uqgs.ico
- <Current directory>\FIIE.exe
- <Current directory>\IsQU.ico
- <Current directory>\SUcs.exe
- <Current directory>\WOog.ico
- <Current directory>\mwkE.ico
- <Current directory>\vSQw.ico
- <Current directory>\VQci.exe
- <Current directory>\KuQA.ico
- <Current directory>\AYUM.exe
- <Current directory>\hsoE.ico
- <Current directory>\PwAu.exe
- <Current directory>\NQgM.ico
- <Current directory>\RUkc.exe
- <Current directory>\cAoe.exe
- <Current directory>\siwc.ico
- <Current directory>\EAgQ.exe
- <Current directory>\QegY.ico
- <Current directory>\zEQG.exe
- <Current directory>\dyEM.ico
- <Current directory>\vcgO.exe
- <Current directory>\fUgY.ico
- <Current directory>\twcM.ico
- <Current directory>\QoYK.exe
- <Current directory>\GacA.ico
- <Current directory>\nswA.exe
- <Current directory>\YAgY.ico
- <Current directory>\UWEk.ico
- <Current directory>\BEcU.exe
- <Current directory>\BkcI.exe
- %TEMP%\hYEcMEgg.bat
- %TEMP%\QicwIwEI.bat
- <Current directory>\DMEY.exe
- <Current directory>\fEMM.ico
- <Current directory>\TQgy.exe
- <Current directory>\eOQs.ico
- <Current directory>\TAMy.exe
- %TEMP%\fqAYIcgw.bat
- <Current directory>\hYkq.exe
- <Current directory>\qIAU.ico
- <Current directory>\tyks.ico
- <Current directory>\Zeoc.ico
- <Current directory>\XIUC.exe
- <Current directory>\IEUY.ico
- <Current directory>\kUgM.exe
- <Current directory>\DcUc.ico
- <Current directory>\LMwE.exe
- <Current directory>\xYsQ.ico
- <Current directory>\JsQO.exe
- <Current directory>\fcgU.ico
- <Current directory>\LcAC.exe
- <Current directory>\wcEe.exe
- %TEMP%\NwAwYUUw.bat
- <Current directory>\vyAg.ico
- <Current directory>\YAQC.exe
- <Current directory>\HqYg.ico
- <Current directory>\IgQU.exe
- <Current directory>\suMM.ico
- <Current directory>\ycIk.ico
- <Current directory>\YEgi.exe
- <Current directory>\TWYc.ico
- <Current directory>\DkIs.exe
- <Current directory>\AogY.ico
- <Current directory>\bYkm.exe
- <Current directory>\duwI.ico
- <Current directory>\iQYu.exe
- from C:\RCXBE86.tmp to <Current directory>\QYEm.exe
- from C:\RCXBC53.tmp to <Current directory>\GAcI.exe
- from C:\RCXC25E.tmp to <Current directory>\NAQw.exe
- from C:\RCXC0F7.tmp to <Current directory>\Sooa.exe
- from C:\RCXB4D1.tmp to <Current directory>\kMIm.exe
- from C:\RCXB389.tmp to <Current directory>\YMkE.exe
- from C:\RCXBB0A.tmp to <Current directory>\tUcS.exe
- from C:\RCXB983.tmp to <Current directory>\ioIk.exe
- from C:\RCXCD4D.tmp to <Current directory>\qkYe.exe
- from C:\RCXCB97.tmp to <Current directory>\FEEe.exe
- from C:\RCXD00D.tmp to <Current directory>\bEQW.exe
- from C:\RCXCEF3.tmp to <Current directory>\kAoc.exe
- from C:\RCXC53E.tmp to <Current directory>\TIks.exe
- from C:\RCXC3A7.tmp to <Current directory>\ZUwA.exe
- from C:\RCXC9A3.tmp to <Current directory>\ykgM.exe
- from C:\RCXC6D4.tmp to <Current directory>\REQC.exe
- from C:\RCX9A82.tmp to <Current directory>\FwIi.exe
- from C:\RCX9830.tmp to <Current directory>\TcEM.exe
- from C:\RCX9F73.tmp to <Current directory>\bUwE.exe
- from C:\RCX9C66.tmp to <Current directory>\nMos.exe
