Поддержка
Круглосуточная поддержка

Позвоните

Бесплатно по России:
8-800-333-79-32

ЧаВо | Форум

Ваши запросы

  • Все: -
  • Незакрытые: -
  • Последний: -

Позвоните

Бесплатно по России:
8-800-333-79-32

Свяжитесь с нами Незакрытые запросы: 

Профиль

Профиль

Trojan.DownLoader8.16084

Добавлен в вирусную базу Dr.Web: 2013-03-10

Описание добавлено:

Техническая информация

Для обеспечения автозапуска и распространения:
Модифицирует следующие ключи реестра:
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Runservices] 'services' = '%WINDIR%\services.exe'
  • [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Run' = '%WINDIR%\services.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservices] 'services' = '%WINDIR%\services.exe'
  • [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'services' = '%WINDIR%\services.exe'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'services' = '%WINDIR%\services.exe'
Создает или изменяет следующие файлы:
  • %HOMEPATH%\Start Menu\Programs\Startup\oohinwu.exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\Startup\yunrife.exe
Вредоносные функции:
Создает и запускает на исполнение:
  • %WINDIR%\services.exe
Изменения в файловой системе:
Создает следующие файлы:
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\App_Code\sigxeang.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\App_Data\rishinyi921.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\AppConfig\wuyio231.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\AppConfig\App_LocalResources\yyhyinyi.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\App_GlobalResources\uanshih.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Providers\ziauasi.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Providers\App_LocalResources\siyunss.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\App_LocalResources\xssciuang.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Images\angeyqyu.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\nshiuan574.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\chrome\uangxeng.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\SQL\EN\ensitljd780.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\ongiongj.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\defaults\xubckiongong922.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\1033\shiiongttp252.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\cikiong.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\defaults\preferences\vaenshi340.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\iancbjveang.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\Config\Browsers\uangingdhuq.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\MOF\oszyuzhi.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Security\Wizard\App_LocalResources\yitvamiang986.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\Config\iongpzfdkueng9.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\MSBuild\wuyuncn.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\ziyteyu.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\chinhang754.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\MUI\uicvangiong358.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\MUI\0409\enlixizhi487.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Security\Permissions\xubjyunuen.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Security\Permissions\App_LocalResources\chiebzi.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Security\shiianlzbn336.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Security\App_LocalResources\ianowuiong337.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Security\Roles\riyri.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Security\Users\App_LocalResources\ingyiwebvh.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Security\Wizard\oongen591.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Security\Roles\App_LocalResources\euangian.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\ASP.NETWebAdminFiles\Security\Users\ziiangow724.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\MSBuild\shiyzvong733.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\MUI\anbgci406.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\CONFIG\zkianueng287.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\CONFIG\Browsers\angiangb.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\MUI\0409\uansidqnoh165.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\uensiqira.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\ziangksdjx621.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RedistList\inencvnzi.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\SubsetList\shiongbufl300.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Permissions\App_LocalResources\yiuanugj.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\zinvhoyun706.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\App_LocalResources\dviongyi487.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Permissions\sihhri.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Roles\App_LocalResources\zisies41.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Wizard\ucqblanchi436.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Wizard\App_LocalResources\yimiuhri.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Users\invpyiong371.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\Users\App_LocalResources\iongyjing18.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\tgynmziiong.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\1033\engzplfuian.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\WPF\en-US\eequangian.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\WPF\XamlViewer\inuangpxv156.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\enjnlisi802.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\MSBuild\wuyyoang.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\SQL\siiangkxdg477.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\Logs\kdtrichi510.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.5\MOF\xyunian944.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\iongcvtuen812.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\MUI\ianffsong420.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 x86\wuyuerftd570.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 x86\Logs\angsgfben.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\MUI\0409\quyuang478.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\SQL\EN\iongange760.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\WPF\zixhin.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\yunenx.exe
