Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'lacMcYws.exe' = '%ALLUSERSPROFILE%\WuIEgAsU\lacMcYws.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,%ALLUSERSPROFILE%\WuIEgAsU\lacMcYws.exe,'
- [<HKLM>\SYSTEM\ControlSet001\Services\vwYgEQEb] 'ImagePath' = '%ALLUSERSPROFILE%\tuIMYcEM\ZgMYMIIE.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\vwYgEQEb] 'Start' = '00000002'
- <STUBS_DIR>\test.exe
- C:\Far2\Far.exe
- скрытых файлов
- расширений файлов
- Средство контроля пользовательских учетных записей (UAC)
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
- '%TEMP%\setup.exe'
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
- '%ALLUSERSPROFILE%\WuIEgAsU\lacMcYws.exe'
- '%HOMEPATH%\gOEYMkgs\SSIkQYgQ.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\setup.exe
- '%ALLUSERSPROFILE%\tuIMYcEM\ZgMYMIIE.exe'
- %HOMEPATH%\gOEYMkgs\IYMA.exe
- %TEMP%\WER44cb.dir00\manifest.txt
- %TEMP%\WER44cb.dir00\appcompat.txt
- %HOMEPATH%\gOEYMkgs\LEgG.exe
- %HOMEPATH%\gOEYMkgs\eAga.exe
- %HOMEPATH%\gOEYMkgs\TQoK.exe
- %TEMP%\WER44cb.dir00\ZgMYMIIE.exe.hdmp
- %HOMEPATH%\gOEYMkgs\WAou.exe
- %TEMP%\WER44cb.dir00\ZgMYMIIE.exe.mdmp
- %HOMEPATH%\gOEYMkgs\uIgM.exe
- %HOMEPATH%\gOEYMkgs\kkgy.exe
- %HOMEPATH%\gOEYMkgs\wwcC.exe
- %HOMEPATH%\gOEYMkgs\AUEo.exe
- %HOMEPATH%\gOEYMkgs\cMko.exe
- %HOMEPATH%\gOEYMkgs\WQsO.exe
- %HOMEPATH%\gOEYMkgs\JUYi.exe
- %HOMEPATH%\gOEYMkgs\LsUq.exe
- %HOMEPATH%\gOEYMkgs\HIYQ.exe
- %HOMEPATH%\gOEYMkgs\KQci.exe
- %HOMEPATH%\gOEYMkgs\Jcku.exe
- %HOMEPATH%\gOEYMkgs\IEYS.exe
- %HOMEPATH%\gOEYMkgs\rkoK.exe
- %HOMEPATH%\gOEYMkgs\aMkK.exe
- %HOMEPATH%\gOEYMkgs\pEgk.exe
- %HOMEPATH%\gOEYMkgs\UIoe.exe
- %HOMEPATH%\gOEYMkgs\DsQE.exe
- %HOMEPATH%\gOEYMkgs\WYks.exe
- %HOMEPATH%\gOEYMkgs\wAgc.exe
- %HOMEPATH%\gOEYMkgs\ycIY.exe
- %HOMEPATH%\gOEYMkgs\wskY.exe
- %HOMEPATH%\gOEYMkgs\vgcm.exe
- %HOMEPATH%\gOEYMkgs\zgks.exe
- %HOMEPATH%\gOEYMkgs\twwM.exe
- %HOMEPATH%\gOEYMkgs\mUck.exe
- %HOMEPATH%\gOEYMkgs\pYoE.exe
- %HOMEPATH%\gOEYMkgs\ZEYs.exe
- %HOMEPATH%\gOEYMkgs\boMc.exe
- %HOMEPATH%\gOEYMkgs\kwUI.exe
- %HOMEPATH%\gOEYMkgs\mwoe.exe
- %HOMEPATH%\gOEYMkgs\LkQK.exe
- %HOMEPATH%\gOEYMkgs\JoMe.exe
- %HOMEPATH%\gOEYMkgs\VIge.exe
- %HOMEPATH%\gOEYMkgs\bcYe.exe
- %HOMEPATH%\gOEYMkgs\isEo.exe