- from C:\RCX937C.tmp to <Current directory>\MAkS.exe
- from C:\RCX91C6.tmp to <Current directory>\aogs.exe
- from C:\RCX966A.tmp to <Current directory>\gosy.exe
- from C:\RCX9486.tmp to <Current directory>\gAsQ.exe
- from C:\RCXACB2.tmp to <Current directory>\AwYQ.exe
- from C:\RCXA9E4.tmp to <Current directory>\icEw.exe
- from C:\RCXB108.tmp to <Current directory>\UwMK.exe
- from C:\RCXAF91.tmp to <Current directory>\TYIk.exe
- from C:\RCXA426.tmp to <Current directory>\KAUK.exe
- from C:\RCXA223.tmp to <Current directory>\RsYe.exe
- from C:\RCXA8E9.tmp to <Current directory>\qAIe.exe
- from C:\RCXA58E.tmp to <Current directory>\CIUY.exe
- from C:\RCXF704.tmp to <Current directory>\aoYY.exe
- from C:\RCXF56D.tmp to <Current directory>\skgU.exe
- from C:\RCXFBF5.tmp to <Current directory>\iQcs.exe
- from C:\RCXF946.tmp to <Current directory>\CEoy.exe
- from C:\RCXEF52.tmp to <Current directory>\ZEIY.exe
- from C:\RCXEDCB.tmp to <Current directory>\dQci.exe
- from C:\RCXF389.tmp to <Current directory>\sokw.exe
- from C:\RCXF108.tmp to <Current directory>\isAG.exe
- from C:\RCX703.tmp to <Current directory>\eUUu.exe
- from C:\RCX4E0.tmp to <Current directory>\EscG.exe
- from C:\RCXB1A.tmp to <Current directory>\fMsc.exe
- from C:\RCX993.tmp to <Current directory>\GEwW.exe
- from C:\RCXFFFD.tmp to <Current directory>\xYoK.exe
- from C:\RCXFD2E.tmp to <Current directory>\HoQk.exe
- from C:\RCX2AD.tmp to <Current directory>\qQgi.exe
- from C:\RCX136.tmp to <Current directory>\jUYE.exe
- from C:\RCXD918.tmp to <Current directory>\ucMU.exe
- from C:\RCXD733.tmp to <Current directory>\Acws.exe
- from C:\RCXDC55.tmp to <Current directory>\fUwC.exe
- from C:\RCXDADD.tmp to <Current directory>\iUwW.exe
- from C:\RCXD2BD.tmp to <Current directory>\psAG.exe
- from C:\RCXD1F1.tmp to <Current directory>\KoQI.exe
- from C:\RCXD5DB.tmp to <Current directory>\HcgS.exe
- from C:\RCXD4D1.tmp to <Current directory>\DEEE.exe
- from C:\RCXE87B.tmp to <Current directory>\AIUo.exe
- from C:\RCXE6F4.tmp to <Current directory>\DgUS.exe
- from C:\RCXEB89.tmp to <Current directory>\uQgE.exe
- from C:\RCXE9D3.tmp to <Current directory>\PwMS.exe
- from C:\RCXE156.tmp to <Current directory>\WsUm.exe
- from C:\RCXDF90.tmp to <Current directory>\SkwI.exe
- from C:\RCXE473.tmp to <Current directory>\bUgI.exe
- from C:\RCXE32B.tmp to <Current directory>\Roge.exe
- from C:\RCX90FA.tmp to <Current directory>\iUQo.exe
- from C:\RCX30F4.tmp to <Current directory>\lwUK.exe
- from C:\RCX2FBB.tmp to <Current directory>\ToQI.exe
- from C:\RCX375C.tmp to <Current directory>\tYUY.exe
- from C:\RCX3539.tmp to <Current directory>\cQUW.exe
- from C:\RCX2A0D.tmp to <Current directory>\RkMG.exe
- from C:\RCX2857.tmp to <Current directory>\QQoS.exe
- from C:\RCX2E34.tmp to <Current directory>\eUoi.exe
- from C:\RCX2CFB.tmp to <Current directory>\xsoi.exe
- from C:\RCX44DA.tmp to <Current directory>\IAIu.exe
- from C:\RCX4297.tmp to <Current directory>\JosO.exe
- from C:\RCX48B2.tmp to <Current directory>\gIsE.exe
- from C:\RCX4779.tmp to <Current directory>\AAME.exe