  • %WINDIR%\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\SQL\pymrmciwu826.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1025\riyud.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1055\ongaqmetiong622.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\2052\qmbqyonguan.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1049\yizipkxd.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1053\uangmeuueng.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\2070\knuengci.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\Extended\okgcensi.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\Graphics\ukwanuen.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\3076\ionguant927.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\3082\uengzhim979.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1040\wuguuang.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1041\iongchi.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1037\ensdsi18.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1038\enxjuan584.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1042\inguanykem.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1045\shiuanholvc416.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1046\airiing721.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1043\ingcihtmx488.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1044\mnsyusi239.exe
  • %WINDIR%\mui\enpen.exe
  • %WINDIR%\ocx\iongziawo189.exe
  • %WINDIR%\msapps\mgcuengong.exe
  • %WINDIR%\msapps\msinfo\kuuingang78.exe
  • %WINDIR%\Offline Web Pages\cfgsiuan.exe
  • %WINDIR%\pchealth\ERRORREP\QHEADLES\shioing713.exe
  • %WINDIR%\pchealth\ERRORREP\QSIGNOFF\siwawu.exe
  • %WINDIR%\pchealth\ianhrjyun.exe
  • %WINDIR%\pchealth\ERRORREP\yunbfvan.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\Temporary ASP.NET Files\angyunvylp.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\WPF\zhisen.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SQL\kbqoiangang10.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SQL\en\dbwenging.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\WPF\en-US\dimangci.exe
  • %WINDIR%\msagent\chars\cixin341.exe
  • %WINDIR%\msagent\intl\dvuanchi356.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\WPF\Fonts\uyieng.exe
  • %WINDIR%\msagent\ueningjowro508.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1041\dtsisi.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1042\wusiy.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1038\fanuang.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1040\fiongiang3.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1043\pokinchi600.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1046\vgkbechiin.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1049\yunwegtqyun224.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1044\iongyuvb.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1045\yxcgwongiang.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1030\yubthyuzhi903.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1031\uangenitqyi.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1028\ongangd625.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1029\eminyi588.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1032\shiuenglxl.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1036\uanrilj.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1037\anfhiukuan679.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1033\zhiuangk.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1035\hmcjciuan180.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1029\jkfcieng98.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1030\uhqjwusi266.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1025\yunuanermv.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1028\shienvzdvm.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1031\inguenglf637.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1035\ddangiang.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1036\shicxlcpuang879.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1032\ciuangq.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\1033\riianfmxle.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\2052\kdchiuan467.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\2070\mxugiyunyi.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1053\yiiangw490.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\1055\enqci525.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\3076\shnuhanyi167.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Graphics\egvuangzhi.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\uenvebzhi784.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\3082\wvkxiiansi.exe
  • %WINDIR%\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Client\chimkuan.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Security\uanindhuv791.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.WasHosting\uencissyw753.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.WasHosting\v4.0_4.0.0.0__b77a5c561934e089\uenltwtfuan703.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.ServiceMoniker40\manging.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.ServiceMoniker40\v4.0_4.0.0.0__b77a5c561934e089\ziuanqyyg.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Web\uenvyu.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\uangtkwing.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Speech\iangzhifnj.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Web\v4.0_4.0.0.0__31bf3856ad364e35\uenggci.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\yiuanut828.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\v4.0_4.0.0.0__31bf3856ad364e35\anxci145.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\inuengxhu.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activation\v4.0_4.0.0.0__31bf3856ad364e35\yujzkan.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activities\iangingckcx.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\saujaingyi88.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\yushihmu712.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Routing\v4.0_4.0.0.0__31bf3856ad364e35\wuuenfudsb.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\engjtzyi650.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Discovery\v4.0_4.0.0.0__31bf3856ad364e35\ongangnvnfq.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.DynamicData.Design\tjnemwuuan16.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.DynamicData.Design\v4.0_4.0.0.0__31bf3856ad364e35\szianwu191.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.DynamicData\ahnomuaneng.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.DynamicData\v4.0_4.0.0.0__31bf3856ad364e35\childcri708.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.Entity\dwuengwu272.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.Entity.Design\v4.0_4.0.0.0__b77a5c561934e089\wyuanyu435.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\xuaiongan.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.Entity\v4.0_4.0.0.0__b77a5c561934e089\mcvianiang691.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.Entity.Design\yuuangcqpca30.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.Abstractions\v4.0_4.0.0.0__31bf3856ad364e35\uengrib.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\qbgrfuenging.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\uqmkazhishi266.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.Abstractions\fxfriian570.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.ApplicationServices\v4.0_4.0.0.0__31bf3856ad364e35\ejruriin311.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.DataVisualization.Design\uansixanfi.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.DataVisualization.Design\v4.0_4.0.0.0__31bf3856ad364e35\engyicclk.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.DataVisualization\dbyuanuang144.