- %HOMEPATH%\gOEYMkgs\igQa.exe
- %HOMEPATH%\gOEYMkgs\HwUy.exe
- %HOMEPATH%\gOEYMkgs\xIga.exe
- %HOMEPATH%\gOEYMkgs\LwUA.exe
- %HOMEPATH%\gOEYMkgs\XAgm.exe
- %HOMEPATH%\gOEYMkgs\hgkY.exe
- %HOMEPATH%\gOEYMkgs\UAkS.exe
- %HOMEPATH%\gOEYMkgs\jAMe.exe
- %HOMEPATH%\gOEYMkgs\xkQu.exe
- %HOMEPATH%\gOEYMkgs\VAIa.exe
- %HOMEPATH%\gOEYMkgs\JQUa.exe
- %HOMEPATH%\gOEYMkgs\Ywwg.exe
- %HOMEPATH%\gOEYMkgs\ysAa.exe
- %HOMEPATH%\gOEYMkgs\toIK.exe
- %HOMEPATH%\gOEYMkgs\awcE.exe
- %HOMEPATH%\gOEYMkgs\Lcsq.exe
- %HOMEPATH%\gOEYMkgs\nUQk.exe
- %HOMEPATH%\gOEYMkgs\BscK.exe
- %HOMEPATH%\gOEYMkgs\PAwW.exe
- %TEMP%\WERb004.dir00\ZgMYMIIE.exe.hdmp
- %TEMP%\WERb004.dir00\ZgMYMIIE.exe.mdmp
- %HOMEPATH%\gOEYMkgs\ZYgy.exe
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\_filelst.cfg
- %TEMP%\WERb004.dir00\manifest.txt
- %TEMP%\WERb004.dir00\appcompat.txt
- %HOMEPATH%\gOEYMkgs\nwMO.exe
- %HOMEPATH%\gOEYMkgs\BYcy.exe
- %HOMEPATH%\gOEYMkgs\UIwQ.exe
- %HOMEPATH%\gOEYMkgs\WYgi.exe
- %HOMEPATH%\gOEYMkgs\REoI.exe
- %HOMEPATH%\gOEYMkgs\kskG.exe
- %HOMEPATH%\gOEYMkgs\yYwq.exe
- %HOMEPATH%\gOEYMkgs\EAYa.exe
- %HOMEPATH%\gOEYMkgs\ZIwC.exe
- %HOMEPATH%\gOEYMkgs\EAYC.exe
- %HOMEPATH%\gOEYMkgs\jMcU.exe
- %HOMEPATH%\gOEYMkgs\FcoK.exe
- %HOMEPATH%\gOEYMkgs\WYwM.exe
- %HOMEPATH%\gOEYMkgs\gYkY.exe
- %HOMEPATH%\gOEYMkgs\TwwQ.exe
- %HOMEPATH%\gOEYMkgs\lIwi.exe
- %HOMEPATH%\gOEYMkgs\vIwY.exe
- %HOMEPATH%\gOEYMkgs\msAy.exe
- %HOMEPATH%\gOEYMkgs\igQQ.exe
- %HOMEPATH%\gOEYMkgs\cMwe.exe
- %HOMEPATH%\gOEYMkgs\HEMI.exe
- %HOMEPATH%\gOEYMkgs\DEEU.exe
- %HOMEPATH%\gOEYMkgs\lkAm.exe
- %HOMEPATH%\gOEYMkgs\SMgE.exe
- %HOMEPATH%\gOEYMkgs\XkMK.exe
- %HOMEPATH%\gOEYMkgs\Ucoq.exe
- %HOMEPATH%\gOEYMkgs\KsAA.exe
- %HOMEPATH%\gOEYMkgs\UUMK.exe
- %HOMEPATH%\gOEYMkgs\lEoe.exe
- %HOMEPATH%\gOEYMkgs\YkwW.exe
- %HOMEPATH%\gOEYMkgs\YwQm.exe
- %HOMEPATH%\gOEYMkgs\ZcIg.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe
- %HOMEPATH%\gOEYMkgs\vsIC.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe
- %HOMEPATH%\gOEYMkgs\xEIU.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe
- %HOMEPATH%\gOEYMkgs\rAoc.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe
- %HOMEPATH%\gOEYMkgs\isYi.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe
- %HOMEPATH%\gOEYMkgs\bsEc.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe
- %HOMEPATH%\gOEYMkgs\AIks.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe
- %HOMEPATH%\gOEYMkgs\YQYq.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe
- %HOMEPATH%\gOEYMkgs\cYYq.exe
- %TEMP%\WERcfdb.dir00\manifest.txt
- %TEMP%\WERcfdb.dir00\appcompat.txt
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe
- %HOMEPATH%\gOEYMkgs\EQAC.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe
- %HOMEPATH%\gOEYMkgs\xwUq.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe
- %HOMEPATH%\gOEYMkgs\qkEc.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe
- %TEMP%\WER4b05.dir00\appcompat.txt
- %TEMP%\WER4b05.dir00\ZgMYMIIE.exe.hdmp
- %TEMP%\WER4b05.dir00\ZgMYMIIE.exe.mdmp
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe
- %HOMEPATH%\gOEYMkgs\akwm.exe
- %TEMP%\WER4b05.dir00\manifest.txt
- %HOMEPATH%\gOEYMkgs\SSIkQYgQ.exe
- %ALLUSERSPROFILE%\WuIEgAsU\lacMcYws
- %HOMEPATH%\gOEYMkgs\SSIkQYgQ
- %ALLUSERSPROFILE%\caQc.txt
- %ALLUSERSPROFILE%\tuIMYcEM\ZgMYMIIE.exe
- %ALLUSERSPROFILE%\WuIEgAsU\lacMcYws.exe
- %HOMEPATH%\gOEYMkgs\NEgg.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe
- %HOMEPATH%\gOEYMkgs\cMAy.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe
- %HOMEPATH%\gOEYMkgs\eokY.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe
- %HOMEPATH%\gOEYMkgs\ikEO.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe
- %HOMEPATH%\gOEYMkgs\rsMu.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe
- %HOMEPATH%\gOEYMkgs\TIUU.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe
- %HOMEPATH%\gOEYMkgs\GsUK.exe
- %HOMEPATH%\gOEYMkgs\pssm.exe
- %HOMEPATH%\gOEYMkgs\qcQA.exe
- %HOMEPATH%\gOEYMkgs\aQEM.exe
- %HOMEPATH%\gOEYMkgs\jQwU.exe
- %HOMEPATH%\gOEYMkgs\ogcs.exe
- %HOMEPATH%\gOEYMkgs\AkcC.exe
- %HOMEPATH%\gOEYMkgs\gQYy.exe
- %HOMEPATH%\gOEYMkgs\TEYY.exe
- %HOMEPATH%\gOEYMkgs\mQYw.exe
- %HOMEPATH%\gOEYMkgs\BYsm.exe
- %HOMEPATH%\gOEYMkgs\EMQU.exe
- %HOMEPATH%\gOEYMkgs\aAwK.exe
- %HOMEPATH%\gOEYMkgs\FMYY.exe
- %HOMEPATH%\gOEYMkgs\PQwW.exe
- %HOMEPATH%\gOEYMkgs\hcUE.exe
- %HOMEPATH%\gOEYMkgs\iUQo.exe
- %HOMEPATH%\gOEYMkgs\MUIY.exe
- %HOMEPATH%\gOEYMkgs\cIYQ.exe
- %HOMEPATH%\gOEYMkgs\BIEQ.exe
- %HOMEPATH%\gOEYMkgs\LgwS.exe
