Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'lacMcYws.exe' = '%ALLUSERSPROFILE%\WuIEgAsU\lacMcYws.exe'
- [<HKLM>\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Userinit' = '<SYSTEM32>\userinit.exe,%ALLUSERSPROFILE%\WuIEgAsU\lacMcYws.exe,'
- [<HKLM>\SYSTEM\ControlSet001\Services\vwYgEQEb] 'ImagePath' = '%ALLUSERSPROFILE%\tuIMYcEM\ZgMYMIIE.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\vwYgEQEb] 'Start' = '00000002'
- <STUBS_DIR>\test.exe
- C:\Far2\Far.exe
- скрытых файлов
- расширений файлов
- Средство контроля пользовательских учетных записей (UAC)
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v Hidden /t REG_DWORD /d 2
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced /f /v HideFileExt /t REG_DWORD /d 1
- '%TEMP%\setup.exe'
- '<SYSTEM32>\reg.exe' add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /d 0 /t REG_DWORD /f
- '%ALLUSERSPROFILE%\WuIEgAsU\lacMcYws.exe'
- '%HOMEPATH%\gOEYMkgs\SSIkQYgQ.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\setup.exe
- '%ALLUSERSPROFILE%\tuIMYcEM\ZgMYMIIE.exe'
- <SYSTEM32>\cmd.exe
- %HOMEPATH%\gOEYMkgs\jUgA.exe
- %HOMEPATH%\gOEYMkgs\ooIC.exe
- %TEMP%\WER065f.dir00\ZgMYMIIE.exe.mdmp
- %HOMEPATH%\gOEYMkgs\gIUI.exe
- %HOMEPATH%\gOEYMkgs\loUS.exe
- %TEMP%\WER065f.dir00\ZgMYMIIE.exe.hdmp
- %HOMEPATH%\gOEYMkgs\eUAo.exe
- %HOMEPATH%\gOEYMkgs\rMsG.exe
- %HOMEPATH%\gOEYMkgs\RMgG.exe
- %HOMEPATH%\gOEYMkgs\bAYM.exe
- %HOMEPATH%\gOEYMkgs\YYIa.exe
- %HOMEPATH%\gOEYMkgs\xMwu.exe
- %HOMEPATH%\gOEYMkgs\eskO.exe
- %HOMEPATH%\gOEYMkgs\vMck.exe
- %HOMEPATH%\gOEYMkgs\GkEQ.exe
- %HOMEPATH%\gOEYMkgs\mYIM.exe
- %HOMEPATH%\gOEYMkgs\CEwg.exe
- %HOMEPATH%\gOEYMkgs\wgwi.exe
- %HOMEPATH%\gOEYMkgs\BIoq.exe
- %HOMEPATH%\gOEYMkgs\sIQq.exe
- %HOMEPATH%\gOEYMkgs\ikMw.exe
- %TEMP%\WER065f.dir00\manifest.txt
- %TEMP%\WER065f.dir00\appcompat.txt
- %HOMEPATH%\gOEYMkgs\Scoi.exe
- %HOMEPATH%\gOEYMkgs\DEEq.exe
- %HOMEPATH%\gOEYMkgs\egcC.exe
- %HOMEPATH%\gOEYMkgs\WgAw.exe
- %HOMEPATH%\gOEYMkgs\wIQa.exe
- %HOMEPATH%\gOEYMkgs\cAcm.exe
- %HOMEPATH%\gOEYMkgs\hoQE.exe
- %HOMEPATH%\gOEYMkgs\xcwi.exe
- %HOMEPATH%\gOEYMkgs\LIcE.exe
- %HOMEPATH%\gOEYMkgs\ksUI.exe
- %HOMEPATH%\gOEYMkgs\ocYY.exe
- %HOMEPATH%\gOEYMkgs\uQQO.exe
- %HOMEPATH%\gOEYMkgs\XQYQ.exe
- %HOMEPATH%\gOEYMkgs\bUgA.exe
- %HOMEPATH%\gOEYMkgs\DcYE.exe
- %HOMEPATH%\gOEYMkgs\IwEA.exe