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\krianan813.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Management\uengjeng.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\yuanowzok27.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\zikxmxtyi.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.IO.Log\v4.0_4.0.0.0__b03f5f7f11d50a3a\cpuanuen.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\ianglibkueng683.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\v4.0_4.0.0.0__b03f5f7f11d50a3a\wuongugxs609.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Net\cvukuanri421.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Management.Instrumentation\v4.0_4.0.0.0__b77a5c561934e089\iongnnjiang.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Messaging\ravoongueng.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Drawing.Design\v4.0_4.0.0.0__b03f5f7f11d50a3a\yibtsi.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\znueniang.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\ciuangx793.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Drawing.Design\uanuangwyrqh32.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\uanfikorchi.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\uanianakba.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel.Selectors\v4.0_4.0.0.0__b77a5c561934e089\siuenutpy.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\ankuclyu333.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\enwub.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\hycvziiong.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\inkian.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\ongzeepueng.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization\v4.0_4.0.0.0__b77a5c561934e089\cianfq.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Security\ajqrazhieng973.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\engolnqashi363.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Activation\ingzigfn163.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\yuuangivk.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\uanyiifhdv.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\shiuanz32.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Caching\yusitv.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Net\v4.0_4.0.0.0__b03f5f7f11d50a3a\mzyschiong.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\uanetong322.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Caching\v4.0_4.0.0.0__b03f5f7f11d50a3a\uengingb.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\uanguengnz.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\chixrzhi781.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\inzigye.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\zhiiongruu786.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\iangwuc.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\v4.0_4.0.0.0__31bf3856ad364e35\yiuanhz.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\XamlBuildTask\gjwuengueng.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\v4.0_4.0.0.0__31bf3856ad364e35\ciingriubr851.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\WindowsFormsIntegration\uanciquwhv.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\XamlBuildTask\v4.0_4.0.0.0__31bf3856ad364e35\sidodxcyi98.exe
  • %WINDIR%\Microsoft.NET\Framework\v1.1.4322\zhiuanzails208.exe
  • %WINDIR%\Microsoft.NET\Framework\v1.1.4322\1033\zixrnyi.exe
  • %WINDIR%\Microsoft.NET\Framework\uengyus.exe
  • %WINDIR%\Microsoft.NET\Framework\v1.0.3705\rifgzhi442.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\jkduenueng875.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClientsideProviders\v4.0_4.0.0.0__31bf3856ad364e35\riangiwg156.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\ddnkauenen.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\UIAutomationClient\v4.0_4.0.0.0__31bf3856ad364e35\kesyziyi357.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\shishiepc520.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\ningzhi.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\WindowsBase\htuansi321.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\dvanguan585.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\ancuan705.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_Code\ajtfcongzi.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_Data\wucgxzfzhi274.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\AppConfig\ongdzwu807.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\AppConfig\App_LocalResources\ccsien.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_GlobalResources\ciwugdnt277.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Providers\cqengiong.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Providers\App_LocalResources\xzcchiyun474.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\App_LocalResources\aninxiv721.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Images\chiwulrf630.exe
  • %WINDIR%\Microsoft.NET\Framework\v1.1.4322\MUI\zhizzan933.exe
  • %WINDIR%\Microsoft.NET\Framework\v1.1.4322\MUI\0409\uangukian.exe
  • %WINDIR%\Microsoft.NET\Framework\v1.1.4322\ASP.NETClientFiles\engmtqryun41.exe
  • %WINDIR%\Microsoft.NET\Framework\v1.1.4322\CONFIG\cpianin595.exe
  • %WINDIR%\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\chilcgwu585.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\1033\ianhxyi.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\aenguan.exe
  • %WINDIR%\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\Bind Logs\ysminuan407.exe
  • %WINDIR%\Microsoft.NET\Framework\v2.0.50727\ionginpb664.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\dogcuanci.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\ianinttct600.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\v4.0_4.0.0.0__b03f5f7f11d50a3a\enziddspx978.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\ianssschi850.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\enxien.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\zidndtin211.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Input.Manipulations\v4.0_4.0.0.0__b77a5c561934e089\shizhiqton.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization.Design\odylenchi.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization.Design\v4.0_4.0.0.0__31bf3856ad364e35\yunuanyrl320.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.Mobile\jeneng.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.Mobile\v4.0_4.0.0.0__b03f5f7f11d50a3a\zhiuenxlc.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions.Design\yunyfqhazi509.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions.Design\v4.0_4.0.0.0__31bf3856ad364e35\engeyvoci264.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.RegularExpressions\hcbyiin988.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.Routing\v4.0_4.0.0.0__31bf3856ad364e35\engiangiwn.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.Services\zichinrt.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.RegularExpressions\v4.0_4.0.0.0__b03f5f7f11d50a3a\iuinwu.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Web.Routing\clbxuanzhi900.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\v4.0_4.0.0.0__b77a5c561934e089\eezenzi.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Xaml.Hosting\xngyuniong.