- from C:\RCX3BE0.tmp to <Current directory>\Vccg.exe
- from C:\RCX3A1B.tmp to <Current directory>\GEoo.exe
- from C:\RCX3FE8.tmp to <Current directory>\pwcg.exe
- from C:\RCX3D77.tmp to <Current directory>\rYkS.exe
- from C:\RCX120E.tmp to <Current directory>\iEgw.exe
- from C:\RCXE27.tmp to <Current directory>\acwG.exe
- from C:\RCX1635.tmp to <Current directory>\qMQM.exe
- from C:\RCX154A.tmp to <Current directory>\oUYY.exe
- from C:\RCX954.tmp to <Current directory>\xIUa.exe
- from C:\RCX82A.tmp to <Current directory>\EokQ.exe
- from C:\RCXC71.tmp to <Current directory>\aMoG.exe
- from C:\RCXA1F.tmp to <Current directory>\qIwq.exe
- from C:\RCX23C2.tmp to <Current directory>\dUkM.exe
- from C:\RCX20E4.tmp to <Current directory>\Mooi.exe
- from C:\RCX2598.tmp to <Current directory>\UEIu.exe
- from C:\RCX24DC.tmp to <Current directory>\xoYa.exe
- from C:\RCX1953.tmp to <Current directory>\CUYK.exe
- from C:\RCX178D.tmp to <Current directory>\QAYy.exe
- from C:\RCX1C9F.tmp to <Current directory>\JcUe.exe
- from C:\RCX1ACA.tmp to <Current directory>\EUoC.exe
- from C:\RCX7BCA.tmp to <Current directory>\NMwG.exe
- from C:\RCX79F5.tmp to <Current directory>\RUou.exe
- from C:\RCX7EC8.tmp to <Current directory>\FIIE.exe
- from C:\RCX7D22.tmp to <Current directory>\SUcs.exe
- from C:\RCX73AB.tmp to <Current directory>\VQci.exe
- from C:\RCX70FC.tmp to <Current directory>\AYUM.exe
- from C:\RCX76D8.tmp to <Current directory>\PwAu.exe
- from C:\RCX7590.tmp to <Current directory>\RUkc.exe
- from C:\RCX8ADF.tmp to <Current directory>\cAoe.exe
- from C:\RCX8996.tmp to <Current directory>\EAgQ.exe
- from C:\RCX8EF6.tmp to <Current directory>\zEQG.exe
- from C:\RCX8C95.tmp to <Current directory>\vcgO.exe
- from C:\RCX82D0.tmp to <Current directory>\QoYK.exe
- from C:\RCX807E.tmp to <Current directory>\nswA.exe
- from C:\RCX8580.tmp to <Current directory>\BEcU.exe
- from C:\RCX8495.tmp to <Current directory>\BkcI.exe
- from C:\RCX53EF.tmp to <Current directory>\DMEY.exe
- from C:\RCX51CC.tmp to <Current directory>\TQgy.exe
- from C:\RCX5651.tmp to <Current directory>\TAMy.exe
- from C:\RCX5528.tmp to <Current directory>\hYkq.exe
- from C:\RCX4C5C.tmp to <Current directory>\XIUC.exe
- from C:\RCX4A68.tmp to <Current directory>\kUgM.exe
- from C:\RCX5045.tmp to <Current directory>\LMwE.exe
- from C:\RCX4EBE.tmp to <Current directory>\JsQO.exe
- from C:\RCX6851.tmp to <Current directory>\LcAC.exe
- from C:\RCX6554.tmp to <Current directory>\wcEe.exe
- from C:\RCX6B8E.tmp to <Current directory>\YAQC.exe
- from C:\RCX69F8.tmp to <Current directory>\IgQU.exe
- from C:\RCX5D26.tmp to <Current directory>\YEgi.exe
- from C:\RCX5AC5.tmp to <Current directory>\DkIs.exe
- from C:\RCX63CD.tmp to <Current directory>\bYkm.exe
- from C:\RCX5FF5.tmp to <Current directory>\iQYu.exe
- DNS ASK dn#.##ftncsi.com
- DNS ASK google.com
- ClassName: '' WindowName: 'rSYkcwMw.exe'
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: 'Microsoft Windows'
- ClassName: 'Indicator' WindowName: ''
- ClassName: '' WindowName: 'GocwIYEU.exe'