- %HOMEPATH%\gOEYMkgs\YokW.exe
- %HOMEPATH%\gOEYMkgs\HoEg.exe
- %HOMEPATH%\gOEYMkgs\esMA.exe
- %HOMEPATH%\gOEYMkgs\AswE.exe
- %HOMEPATH%\gOEYMkgs\zokE.exe
- %HOMEPATH%\gOEYMkgs\Gksg.exe
- %HOMEPATH%\gOEYMkgs\KYkC.exe
- %HOMEPATH%\gOEYMkgs\QsYM.exe
- %HOMEPATH%\gOEYMkgs\scgO.exe
- %HOMEPATH%\gOEYMkgs\HMAo.exe
- %HOMEPATH%\gOEYMkgs\BAIK.exe
- %HOMEPATH%\gOEYMkgs\OsQc.exe
- %HOMEPATH%\gOEYMkgs\vQsU.exe
- %HOMEPATH%\gOEYMkgs\pcsc.exe
- %HOMEPATH%\gOEYMkgs\PMgQ.exe
- %HOMEPATH%\gOEYMkgs\JsIS.exe
- %HOMEPATH%\gOEYMkgs\QsgQ.exe
- %HOMEPATH%\gOEYMkgs\GgQK.exe
- %HOMEPATH%\gOEYMkgs\sEAi.exe
- %HOMEPATH%\gOEYMkgs\mUoa.exe
- %HOMEPATH%\gOEYMkgs\LUMc.exe
- %HOMEPATH%\gOEYMkgs\QgMs.exe
- %HOMEPATH%\gOEYMkgs\mEco.exe
- %HOMEPATH%\gOEYMkgs\EEoc.exe
- %HOMEPATH%\gOEYMkgs\xYUG.exe
- %HOMEPATH%\gOEYMkgs\psko.exe
- %TEMP%\WEReac9.dir00\ZgMYMIIE.exe.hdmp
- %TEMP%\WEReac9.dir00\ZgMYMIIE.exe.mdmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\fifo.log
- C:\Documents and Settings\LocalService\gOEYMkgs\SSIkQYgQ
- %TEMP%\WEReac9.dir00\manifest.txt
- %TEMP%\WEReac9.dir00\appcompat.txt
- %TEMP%\WER72f9.dir00\manifest.txt
- %HOMEPATH%\gOEYMkgs\UUcM.exe
- %HOMEPATH%\gOEYMkgs\poYS.exe
- %HOMEPATH%\gOEYMkgs\BMYK.exe
- %TEMP%\WER72f9.dir00\appcompat.txt
- %TEMP%\WER72f9.dir00\ZgMYMIIE.exe.hdmp
- %TEMP%\WER72f9.dir00\ZgMYMIIE.exe.mdmp
- %HOMEPATH%\gOEYMkgs\TcUg.exe
- %HOMEPATH%\gOEYMkgs\WUkU.exe
- %HOMEPATH%\gOEYMkgs\tcoQ.exe
- %HOMEPATH%\gOEYMkgs\gsEw.exe
- %HOMEPATH%\gOEYMkgs\ikYg.exe
- %HOMEPATH%\gOEYMkgs\DggW.exe
- %HOMEPATH%\gOEYMkgs\DUsE.exe
- %HOMEPATH%\gOEYMkgs\zUUu.exe
- %HOMEPATH%\gOEYMkgs\Vkkq.exe
- %HOMEPATH%\gOEYMkgs\pMYi.exe
- %HOMEPATH%\gOEYMkgs\XQMA.exe
- %HOMEPATH%\gOEYMkgs\OoAQ.exe
- %HOMEPATH%\gOEYMkgs\Ckgk.exe
- %HOMEPATH%\gOEYMkgs\RkEO.exe
- %HOMEPATH%\gOEYMkgs\wsMu.exe
- %HOMEPATH%\gOEYMkgs\ucsw.exe
- %HOMEPATH%\gOEYMkgs\wMIo.exe
- %HOMEPATH%\gOEYMkgs\CooA.exe
- %HOMEPATH%\gOEYMkgs\qAcm.exe
- %HOMEPATH%\gOEYMkgs\oEEi.exe
- %HOMEPATH%\gOEYMkgs\TkEQ.exe
- %HOMEPATH%\gOEYMkgs\tUIg.exe
- %HOMEPATH%\gOEYMkgs\GUMI.exe
- %HOMEPATH%\gOEYMkgs\TogS.exe
- %HOMEPATH%\gOEYMkgs\dsYI.exe
- %HOMEPATH%\gOEYMkgs\zwke.exe
- %HOMEPATH%\gOEYMkgs\MkYS.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe
- %HOMEPATH%\gOEYMkgs\ugUi.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe