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.WorkflowServices\v4.0_4.0.0.0__31bf3856ad364e35\cbianan.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Xaml\uangkuzi723.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Xaml.Hosting\v4.0_4.0.0.0__31bf3856ad364e35\ejvsvyushi.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\cqiangzhi.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\iannan.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Xml\riingdb.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\zhiwlqreeng.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.Activities\anguanyn.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.Activities\v4.0_4.0.0.0__31bf3856ad364e35\jczzeenin.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\yvvzuanong.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Presentation\v4.0_4.0.0.0__b77a5c561934e089\angajmluen569.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.ComponentModel\uengyuqmw143.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.Runtime\v4.0_4.0.0.0__31bf3856ad364e35\cibci.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.WorkflowServices\wuangn582.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.ComponentModel\v4.0_4.0.0.0__31bf3856ad364e35\uangjltidueng332.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Workflow.Runtime\agluwianri477.exe
  • %WINDIR%\pchealth\helpctr\anguzi.exe
  • <SYSTEM32>\oobe\html\oemhw\zhiangscjur.exe
  • <SYSTEM32>\oobe\html\oemreg\angtjnhzhi.exe
  • <SYSTEM32>\oobe\html\mouse\images\inganuklul.exe
  • <SYSTEM32>\oobe\html\oemcust\iangzhij741.exe
  • <SYSTEM32>\oobe\html\sconnect\vyianen.exe
  • <SYSTEM32>\oobe\isperror\uengydbpcchi.exe
  • <SYSTEM32>\oobe\regerror\uenyudwes823.exe
  • <SYSTEM32>\oobe\icserror\zhivwyen.exe
  • <SYSTEM32>\oobe\images\mxiongzhi.exe
  • <SYSTEM32>\oobe\error\iangricsu539.exe
  • <SYSTEM32>\oobe\html\uenluan572.exe
  • <SYSTEM32>\oobe\sinftrtyu743.exe
  • <SYSTEM32>\oobe\actsetup\xpjcqonguan.exe
  • <SYSTEM32>\oobe\html\dslmain\gtbangin785.exe
  • <SYSTEM32>\oobe\html\isptype\riyunc.exe
  • <SYSTEM32>\oobe\html\mouse\angdkjtan747.exe
  • <SYSTEM32>\oobe\html\iconnect\cidin.exe
  • <SYSTEM32>\oobe\html\ispsgnup\pnruangan.exe
  • <SYSTEM32>\spool\PRINTERS\engxaagang832.exe
  • <SYSTEM32>\spool\prtprocs\ebzizi209.exe
  • <SYSTEM32>\spool\drivers\w32x86\ingkwqlshi.exe
  • <SYSTEM32>\spool\drivers\w32x86\3\yuyunzqn.exe
  • <SYSTEM32>\spool\prtprocs\w32x86\cinxiloing.exe
  • <SYSTEM32>\spool\XPSEP\amd64\ofuanong.exe
  • <SYSTEM32>\spool\XPSEP\amd64\amd64\wucsnkpzi.exe
  • <SYSTEM32>\spool\prtprocs\x64\anicvwriang.exe
  • <SYSTEM32>\spool\XPSEP\jomtrriueng.exe
  • <SYSTEM32>\ras\cciiong590.exe
  • <SYSTEM32>\Restore\ingongqfp443.exe
  • <SYSTEM32>\oobe\sample\zhimvyong.exe
  • <SYSTEM32>\oobe\setup\shiiangdfflk569.exe
  • <SYSTEM32>\Setup\ianinnp146.exe
  • <SYSTEM32>\spool\drivers\siuengammuq.exe
  • <SYSTEM32>\spool\drivers\color\jrjshiwu.exe
  • <SYSTEM32>\ShellExt\ianslyxueng543.exe
  • <SYSTEM32>\spool\inwuct.exe
  • <SYSTEM32>\mui\0412\yunurouen.exe
  • <SYSTEM32>\mui\0413\pkoacinzhi.exe
  • <SYSTEM32>\mui\0410\wurpmnyun.exe
  • <SYSTEM32>\mui\0411\uanwyi.exe
  • <SYSTEM32>\mui\0414\rizhifv.exe
  • <SYSTEM32>\mui\0418\faasiyu.exe
  • <SYSTEM32>\mui\0419\zhiuanfxxv.exe
  • <SYSTEM32>\mui\0415\ziwuqcga966.exe
  • <SYSTEM32>\mui\0416\kuengin28.exe
  • <SYSTEM32>\mui\0407\uanengyrj.exe
  • <SYSTEM32>\mui\0408\ongzskseng150.exe
  • <SYSTEM32>\mui\0405\bweangiang.exe
  • <SYSTEM32>\mui\0406\wfqtjiangiang.exe
  • <SYSTEM32>\mui\0409\yirieeinh.exe
  • <SYSTEM32>\mui\040D\uenzhi.exe
  • <SYSTEM32>\mui\040e\eningx.exe
  • <SYSTEM32>\mui\040b\ianvuen.exe
  • <SYSTEM32>\mui\040C\ingwqqan.exe
  • <SYSTEM32>\mui\042d\uanguensxdbr423.exe
  • <SYSTEM32>\mui\0804\uendzpmyun.exe
  • <SYSTEM32>\mui\0427\vxfnchiang968.exe
  • <SYSTEM32>\mui\042a\angruuen414.exe
  • <SYSTEM32>\mui\0816\iongnzlagchi.exe
  • <SYSTEM32>\mui\dispspec\prhxuingian274.exe
  • <SYSTEM32>\npp\ttechisi.exe
  • <SYSTEM32>\mui\081a\iandhaviang.exe
  • <SYSTEM32>\mui\0C0A\riyawwjian.exe
  • <SYSTEM32>\mui\041D\ojyueng744.exe
  • <SYSTEM32>\mui\041e\ziingi599.exe
  • <SYSTEM32>\mui\041a\wnuengan.exe
  • <SYSTEM32>\mui\041b\zhiingaya692.exe
  • <SYSTEM32>\mui\041f\engownyun384.exe
  • <SYSTEM32>\mui\0425\ongmkdkri757.exe
  • <SYSTEM32>\mui\0426\uengfwci43.exe
  • <SYSTEM32>\mui\0422\ingochi868.exe
  • <SYSTEM32>\mui\0424\yinwu980.exe
  • <SYSTEM32>\spool\XPSEP\i386\anenggowc839.exe
  • %WINDIR%\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\uanguengw.exe
  • %WINDIR%\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\wuuangw.exe
  • %WINDIR%\WinSxS\Policies\x86_policy.9.0.Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_x-ww_4ee8bb30\inyunfy.exe
  • %WINDIR%\WinSxS\Policies\x86_policy.9.0.Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_x-ww_6ad67377\zhiongqi449.exe
  • %WINDIR%\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\yizuen868.exe
  • %WINDIR%\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\aianan607.exe
  • %WINDIR%\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\lhrgawusi.exe
  • %WINDIR%\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\zhiingihfcx278.exe
  • %WINDIR%\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\shiangg.exe
  • %WINDIR%\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773\cvjiniong26.exe
  • %WINDIR%\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_x-ww_caeee150\jlxiangsi750.exe
  • %WINDIR%\WinSxS\Policies\x86_policy.7.0.Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_x-ww_a317e4b3\ciongqep629.exe
  • %WINDIR%\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_x-ww_5f0bbcff\shiintbs235.exe
  • %WINDIR%\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_x-ww_0f75c32e\inuane.exe
  • %WINDIR%\WinSxS\Policies\x86_policy.9.0.Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_x-ww_b7353f75\qachishi120.exe
  • %WINDIR%\WinSxS\Policies\x86_policy.9.0.Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_x-ww_b8438ace\wuuanbhk.exe
  • %WINDIR%\WinSxS\Policies\x86_policy.8.0.Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_x-ww_7d81c9f9\xaxruanyun341.exe
  • %WINDIR%\WinSxS\Policies\x86_policy.9.0.Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_x-ww_9e7eb501\ianyunegqy780.exe
  • %WINDIR%\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.0.0_x-ww_8d353f13\ciangykleq.exe
  • %WINDIR%\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\smqxgyien363.exe
  • %WINDIR%\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a\duanuan.exe
  • %WINDIR%\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_b2505ed9\gggcuanan.exe
  • %WINDIR%\WinSxS\x86_Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_5.2.2.3_x-ww_468466a7\vkdzizhi180.exe
  • %WINDIR%\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\uangenzkhno802.exe
  • %WINDIR%\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_4.0.0.0_x-ww_29b51492\rihcqain726.exe
  • %WINDIR%\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\fznaiuangshi.exe
  • %WINDIR%\WinSxS\x86_Microsoft.Windows.Networking.RtcRes_6595b64144ccf1df_5.2.2.3_en_16a24bc0\wiongueng.exe
  • %WINDIR%\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\chikqdrmyun208.exe
  • %WINDIR%\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\yunlfayi.exe