- %HOMEPATH%\gOEYMkgs\OUko.exe
- %HOMEPATH%\gOEYMkgs\HAAM.exe
- %HOMEPATH%\gOEYMkgs\nsUu.exe
- %HOMEPATH%\gOEYMkgs\ykIk.exe
- %HOMEPATH%\gOEYMkgs\HQUY.exe
- %HOMEPATH%\gOEYMkgs\BUAc.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe
- %HOMEPATH%\gOEYMkgs\qoks.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\%USERNAME%.bmp.exe
- %HOMEPATH%\gOEYMkgs\AMkG.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\guest.bmp.exe
- %HOMEPATH%\gOEYMkgs\NwYC.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe
- %HOMEPATH%\gOEYMkgs\AAoE.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe
- %HOMEPATH%\gOEYMkgs\lYoW.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe
- %HOMEPATH%\gOEYMkgs\awoC.exe
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe
- %HOMEPATH%\gOEYMkgs\WYke.exe
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe
- %HOMEPATH%\gOEYMkgs\BkYU.exe
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\Winter.jpg.exe
- %HOMEPATH%\gOEYMkgs\dMYg.exe
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe
- %HOMEPATH%\gOEYMkgs\vkQa.exe
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe
- %HOMEPATH%\gOEYMkgs\FMkG.exe
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe
- %HOMEPATH%\gOEYMkgs\eQsc.exe
- %HOMEPATH%\gOEYMkgs\TwwQ.exe
- %HOMEPATH%\gOEYMkgs\LsUq.exe
- %HOMEPATH%\gOEYMkgs\WYwM.exe
- %HOMEPATH%\gOEYMkgs\gYkY.exe
- %HOMEPATH%\gOEYMkgs\HIYQ.exe
- %HOMEPATH%\gOEYMkgs\WQsO.exe
- %HOMEPATH%\gOEYMkgs\JUYi.exe
- %HOMEPATH%\gOEYMkgs\KQci.exe
- %HOMEPATH%\gOEYMkgs\cMko.exe
- %HOMEPATH%\gOEYMkgs\msAy.exe
- %HOMEPATH%\gOEYMkgs\jMcU.exe
- %HOMEPATH%\gOEYMkgs\FcoK.exe
- %HOMEPATH%\gOEYMkgs\igQQ.exe
- %HOMEPATH%\gOEYMkgs\EAYC.exe
- %HOMEPATH%\gOEYMkgs\yYwq.exe
- %HOMEPATH%\gOEYMkgs\lIwi.exe
- %HOMEPATH%\gOEYMkgs\vIwY.exe
- %HOMEPATH%\gOEYMkgs\EAYa.exe
- %HOMEPATH%\gOEYMkgs\ZIwC.exe
- %HOMEPATH%\gOEYMkgs\aMkK.exe
- %HOMEPATH%\gOEYMkgs\wwcC.exe
- %HOMEPATH%\gOEYMkgs\WAou.exe
- %HOMEPATH%\gOEYMkgs\uIgM.exe
- %HOMEPATH%\gOEYMkgs\kkgy.exe
- %HOMEPATH%\gOEYMkgs\VIge.exe
- %HOMEPATH%\gOEYMkgs\mwoe.exe
- %HOMEPATH%\gOEYMkgs\LkQK.exe
- %HOMEPATH%\gOEYMkgs\bcYe.exe
- %HOMEPATH%\gOEYMkgs\isEo.exe
- %HOMEPATH%\gOEYMkgs\IYMA.exe
- %HOMEPATH%\gOEYMkgs\Jcku.exe
- %HOMEPATH%\gOEYMkgs\IEYS.exe