- %HOMEPATH%\gOEYMkgs\ZIUm.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe
- %HOMEPATH%\gOEYMkgs\ZgcK.exe
- %HOMEPATH%\gOEYMkgs\ZUcM.exe
- %HOMEPATH%\gOEYMkgs\VwMQ.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe
- %HOMEPATH%\gOEYMkgs\KAEU.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe
- %HOMEPATH%\gOEYMkgs\RMQI.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe
- %HOMEPATH%\gOEYMkgs\coAK.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe
- %HOMEPATH%\gOEYMkgs\SwYa.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe
- %HOMEPATH%\gOEYMkgs\zgAw.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe
- %HOMEPATH%\gOEYMkgs\vMMo.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe
- %HOMEPATH%\gOEYMkgs\UcIA.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe
- %HOMEPATH%\gOEYMkgs\dYUk.exe
- %TEMP%\WER115f.dir00\manifest.txt
- %TEMP%\WER115f.dir00\appcompat.txt
- %TEMP%\WER115f.dir00\ZgMYMIIE.exe.hdmp
- %HOMEPATH%\gOEYMkgs\eUAY.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe
- %HOMEPATH%\gOEYMkgs\mkwS.exe
- %ALLUSERSPROFILE%\caQc.txt
- %HOMEPATH%\gOEYMkgs\SSIkQYgQ.exe
- %ALLUSERSPROFILE%\WuIEgAsU\lacMcYws
- %HOMEPATH%\gOEYMkgs\SSIkQYgQ
- %TEMP%\WER115f.dir00\ZgMYMIIE.exe.mdmp
- %ALLUSERSPROFILE%\tuIMYcEM\ZgMYMIIE.exe
- %ALLUSERSPROFILE%\WuIEgAsU\lacMcYws.exe
- %HOMEPATH%\gOEYMkgs\fooo.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe
- %HOMEPATH%\gOEYMkgs\EEkI.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe
- %HOMEPATH%\gOEYMkgs\GcIK.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe
- %HOMEPATH%\gOEYMkgs\xIYs.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe
- %HOMEPATH%\gOEYMkgs\EUgi.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe
- %HOMEPATH%\gOEYMkgs\MIYe.exe
- %HOMEPATH%\gOEYMkgs\IAIK.exe
- %HOMEPATH%\gOEYMkgs\QYMw.exe
- %HOMEPATH%\gOEYMkgs\VIwU.exe
- %HOMEPATH%\gOEYMkgs\TIki.exe
- %HOMEPATH%\gOEYMkgs\pYYS.exe
- %HOMEPATH%\gOEYMkgs\xEMi.exe
- %TEMP%\WER894f.dir00\manifest.txt
- %HOMEPATH%\gOEYMkgs\mUYs.exe
- %HOMEPATH%\gOEYMkgs\NwsW.exe
- %HOMEPATH%\gOEYMkgs\VEsw.exe
- %HOMEPATH%\gOEYMkgs\nQwg.exe
- %TEMP%\WER894f.dir00\appcompat.txt
- %HOMEPATH%\gOEYMkgs\PYYg.exe
- %HOMEPATH%\gOEYMkgs\rwAu.exe
- %HOMEPATH%\gOEYMkgs\QggS.exe
- %HOMEPATH%\gOEYMkgs\sUUU.exe
- %HOMEPATH%\gOEYMkgs\nUQc.exe