  • %WINDIR%\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\ninuang684.exe
  • %WINDIR%\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\suengiong.exe
  • %WINDIR%\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\rzhgozhishi124.exe
  • %WINDIR%\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\ziwgujlci.exe
  • %WINDIR%\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\nswqciyun595.exe
  • %WINDIR%\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\ingyufrl.exe
  • %WINDIR%\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\wuohvzci569.exe
  • <SYSTEM32>\wbem\Repository\ionguenguiig.exe
  • <SYSTEM32>\wbem\Repository\FS\nlyiangci993.exe
  • %WINDIR%\Temp\tmp1.tmp
  • <SYSTEM32>\wbem\Performance\zhixkbxiyu604.exe
  • <SYSTEM32>\wbem\snmp\anchidqp798.exe
  • <SYSTEM32>\xircom\envfubyun.exe
  • <SYSTEM32>\XPSViewer\envxxin312.exe
  • <SYSTEM32>\wbem\xml\iongqdnuan325.exe
  • <SYSTEM32>\wins\juanzhi229.exe
  • <SYSTEM32>\usmt\zhiziey.exe
  • <SYSTEM32>\wbem\ziuenumuxb.exe
  • <SYSTEM32>\spool\XPSEP\i386\i386\uanyuna.exe
  • <SYSTEM32>\URTTEMP\ciuanpbbdf583.exe
  • <SYSTEM32>\wbem\AutoRecover\siongri.exe
  • <SYSTEM32>\wbem\mof\bad\nyuueng796.exe
  • <SYSTEM32>\wbem\mof\good\uxkfinging26.exe
  • <SYSTEM32>\wbem\Logs\tzhiri764.exe
  • <SYSTEM32>\wbem\mof\ianysi.exe
  • %WINDIR%\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5\eniangyzss51.exe
  • %WINDIR%\WinSxS\Policies\rikazi147.exe
  • %WINDIR%\WinSxS\Manifests\uangheng478.exe
  • %WINDIR%\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\bjzxmenging765.exe
  • %WINDIR%\WinSxS\Policies\x86_policy.1.0.Microsoft.Windows.GdiPlus_6595b64144ccf1df_x-ww_4e8510ac\uenanq.exe
  • %WINDIR%\WinSxS\Policies\x86_policy.5.2.Microsoft.Windows.Networking.Rtcdll_6595b64144ccf1df_x-ww_c7b7206f\hosiueng271.exe
  • %WINDIR%\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\ingkong184.exe
  • %WINDIR%\WinSxS\Policies\x86_policy.5.1.Microsoft.Windows.SystemCompatible_6595b64144ccf1df_x-ww_a0111510\ionggjiiong379.exe
  • %WINDIR%\WinSxS\Policies\x86_policy.5.2.Microsoft.Windows.Networking.Dxmrtp_6595b64144ccf1df_x-ww_362e60dd\rmnzeiangshi366.exe
  • %WINDIR%\twain_32\afatyongci.exe
  • %WINDIR%\Web\vraxienshi.exe
  • <SYSTEM32>\XPSViewer\en-US\yunsazuen817.exe
  • %WINDIR%\Temp\gtbongshi791.exe
  • %WINDIR%\Web\printers\annblmxiong.exe
  • %WINDIR%\WinSxS\khyiong.exe
  • %WINDIR%\WinSxS\InstallTemp\oshiyu321.exe
  • %WINDIR%\Web\printers\images\enrimro.exe
  • %WINDIR%\Web\Wallpaper\chihoneng.exe
  • <SYSTEM32>\mui\0404\angchiwwpa840.exe
  • %WINDIR%\pchealth\helpctr\System_OEM\ciwtzchi.exe
  • %WINDIR%\pchealth\helpctr\Temp\qydsyuniong.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\47x24pie\sryunuan.exe
  • %WINDIR%\pchealth\helpctr\System\UpdateCtr\hanshi759.exe
  • %WINDIR%\pchealth\helpctr\Vendors\ziuenga.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\ciongcmkh785.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Css\uanixing.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\tbmrwwuuang.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\anvhoshi676.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\engzhigvm.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Common\ingsihpv641.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Css\yuezi223.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\ridzrdyi329.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Interaction\Server\ineszi76.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\siyiptcd.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\graphics\33x16pie\siiongazqmh.exe
  • %WINDIR%\pchealth\helpctr\System\scripts\uangangddbh429.exe
  • %WINDIR%\pchealth\helpctr\System\sysinfo\vksvxuaning.exe
  • %WINDIR%\pss\inshivxpv656.exe
  • %WINDIR%\Registration\uenhbliang.exe
  • %WINDIR%\Provisioning\vulroinri168.exe
  • %WINDIR%\Provisioning\Schemas\iangsiosq701.exe
  • %WINDIR%\Registration\CRMLog\bmdivuanchi.exe
  • %WINDIR%\Resources\Themes\cezlsanuen581.exe
  • %WINDIR%\Resources\Themes\Luna\ulzuanuen971.exe
  • %WINDIR%\repair\ongiangqcz.exe
  • %WINDIR%\Resources\yustin566.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\wuyunji.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Unsolicited\uengwudvegj.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\uenbuan24.exe
  • %WINDIR%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\zifqeng112.exe
  • %WINDIR%\pchealth\UploadLB\neszhiong594.exe
  • %WINDIR%\PeerNet\rqrzhiin842.exe
  • %WINDIR%\Prefetch\yuninp.exe
  • %WINDIR%\pchealth\UploadLB\Binaries\cilmabsin915.exe
  • %WINDIR%\pchealth\UploadLB\Config\inguenphvn354.exe
  • %WINDIR%\pchealth\helpctr\OfflineCache\wuumiang374.exe
  • %WINDIR%\pchealth\helpctr\OfflineCache\Professional_32#0409\nvtcswuuang.exe
  • %WINDIR%\pchealth\helpctr\InstalledSKUs\ziyijryoq311.exe
  • %WINDIR%\pchealth\helpctr\Logs\encihtngu736.exe
  • %WINDIR%\pchealth\helpctr\PackageStore\mrineng390.exe
  • %WINDIR%\pchealth\helpctr\System\CompatCtr\riccen.exe
  • %WINDIR%\pchealth\helpctr\System\css\fgttshian.exe
  • %WINDIR%\pchealth\helpctr\System\bcingen.exe
  • %WINDIR%\pchealth\helpctr\System\blurbs\ananiee.exe
  • %WINDIR%\pchealth\helpctr\Config\angvmkchi.exe
  • %WINDIR%\pchealth\helpctr\Config\Cache\yutxzkwu192.exe
  • %WINDIR%\pchealth\helpctr\BATCH\sienwu489.exe
  • %WINDIR%\pchealth\helpctr\binaries\angkyyun630.exe
  • %WINDIR%\pchealth\helpctr\Config\CheckPoint\shizhile510.exe
  • %WINDIR%\pchealth\helpctr\HelpFiles\engingysl.exe
  • %WINDIR%\pchealth\helpctr\Indices\zicaci887.exe
  • %WINDIR%\pchealth\helpctr\Database\gvyfangyu.exe
  • %WINDIR%\pchealth\helpctr\DataColl\riludcliang.exe
  • %WINDIR%\pchealth\helpctr\System\images\Expando\uenziz.exe
  • %WINDIR%\pchealth\helpctr\System\NetDiag\sigfan835.exe
  • %WINDIR%\pchealth\helpctr\System\images\48x48\tiangen666.exe
  • %WINDIR%\pchealth\helpctr\System\images\Centers\imfbcziuan.exe
  • %WINDIR%\pchealth\helpctr\System\panels\jmvgziuan941.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\riqci.exe
  • %WINDIR%\pchealth\helpctr\System\Remote Assistance\Common\enazhi506.exe
  • %WINDIR%\pchealth\helpctr\System\panels\subpanels\sichirbtdt457.exe
  • %WINDIR%\pchealth\helpctr\System\rc\yuniangf117.exe
  • %WINDIR%\pchealth\helpctr\System\DVDUpgrd\jptshiiong842.exe
  • %WINDIR%\pchealth\helpctr\System\ErrMsg\zhiuzbri163.exe
  • %WINDIR%\pchealth\helpctr\System\DFS\wrvbchiuan.exe
  • %WINDIR%\pchealth\helpctr\System\dialogs\lndeiongueng.exe
  • %WINDIR%\pchealth\helpctr\System\errors\siengtz351.exe
  • %WINDIR%\pchealth\helpctr\System\images\24x24\inuanoi966.exe
  • %WINDIR%\pchealth\helpctr\System\images\32x32\anping.exe
  • %WINDIR%\pchealth\helpctr\System\images\iangsij129.exe
  • %WINDIR%\pchealth\helpctr\System\images\16x16\moepwushi29.exe
  • %WINDIR%\Resources\Themes\Luna\Shell\aniongtndv64.exe
  • <SYSTEM32>\config\systemprofile\Start Menu\Programs\Startup\shiduan473.exe
  • <SYSTEM32>\dhcp\onguanud.exe
  • <SYSTEM32>\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\uenwuhqq.exe
  • <SYSTEM32>\config\systemprofile\Start Menu\Programs\Accessories\Entertainment\euanueng.exe
  • <SYSTEM32>\DirectX\enguandwjw.exe
  • <DRIVERS>\disdn\englsi570.exe
  • <DRIVERS>\etc\uanengo.exe
  • <SYSTEM32>\DirectX\Dinput\yxdchiong17.exe
  • <DRIVERS>\eniansmhv.exe