- %HOMEPATH%\gOEYMkgs\pEgk.exe
- %HOMEPATH%\gOEYMkgs\UIoe.exe
- %HOMEPATH%\gOEYMkgs\rkoK.exe
- %HOMEPATH%\gOEYMkgs\eAga.exe
- %HOMEPATH%\gOEYMkgs\TQoK.exe
- %HOMEPATH%\gOEYMkgs\AUEo.exe
- %HOMEPATH%\gOEYMkgs\LEgG.exe
- %HOMEPATH%\gOEYMkgs\UUMK.exe
- %HOMEPATH%\gOEYMkgs\nwMO.exe
- %HOMEPATH%\gOEYMkgs\BYcy.exe
- %HOMEPATH%\gOEYMkgs\REoI.exe
- %HOMEPATH%\gOEYMkgs\kskG.exe
- %HOMEPATH%\gOEYMkgs\UIwQ.exe
- %HOMEPATH%\gOEYMkgs\JQUa.exe
- %HOMEPATH%\gOEYMkgs\Ywwg.exe
- %HOMEPATH%\gOEYMkgs\PAwW.exe
- %HOMEPATH%\gOEYMkgs\VAIa.exe
- %HOMEPATH%\gOEYMkgs\WYgi.exe
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP14\rp.log
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP14\RestorePointSize
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP15\rp.log
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP15\RestorePointSize
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP13\rp.log
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\RestorePointSize
- %HOMEPATH%\gOEYMkgs\ZYgy.exe
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP13\RestorePointSize
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP12\rp.log
- %HOMEPATH%\gOEYMkgs\UAkS.exe
- %HOMEPATH%\gOEYMkgs\HEMI.exe
- %HOMEPATH%\gOEYMkgs\DEEU.exe
- %HOMEPATH%\gOEYMkgs\XkMK.exe
- %HOMEPATH%\gOEYMkgs\cMwe.exe
- %HOMEPATH%\gOEYMkgs\lEoe.exe
- %HOMEPATH%\gOEYMkgs\Ucoq.exe
- %HOMEPATH%\gOEYMkgs\KsAA.exe
- %HOMEPATH%\gOEYMkgs\YkwW.exe
- %HOMEPATH%\gOEYMkgs\YwQm.exe
- %HOMEPATH%\gOEYMkgs\SMgE.exe
- %HOMEPATH%\gOEYMkgs\Lcsq.exe
- %HOMEPATH%\gOEYMkgs\nUQk.exe
- %HOMEPATH%\gOEYMkgs\jAMe.exe
- %HOMEPATH%\gOEYMkgs\xkQu.exe
- %HOMEPATH%\gOEYMkgs\BscK.exe
- %HOMEPATH%\gOEYMkgs\awcE.exe
- %HOMEPATH%\gOEYMkgs\lkAm.exe
- %HOMEPATH%\gOEYMkgs\ysAa.exe
- %HOMEPATH%\gOEYMkgs\toIK.exe
- %HOMEPATH%\gOEYMkgs\awoC.exe
- %HOMEPATH%\gOEYMkgs\AMkG.exe
- %HOMEPATH%\gOEYMkgs\eQsc.exe
- %HOMEPATH%\gOEYMkgs\vkQa.exe
- %HOMEPATH%\gOEYMkgs\BUAc.exe
- %HOMEPATH%\gOEYMkgs\NwYC.exe
- %HOMEPATH%\gOEYMkgs\AAoE.exe
- %HOMEPATH%\gOEYMkgs\qoks.exe
- %HOMEPATH%\gOEYMkgs\lYoW.exe
- %HOMEPATH%\gOEYMkgs\FMkG.exe
- %HOMEPATH%\gOEYMkgs\aAwK.exe
- %HOMEPATH%\gOEYMkgs\gQYy.exe
- %HOMEPATH%\gOEYMkgs\BYsm.exe
- %HOMEPATH%\gOEYMkgs\EMQU.exe
- %HOMEPATH%\gOEYMkgs\TEYY.exe