- %HOMEPATH%\gOEYMkgs\rQcA.exe
- %HOMEPATH%\gOEYMkgs\GMEK.exe
- %HOMEPATH%\gOEYMkgs\GMcQ.exe
- %HOMEPATH%\gOEYMkgs\jUsY.exe
- %HOMEPATH%\gOEYMkgs\mkwk.exe
- %HOMEPATH%\gOEYMkgs\zMMe.exe
- %HOMEPATH%\gOEYMkgs\uoEE.exe
- %HOMEPATH%\gOEYMkgs\iwUS.exe
- %HOMEPATH%\gOEYMkgs\xMEo.exe
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe
- %HOMEPATH%\gOEYMkgs\VAEg.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\%USERNAME%.bmp.exe
- %HOMEPATH%\gOEYMkgs\wQMY.exe
- %ALLUSERSPROFILE%\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe
- %HOMEPATH%\gOEYMkgs\jMkq.exe
- %HOMEPATH%\gOEYMkgs\PUkK.exe
- %HOMEPATH%\gOEYMkgs\IYcC.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe
- %HOMEPATH%\gOEYMkgs\rcgg.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\guest.bmp.exe
- %HOMEPATH%\gOEYMkgs\CosK.exe
- %ALLUSERSPROFILE%\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe
- %TEMP%\WER894f.dir00\ZgMYMIIE.exe.hdmp
- %HOMEPATH%\gOEYMkgs\ygYY.exe
- %TEMP%\WER894f.dir00\ZgMYMIIE.exe.mdmp
- %HOMEPATH%\gOEYMkgs\AUsO.exe
- %HOMEPATH%\gOEYMkgs\xMUy.exe
- %HOMEPATH%\gOEYMkgs\BAYA.exe
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\Winter.jpg.exe
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe
- %HOMEPATH%\gOEYMkgs\rMkm.exe
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe
- %HOMEPATH%\gOEYMkgs\MMIi.exe
- %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe
- %HOMEPATH%\gOEYMkgs\FgIE.exe
- %HOMEPATH%\gOEYMkgs\Scoi.exe
- %HOMEPATH%\gOEYMkgs\DEEq.exe
- %HOMEPATH%\gOEYMkgs\mYIM.exe
- %HOMEPATH%\gOEYMkgs\sIQq.exe
- %HOMEPATH%\gOEYMkgs\egcC.exe
- %HOMEPATH%\gOEYMkgs\loUS.exe
- %HOMEPATH%\gOEYMkgs\jUgA.exe
- %HOMEPATH%\gOEYMkgs\ikMw.exe
- %HOMEPATH%\gOEYMkgs\gIUI.exe
- %HOMEPATH%\gOEYMkgs\Vkkq.exe
- %HOMEPATH%\gOEYMkgs\pMYi.exe
- %HOMEPATH%\gOEYMkgs\Ckgk.exe
- %HOMEPATH%\gOEYMkgs\zUUu.exe
- %HOMEPATH%\gOEYMkgs\CEwg.exe
- %HOMEPATH%\gOEYMkgs\vMck.exe
- %HOMEPATH%\gOEYMkgs\GkEQ.exe
- %HOMEPATH%\gOEYMkgs\wgwi.exe
- %HOMEPATH%\gOEYMkgs\BIoq.exe
- %HOMEPATH%\gOEYMkgs\ooIC.exe
- %HOMEPATH%\gOEYMkgs\HoEg.exe
- %HOMEPATH%\gOEYMkgs\esMA.exe
- %HOMEPATH%\gOEYMkgs\Gksg.exe
- %HOMEPATH%\gOEYMkgs\YokW.exe
- %HOMEPATH%\gOEYMkgs\KYkC.exe
- %HOMEPATH%\gOEYMkgs\vQsU.exe
- %HOMEPATH%\gOEYMkgs\QsYM.exe
- %HOMEPATH%\gOEYMkgs\BAIK.exe
- %HOMEPATH%\gOEYMkgs\OsQc.exe