  • <SYSTEM32>\config\systemprofile\anbzi356.exe
  • <SYSTEM32>\config\systemprofile\Desktop\fwdfauengin941.exe
  • <SYSTEM32>\Com\ingrib972.exe
  • <SYSTEM32>\config\sianuen.exe
  • <SYSTEM32>\config\systemprofile\Favorites\sievnueng.exe
  • <SYSTEM32>\config\systemprofile\Start Menu\Programs\iongkkzytuan.exe
  • <SYSTEM32>\config\systemprofile\Start Menu\Programs\Accessories\ziozeuoyi674.exe
  • <SYSTEM32>\config\systemprofile\My Documents\uanchitj.exe
  • <SYSTEM32>\config\systemprofile\Start Menu\sriri.exe
  • <SYSTEM32>\MsDtc\tvengian806.exe
  • <SYSTEM32>\MsDtc\Trace\uangkgfhing363.exe
  • <SYSTEM32>\Macromed\uanfuhauen272.exe
  • <SYSTEM32>\Macromed\Flash\enlbdjsi59.exe
  • <SYSTEM32>\mui\uanjitdoyun118.exe
  • <SYSTEM32>\mui\0402\shiingwfqj.exe
  • <SYSTEM32>\mui\0403\vouengshi.exe
  • <SYSTEM32>\mui\0009\uangluewu551.exe
  • <SYSTEM32>\mui\0401\ofiongshi.exe
  • <SYSTEM32>\ias\inwuy.exe
  • <SYSTEM32>\icsxml\uanoswang.exe
  • <SYSTEM32>\en-us\iongsiang438.exe
  • <SYSTEM32>\export\yiongwu.exe
  • <SYSTEM32>\IME\tmsishi.exe
  • <SYSTEM32>\IME\TINTLGNT\yunyukempf.exe
  • <SYSTEM32>\inetsrv\riwuuwa.exe
  • <SYSTEM32>\IME\CINTLGNT\yunshiqcgkp791.exe
  • <SYSTEM32>\IME\PINTLGNT\uzychziuan.exe
  • %WINDIR%\SoftwareDistribution\EventCache\ciuvjayun811.exe
  • %WINDIR%\SoftwareDistribution\SelfUpdate\engykchwuang90.exe
  • %WINDIR%\SoftwareDistribution\DataStore\Logs\uengzhirtrsn675.exe
  • %WINDIR%\SoftwareDistribution\Download\iongshilihio628.exe
  • %WINDIR%\srchasst\hdengang224.exe
  • %WINDIR%\srchasst\mui\0409\iangpiochi8.exe
  • %WINDIR%\system\rweqwuwu422.exe
  • %WINDIR%\srchasst\chars\bvyuang.exe
  • %WINDIR%\srchasst\mui\iongriyu835.exe
  • %WINDIR%\Resources\Themes\Luna\Shell\NormalColor\sihsbaguan630.exe
  • %WINDIR%\security\chixfbin310.exe
  • %WINDIR%\Resources\Themes\Luna\Shell\Homestead\ibtvzhien.exe
  • %WINDIR%\Resources\Themes\Luna\Shell\Metallic\ingwqaljiang.exe
  • %WINDIR%\security\Database\ziananv.exe
  • %WINDIR%\SoftwareDistribution\riencoqr.exe
  • %WINDIR%\SoftwareDistribution\DataStore\chixshi513.exe
  • %WINDIR%\security\logs\iangvtkgqin656.exe
  • %WINDIR%\security\templates\ianyugjua.exe
  • <SYSTEM32>\3com_dmi\yiufjian.exe
  • <SYSTEM32>\CatRoot\uenuanxssh478.exe
  • <SYSTEM32>\2052\ongaong.exe
  • <SYSTEM32>\3076\xikscuensi.exe
  • <SYSTEM32>\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\kyunian.exe
  • <SYSTEM32>\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\winging.exe
  • <SYSTEM32>\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ianvci.exe
  • <SYSTEM32>\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\angyinre740.exe
  • <SYSTEM32>\CatRoot2\uangmri577.exe
  • <SYSTEM32>\1028\cifisi.exe
  • <SYSTEM32>\1031\anincl.exe
  • <SYSTEM32>\uanmqvian.exe
  • <SYSTEM32>\1025\uengnrven.exe
  • <SYSTEM32>\1033\nzhiiong.exe
  • <SYSTEM32>\1042\tyiuan.exe
  • <SYSTEM32>\1054\incipokz.exe
  • <SYSTEM32>\1037\ianangbu.exe
  • <SYSTEM32>\1041\enovheng.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\uangiyi.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\yunanizsko294.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\ananguw151.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\iangiangfskg.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\risjyu.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\feeds\inukzbuyun.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\tabbrowser\xhiongueng.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\tabview\ytposwuan.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\places\uanvakvyi.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\aero\browser\preferences\uangbyun379.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\history\mpzhisi352.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\migration\inggjbwdeng.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\certerror\zhisendsi195.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\feeds\cioiuanuan.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\pageinfo\qmgwuri351.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\safebrowsing\uengjwzyun437.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\search\bnhmmuenyu10.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\places\upvshici485.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\preferences\pwanshi852.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\downloads\rilzweyian.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\feeds\iongeufweyu.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\branding\zhiianoldou681.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\inktvkrzi.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\migration\uanwumdu67.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\safebrowsing\angsmfqing.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\sidebar\anonglov.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\places\iangdlmleng.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser\preferences\enauwwu.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\places\anjydong787.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\preferences\zhiyunlcbf.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\invjxyu.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\feeds\dunueciyun647.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\tabbrowser\eniongzi.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\shiingwwtd946.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\dvcziin.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\browser\tabview\mpnaning370.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\skin\classic\communicator\wuuewiong178.exe
  • %CommonProgramFiles%\MSSoap\inanlxjg832.exe
  • %CommonProgramFiles%\MSSoap\Binaries\uansnren.exe
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\40\_vti_bin\_vti_adm\hmhcpanueng.exe
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\40\_vti_bin\_vti_aut\hnsjsyuning.exe
  • %CommonProgramFiles%\MSSoap\Binaries\Resources\fssaniang.exe
  • %CommonProgramFiles%\ODBC\Data Sources\engyiyvyl145.exe
  • %CommonProgramFiles%\Services\ingyunqja142.exe
  • %CommonProgramFiles%\MSSoap\Binaries\Resources\1033\ionguangxeiw604.exe
  • %CommonProgramFiles%\ODBC\pdtduaniong648.exe
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\40\bots\ktyinan.exe
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\40\bots\vinavbar\lriuan.exe
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\40\bin\sauengiong699.exe
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\40\bin\1033\pjpeviangueng71.exe
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\40\isapi\jeangin399.exe
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\40\servsupp\eninn38.exe
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\40\_vti_bin\wuvuvyjueng.exe
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\40\isapi\_vti_adm\iongongj.exe
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\40\isapi\_vti_aut\uengongw.exe
  • %PROGRAM_FILES%\FireFox\zitoczzi.exe
  • %PROGRAM_FILES%\FireFox\chrome\wushiyrhhe304.exe
  • %CommonProgramFiles%\System\Ole DB\siiangvx281.exe
  • %PROGRAM_FILES%\ComPlus Applications\bjafiianguen206.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\ingnlcquang882.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\inguanpkxvu935.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\browser\bookmarks\uanmqiceueng712.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\uenghuldchi344.exe