- %HOMEPATH%\gOEYMkgs\dMYg.exe
- %HOMEPATH%\gOEYMkgs\WYke.exe
- %HOMEPATH%\gOEYMkgs\mQYw.exe
- %HOMEPATH%\gOEYMkgs\BkYU.exe
- %HOMEPATH%\gOEYMkgs\YQYq.exe
- %HOMEPATH%\gOEYMkgs\ikEO.exe
- %HOMEPATH%\gOEYMkgs\cMAy.exe
- %HOMEPATH%\gOEYMkgs\isYi.exe
- %HOMEPATH%\gOEYMkgs\eokY.exe
- %HOMEPATH%\gOEYMkgs\TIUU.exe
- %HOMEPATH%\gOEYMkgs\NEgg.exe
- %HOMEPATH%\gOEYMkgs\akwm.exe
- %HOMEPATH%\gOEYMkgs\GsUK.exe
- %HOMEPATH%\gOEYMkgs\rsMu.exe
- %HOMEPATH%\gOEYMkgs\AIks.exe
- %HOMEPATH%\gOEYMkgs\qkEc.exe
- %HOMEPATH%\gOEYMkgs\EQAC.exe
- %TEMP%\uIEkcAgI.bat
- %HOMEPATH%\gOEYMkgs\cYYq.exe
- %HOMEPATH%\gOEYMkgs\xwUq.exe
- %HOMEPATH%\gOEYMkgs\vsIC.exe
- %HOMEPATH%\gOEYMkgs\bsEc.exe
- %HOMEPATH%\gOEYMkgs\xEIU.exe
- %HOMEPATH%\gOEYMkgs\rAoc.exe
- %HOMEPATH%\gOEYMkgs\aQEM.exe
- %HOMEPATH%\gOEYMkgs\WYks.exe
- %HOMEPATH%\gOEYMkgs\wAgc.exe
- %HOMEPATH%\gOEYMkgs\vgcm.exe
- %HOMEPATH%\gOEYMkgs\DsQE.exe
- %HOMEPATH%\gOEYMkgs\pYoE.exe
- %HOMEPATH%\gOEYMkgs\zgks.exe
- %HOMEPATH%\gOEYMkgs\twwM.exe
- %HOMEPATH%\gOEYMkgs\ZEYs.exe
- %HOMEPATH%\gOEYMkgs\boMc.exe
- %HOMEPATH%\gOEYMkgs\wskY.exe
- %HOMEPATH%\gOEYMkgs\XAgm.exe
- %HOMEPATH%\gOEYMkgs\hgkY.exe
- %HOMEPATH%\gOEYMkgs\JoMe.exe
- %HOMEPATH%\gOEYMkgs\LwUA.exe
- %HOMEPATH%\gOEYMkgs\igQa.exe
- %HOMEPATH%\gOEYMkgs\kwUI.exe
- %HOMEPATH%\gOEYMkgs\ycIY.exe
- %HOMEPATH%\gOEYMkgs\HwUy.exe
- %HOMEPATH%\gOEYMkgs\xIga.exe
- %HOMEPATH%\gOEYMkgs\mUck.exe
- %HOMEPATH%\gOEYMkgs\HAAM.exe
- %HOMEPATH%\gOEYMkgs\FMYY.exe
- %HOMEPATH%\gOEYMkgs\LgwS.exe
- %HOMEPATH%\gOEYMkgs\OUko.exe
- %HOMEPATH%\gOEYMkgs\jQwU.exe
- %HOMEPATH%\gOEYMkgs\pssm.exe
- %HOMEPATH%\gOEYMkgs\qcQA.exe
- %HOMEPATH%\gOEYMkgs\ogcs.exe
- %HOMEPATH%\gOEYMkgs\AkcC.exe
- %HOMEPATH%\gOEYMkgs\HQUY.exe
- %HOMEPATH%\gOEYMkgs\cIYQ.exe
- %HOMEPATH%\gOEYMkgs\BIEQ.exe
- %HOMEPATH%\gOEYMkgs\ZcIg.exe
- %HOMEPATH%\gOEYMkgs\MUIY.exe
- %HOMEPATH%\gOEYMkgs\PQwW.exe
- %HOMEPATH%\gOEYMkgs\nsUu.exe
- %HOMEPATH%\gOEYMkgs\ykIk.exe
- %HOMEPATH%\gOEYMkgs\hcUE.exe
- %HOMEPATH%\gOEYMkgs\iUQo.exe
- %HOMEPATH%\gOEYMkgs\HEMI.exe
- '74.##5.232.51':80
- http://google.com/ via 74.##5.232.51
- http:/// via 74.##5.232.51
- DNS ASK google.com
- ClassName: '' WindowName: 'SSIkQYgQ.exe'
- ClassName: '' WindowName: 'Microsoft Windows'
- ClassName: '' WindowName: 'lacMcYws.exe'