- %HOMEPATH%\gOEYMkgs\xMwu.exe
- %HOMEPATH%\gOEYMkgs\eskO.exe
- %HOMEPATH%\gOEYMkgs\eUAo.exe
- %HOMEPATH%\gOEYMkgs\YYIa.exe
- %HOMEPATH%\gOEYMkgs\rMsG.exe
- %HOMEPATH%\gOEYMkgs\AswE.exe
- %HOMEPATH%\gOEYMkgs\zokE.exe
- %HOMEPATH%\gOEYMkgs\RMgG.exe
- %HOMEPATH%\gOEYMkgs\bAYM.exe
- %HOMEPATH%\gOEYMkgs\OoAQ.exe
- %HOMEPATH%\gOEYMkgs\xYUG.exe
- %HOMEPATH%\gOEYMkgs\psko.exe
- %HOMEPATH%\gOEYMkgs\mUoa.exe
- %HOMEPATH%\gOEYMkgs\EEoc.exe
- %HOMEPATH%\gOEYMkgs\LUMc.exe
- %HOMEPATH%\gOEYMkgs\wMIo.exe
- %HOMEPATH%\gOEYMkgs\CooA.exe
- %HOMEPATH%\gOEYMkgs\QgMs.exe
- %HOMEPATH%\gOEYMkgs\mEco.exe
- %HOMEPATH%\gOEYMkgs\BMYK.exe
- %HOMEPATH%\gOEYMkgs\QsgQ.exe
- %HOMEPATH%\gOEYMkgs\UUcM.exe
- %HOMEPATH%\gOEYMkgs\poYS.exe
- %HOMEPATH%\gOEYMkgs\GgQK.exe
- %HOMEPATH%\gOEYMkgs\PMgQ.exe
- %HOMEPATH%\gOEYMkgs\JsIS.exe
- %HOMEPATH%\gOEYMkgs\sEAi.exe
- %HOMEPATH%\gOEYMkgs\pcsc.exe
- %HOMEPATH%\gOEYMkgs\qAcm.exe
- %HOMEPATH%\gOEYMkgs\ikYg.exe
- %HOMEPATH%\gOEYMkgs\DggW.exe
- %HOMEPATH%\gOEYMkgs\GUMI.exe
- %HOMEPATH%\gOEYMkgs\gsEw.exe
- %HOMEPATH%\gOEYMkgs\TcUg.exe
- %HOMEPATH%\gOEYMkgs\DUsE.exe
- %HOMEPATH%\gOEYMkgs\XQMA.exe
- %HOMEPATH%\gOEYMkgs\WUkU.exe
- %HOMEPATH%\gOEYMkgs\tcoQ.exe
- %HOMEPATH%\gOEYMkgs\ucsw.exe
- %HOMEPATH%\gOEYMkgs\oEEi.exe
- %HOMEPATH%\gOEYMkgs\RkEO.exe
- %HOMEPATH%\gOEYMkgs\wsMu.exe
- %HOMEPATH%\gOEYMkgs\TogS.exe
- %HOMEPATH%\gOEYMkgs\TkEQ.exe
- %HOMEPATH%\gOEYMkgs\tUIg.exe
- %HOMEPATH%\gOEYMkgs\dsYI.exe
- %HOMEPATH%\gOEYMkgs\zwke.exe
- %HOMEPATH%\gOEYMkgs\scgO.exe
- %HOMEPATH%\gOEYMkgs\VAEg.exe
- %HOMEPATH%\gOEYMkgs\PUkK.exe
- %HOMEPATH%\gOEYMkgs\wQMY.exe
- %HOMEPATH%\gOEYMkgs\jMkq.exe
- %HOMEPATH%\gOEYMkgs\CosK.exe
- %HOMEPATH%\gOEYMkgs\zgAw.exe
- %HOMEPATH%\gOEYMkgs\coAK.exe
- %HOMEPATH%\gOEYMkgs\IYcC.exe
- %HOMEPATH%\gOEYMkgs\rcgg.exe
- %HOMEPATH%\gOEYMkgs\xMUy.exe
- %HOMEPATH%\gOEYMkgs\BAYA.exe
- %HOMEPATH%\gOEYMkgs\VEsw.exe
- %HOMEPATH%\gOEYMkgs\AUsO.exe
- %HOMEPATH%\gOEYMkgs\ygYY.exe
- %HOMEPATH%\gOEYMkgs\FgIE.exe
- %HOMEPATH%\gOEYMkgs\rMkm.exe
- %TEMP%\hAQIIwAc.bat
- %HOMEPATH%\gOEYMkgs\MMIi.exe
- %HOMEPATH%\gOEYMkgs\SwYa.exe
- %HOMEPATH%\gOEYMkgs\fooo.exe
- %HOMEPATH%\gOEYMkgs\EEkI.exe
- %HOMEPATH%\gOEYMkgs\KAEU.exe
- %HOMEPATH%\gOEYMkgs\GcIK.exe
- %HOMEPATH%\gOEYMkgs\EUgi.exe
- %HOMEPATH%\gOEYMkgs\eUAY.exe
- %HOMEPATH%\gOEYMkgs\mkwS.exe
- %HOMEPATH%\gOEYMkgs\MIYe.exe