  • %PROGRAM_FILES%\FireFox\chrome\browser\content\branding\iangsin173.exe
  • %CommonProgramFiles%\SpeechEngines\Microsoft\Lexicon\ziingpn.exe
  • %CommonProgramFiles%\SpeechEngines\Microsoft\Lexicon\1033\chihsyu798.exe
  • %CommonProgramFiles%\SpeechEngines\enbseng101.exe
  • %CommonProgramFiles%\SpeechEngines\Microsoft\uengyaaen.exe
  • %CommonProgramFiles%\SpeechEngines\Microsoft\TTS\engskueng.exe
  • %CommonProgramFiles%\System\ado\luvkchizi501.exe
  • %CommonProgramFiles%\System\msadc\yuziang.exe
  • %CommonProgramFiles%\SpeechEngines\Microsoft\TTS\1033\yuuengzsx.exe
  • %CommonProgramFiles%\System\yunjen.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\browser-region\riquan.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\downloads\iongdqynzhi912.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\extensions\ffchiiang.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\xml\zdengonguan.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\ikziongin.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\handling\hvjwiangsi.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\profile\cypeuenci.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\update\chiylnqzi.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\plugins\ianbumri.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\preferences\gaercyiin425.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\engiana469.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\cookie\uanyuifs.exe
  • %PROGRAM_FILES%\FireFox\chrome\pippki\content\pippki\shiyunfjeo989.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\rgqinian.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\shiisi.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\cpow\inguanfooyf195.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\svg\tlymenyi.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\alerts\uenguendpxx.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\global\bindings\zuaning.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\checkbox\yunqing202.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\console\uenwuxrtxh.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\alerts\ongsmueng28.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\arrow\uanianhthc.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\dirListing\uevgshien.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\printpreview\inervnin.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\radio\uenlxulzian237.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\icons\inuytkeng98.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\media\uenwuhfb307.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\satchel\uenbutci.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\xbl-marquee\ziyuntuwgm76.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\mozapps\xpinstall\rprsueniong.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\content\passwordmgr\uangsuan.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\res\tguanuan.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\siykyi.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\fciin179.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\euanuen282.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\engeqneng520.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\xpinstall\wuppuan.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\xslt\uaningofj.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\svg\enpleng.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\xml\inwvzhi469.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global-platform\pjugszishi338.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global-platform\win\ziwichkang.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global-region\yuningb309.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global-platform\mac\eninglwqt977.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global-platform\unix\iongongm.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\autoconfig\shichiiao.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\cookie\engyix423.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\uengshoyu614.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\alerts\engqmvwnri.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\uanmbzhi606.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\search\enrfian.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\security\dzhici426.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\dom\zhiztgilen463.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\global\layout\uenmtiang5.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\pipnss\bcfanuan.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\pippki\riendms184.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\necko\wfongwu.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\passwordmgr\ejfemenuan681.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\places\uvklongong.exe
  • %PROGRAM_FILES%\FireFox\chrome\pippki\chizqxosi720.exe
  • %PROGRAM_FILES%\FireFox\chrome\pippki\content\uangyuhlvm424.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\services\shikluan469.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\feedback\ciianmt.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\extensions\iangshitxwc.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\handling\enguanzy614.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\zhiovcqcuen713.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\downloads\swucangshi579.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\plugins\iggzewuan.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\update\zisifpj860.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\xpinstall\chijhiong.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\preferences\tfiwgyiyi.exe
  • %PROGRAM_FILES%\FireFox\chrome\en-US\locale\en-US\mozapps\profile\mosochiri.exe
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\40\admisapi\scripts\iangviyi.exe
  • C:\Far2\Addons\SetUp\uangingpxla.exe
  • C:\Far2\Addons\Shell\psckwuzi554.exe
  • C:\Far2\Addons\Colors\Default Highlighting\uanuendhf.exe
  • C:\Far2\Addons\Macros\uwuchi296.exe
  • C:\Far2\Addons\XLat\bdvyciiang598.exe
  • C:\Far2\Documentation\eng\yunionga518.exe
  • C:\Far2\Documentation\rus\ianouan305.exe
  • C:\Far2\Addons\XLat\Russian\uencekrong.exe
  • C:\Far2\Documentation\ongjjjpxwu262.exe
  • %HOMEPATH%\Start Menu\Programs\Accessories\enuenyqjn656.exe
  • %HOMEPATH%\Start Menu\Programs\Accessories\Accessibility\chiicuen.exe
  • %HOMEPATH%\Start Menu\wusubuuen.exe
  • %HOMEPATH%\Start Menu\Programs\anqldcpeng656.exe
  • %HOMEPATH%\Start Menu\Programs\Accessories\Entertainment\cixzshi601.exe
  • C:\Far2\Addons\Colors\cixtzhi.exe
  • C:\Far2\Addons\Colors\Custom Highlighting\incjnuuen.exe
  • C:\Far2\iongvcdiang.exe
  • C:\Far2\Addons\cicbvnhri.exe
  • C:\Far2\Plugins\Colorer\hrc\auto\omfpangci833.exe
  • C:\Far2\Plugins\Colorer\hrc\auto\types\pciuan.exe
  • C:\Far2\Plugins\Colorer\bin\ianmang.exe
  • C:\Far2\Plugins\Colorer\hrc\enchiqgkac.exe
  • C:\Far2\Plugins\Colorer\hrd\kuenuen515.exe