- %HOMEPATH%\gOEYMkgs\xIYs.exe
- %HOMEPATH%\gOEYMkgs\vMMo.exe
- %HOMEPATH%\gOEYMkgs\ZIUm.exe
- %HOMEPATH%\gOEYMkgs\UcIA.exe
- %HOMEPATH%\gOEYMkgs\dYUk.exe
- %HOMEPATH%\gOEYMkgs\ZgcK.exe
- %HOMEPATH%\gOEYMkgs\RMQI.exe
- %HOMEPATH%\gOEYMkgs\VwMQ.exe
- %HOMEPATH%\gOEYMkgs\ugUi.exe
- %HOMEPATH%\gOEYMkgs\ZUcM.exe
- %HOMEPATH%\gOEYMkgs\NwsW.exe
- %HOMEPATH%\gOEYMkgs\ocYY.exe
- %HOMEPATH%\gOEYMkgs\uQQO.exe
- %HOMEPATH%\gOEYMkgs\DcYE.exe
- %HOMEPATH%\gOEYMkgs\IwEA.exe
- %HOMEPATH%\gOEYMkgs\XQYQ.exe
- %HOMEPATH%\gOEYMkgs\rQcA.exe
- %HOMEPATH%\gOEYMkgs\GMEK.exe
- %HOMEPATH%\gOEYMkgs\MkYS.exe
- %HOMEPATH%\gOEYMkgs\nUQc.exe
- %HOMEPATH%\gOEYMkgs\xcwi.exe
- %HOMEPATH%\gOEYMkgs\LIcE.exe
- %HOMEPATH%\gOEYMkgs\HMAo.exe
- %HOMEPATH%\gOEYMkgs\hoQE.exe
- %HOMEPATH%\gOEYMkgs\WgAw.exe
- %HOMEPATH%\gOEYMkgs\ksUI.exe
- %HOMEPATH%\gOEYMkgs\bUgA.exe
- %HOMEPATH%\gOEYMkgs\wIQa.exe
- %HOMEPATH%\gOEYMkgs\cAcm.exe
- %HOMEPATH%\gOEYMkgs\rwAu.exe
- %HOMEPATH%\gOEYMkgs\xEMi.exe
- %HOMEPATH%\gOEYMkgs\IAIK.exe
- %HOMEPATH%\gOEYMkgs\TIki.exe
- %HOMEPATH%\gOEYMkgs\pYYS.exe
- %HOMEPATH%\gOEYMkgs\QYMw.exe
- %HOMEPATH%\gOEYMkgs\PYYg.exe
- %HOMEPATH%\gOEYMkgs\mUYs.exe
- %HOMEPATH%\gOEYMkgs\VIwU.exe
- %HOMEPATH%\gOEYMkgs\nQwg.exe
- %HOMEPATH%\gOEYMkgs\GMcQ.exe
- %HOMEPATH%\gOEYMkgs\uoEE.exe
- %HOMEPATH%\gOEYMkgs\QggS.exe
- %HOMEPATH%\gOEYMkgs\sUUU.exe
- %HOMEPATH%\gOEYMkgs\iwUS.exe
- %HOMEPATH%\gOEYMkgs\mkwk.exe
- %HOMEPATH%\gOEYMkgs\zMMe.exe
- %HOMEPATH%\gOEYMkgs\xMEo.exe
- %HOMEPATH%\gOEYMkgs\jUsY.exe
- '74.##5.232.51':443
- 'ap#.###coincharts.com':443
- '74.##5.232.51':80
- http://google.com/ via 74.##5.232.51
- http:/// via 74.##5.232.51
- DNS ASK ma##.google.com
- DNS ASK ap#.###coincharts.com
- DNS ASK google.com
- ClassName: '' WindowName: 'Run'
- ClassName: 'ConsoleWindowClass' WindowName: ''
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: '' WindowName: 'Open'
- ClassName: 'WorkerW' WindowName: ''
- ClassName: 'DV2ControlHost' WindowName: ''
- ClassName: 'BUTTON' WindowName: 'START'
- ClassName: '' WindowName: 'SSIkQYgQ.exe'
- ClassName: '' WindowName: 'Microsoft Windows'
- ClassName: '' WindowName: 'lacMcYws.exe'
- ClassName: '' WindowName: 'xSMgIcIg'
- ClassName: '' WindowName: 'Windows Internet Explorer'
- ClassName: '' WindowName: 'Open File'
- ClassName: 'Shell_TrayWnd' WindowName: ''