  • C:\Far2\Plugins\Compare\shiiangvao816.exe
  • C:\Far2\Plugins\DrawLine\yigodgyu285.exe
  • C:\Far2\Plugins\Colorer\hrd\console\ongwffyun.exe
  • C:\Far2\Plugins\Colorer\hrd\console\contrib\gyiuan.exe
  • C:\Far2\Plugins\slingzhi.exe
  • C:\Far2\Plugins\7-Zip\iangangid356.exe
  • C:\Far2\Encyclopedia\anzzi503.exe
  • C:\Far2\FExcept\yiyuyi353.exe
  • C:\Far2\Plugins\Align\yixoncsi.exe
  • C:\Far2\Plugins\Brackets\uangxhuan934.exe
  • C:\Far2\Plugins\Colorer\yjruyuiang.exe
  • C:\Far2\Plugins\arclite\uenfdrluan.exe
  • C:\Far2\Plugins\AutoWrap\yuenxok.exe
  • %ALLUSERSPROFILE%\Documents\My Music\Sample Music\uengkqcnueng380.exe
  • %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\zhiuangtpf.exe
  • %ALLUSERSPROFILE%\Documents\My Music\enginzs.exe
  • %ALLUSERSPROFILE%\Documents\My Music\My Playlists\yxgariuang.exe
  • %ALLUSERSPROFILE%\Documents\My Music\Sample Playlists\0338E140\wbluengin.exe
  • %ALLUSERSPROFILE%\Documents\My Videos\qfwuiang.exe
  • %ALLUSERSPROFILE%\Favorites\ongenye869.exe
  • %ALLUSERSPROFILE%\Documents\My Pictures\engxlgqzi874.exe
  • %ALLUSERSPROFILE%\Documents\My Pictures\Sample Pictures\chichiscn829.exe
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\login[1].asp
  • %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\login[1].asp
  • %WINDIR%\services.exe
  • <Текущая директория>\ixiziiang491.exe
  • %ALLUSERSPROFILE%\Desktop\ihxwzinan245.exe
  • %ALLUSERSPROFILE%\Documents\cienexrac.exe
  • C:\Documents and Settings\ansioew801.exe
  • %ALLUSERSPROFILE%\ciingdl.exe
  • %HOMEPATH%\Favorites\eqytshiiang909.exe
  • %HOMEPATH%\Favorites\Links\xozhiuang.exe
  • %HOMEPATH%\cikvqydyun245.exe
  • %HOMEPATH%\Desktop\ciuxeng.exe
  • %HOMEPATH%\My Documents\angwksi.exe
  • %HOMEPATH%\My Documents\My Pictures\chihwrshi.exe
  • %HOMEPATH%\My Documents\My Received Files\rchiing941.exe
  • %HOMEPATH%\My Documents\Downloads\tdqjuanyun.exe
  • %HOMEPATH%\My Documents\My Music\rvtzhien.exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\uengzbian192.exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Accessibility\ianuuytizhi72.exe
  • %ALLUSERSPROFILE%\Start Menu\xnsizi.exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\onguenos972.exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Communications\sizihc.exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\Administrative Tools\wuling706.exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\Games\xviyishi378.exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Entertainment\uengsia.exe
  • %ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\etoshiwu573.exe
  • C:\Far2\Plugins\EditCase\uenohktwu304.exe
  • %CommonProgramFiles%\Microsoft Shared\DW\yongyu484.exe
  • %CommonProgramFiles%\Microsoft Shared\DW\1025\sicwqnxyun678.exe
  • %CommonProgramFiles%\Microsoft Shared\mdongyun748.exe
  • %CommonProgramFiles%\Microsoft Shared\DAO\chiaoguang.exe
  • %CommonProgramFiles%\Microsoft Shared\DW\1028\uennuan.exe
  • %CommonProgramFiles%\Microsoft Shared\DW\1036\uanwuzri401.exe
  • %CommonProgramFiles%\Microsoft Shared\DW\1040\qhprxsiyun1.exe
  • %CommonProgramFiles%\Microsoft Shared\DW\1031\engucrci835.exe
  • %CommonProgramFiles%\Microsoft Shared\DW\1033\uenguenhus.exe
  • C:\Far2\Plugins\WinSCP\windows\yipri.exe
  • C:\Far2\PluginSDK\uanuangmmil.exe
  • C:\Far2\Plugins\WinSCP\release\chiingpvvx.exe
  • C:\Far2\Plugins\WinSCP\resource\dsvbianiang.exe
  • C:\Far2\PluginSDK\Headers.c\uengangynhy683.exe
  • %PROGRAM_FILES%\zisicy.exe
  • %CommonProgramFiles%\uuybbuenguan983.exe
  • C:\Far2\PluginSDK\Headers.pas\guwenin401.exe
  • <Служебный элемент>
  • %CommonProgramFiles%\Microsoft Shared\VGX\sichijgnv.exe
  • %CommonProgramFiles%\Microsoft Shared\Web Folders\ingcfpiang.exe
  • %CommonProgramFiles%\Microsoft Shared\Triedit\ongribj980.exe
  • %CommonProgramFiles%\Microsoft Shared\VC\shianw577.exe
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\engdhsowu.exe
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\40\admcgi\scripts\ccuengshi.exe
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\40\admisapi\angixsi513.exe
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\40\kkzengen469.exe
  • %CommonProgramFiles%\Microsoft Shared\web server extensions\40\admcgi\inopbong.exe
  • %CommonProgramFiles%\Microsoft Shared\DW\2052\wuingve.exe
  • %CommonProgramFiles%\Microsoft Shared\DW\3082\uangkeci.exe
  • %CommonProgramFiles%\Microsoft Shared\DW\1041\inguengh831.exe
  • %CommonProgramFiles%\Microsoft Shared\DW\1042\engyuspauw949.exe
  • %CommonProgramFiles%\Microsoft Shared\MSInfo\onqeqyisi.exe
  • %CommonProgramFiles%\Microsoft Shared\Stationery\uenguanxm.exe
  • %CommonProgramFiles%\Microsoft Shared\TextConv\wuianghb647.exe
  • %CommonProgramFiles%\Microsoft Shared\Speech\anhuen.exe
  • %CommonProgramFiles%\Microsoft Shared\Speech\1033\yunbyun.exe
  • C:\Far2\Plugins\MacroView\uaniangsnm.exe
  • C:\Far2\Plugins\Network\uanjmurpian511.exe
  • C:\Far2\Plugins\FTP\lib\uzkbnyunian.exe
  • C:\Far2\Plugins\HlfViewer\cimwdcueng.exe
  • C:\Far2\Plugins\ProcList\angenrdang.exe
  • C:\Far2\Plugins\WinSCP\components\angong459.exe
  • C:\Far2\Plugins\WinSCP\console\ongengo.exe
  • C:\Far2\Plugins\TmpPanel\senwu.exe
  • C:\Far2\Plugins\WinSCP\inpgyi.exe
  • C:\Far2\Plugins\ExtSearch\doc\neesfiongiong418.exe
  • C:\Far2\Plugins\ExtSearch\keys\ingujlqvong.exe
  • C:\Far2\Plugins\EMenu\shizuen96.exe
  • C:\Far2\Plugins\ExtSearch\knrtuanguan342.exe
  • C:\Far2\Plugins\ExtSearch\sources\siribwgs.exe
  • C:\Far2\Plugins\FileCase\inscian.exe
  • C:\Far2\Plugins\FTP\uanglccgiang.exe
  • C:\Far2\Plugins\ExtSearch\sources\RegExp\ianegiyun.exe
  • C:\Far2\Plugins\FarCmds\angsiang.exe
  • C:\Far2\Plugins\WinSCP\packages\my\encxdsshi941.exe
  • C:\Far2\Plugins\WinSCP\packages\tb2k\ugnzhici614.exe
  • C:\Far2\Plugins\WinSCP\packages\dragndrop\ciuanyz727.exe
  • C:\Far2\Plugins\WinSCP\packages\filemng\yuehutchi347.exe
  • C:\Far2\Plugins\WinSCP\packages\tbx\qwuang138.exe
  • C:\Far2\Plugins\WinSCP\putty\charset\kmrfangiang.exe
  • C:\Far2\Plugins\WinSCP\putty\windows\cpyuueng943.exe
  • C:\Far2\Plugins\WinSCP\packages\theme\enpbjbri.exe
  • C:\Far2\Plugins\WinSCP\putty\ianangqdcrs530.exe
  • C:\Far2\Plugins\WinSCP\far\fianian.exe
  • C:\Far2\Plugins\WinSCP\fari\chishig.exe
  • C:\Far2\Plugins\WinSCP\core\civgfrjong760.exe
  • C:\Far2\Plugins\WinSCP\dragext\nllrangeng.exe
  • C:\Far2\Plugins\WinSCP\filezilla\onganalchj.exe
  • C:\Far2\Plugins\WinSCP\lib\angpjyzzuan371.exe
  • C:\Far2\Plugins\WinSCP\packages\inymruwu475.exe
  • C:\Far2\Plugins\WinSCP\filezilla\misc\zhirindd.exe
  • C:\Far2\Plugins\WinSCP\forms\ririws.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\scrollbar\uanvakezian484.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Engine\rcmangiang265.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Engine\v4.0_4.0.0.0__b03f5f7f11d50a3a\enenga623.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Conversion.v4.0\chiingimw768.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Conversion.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\chiuphsbiong.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Framework\bwushi.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Tasks.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\sgujenri.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Utilities.v4.0\vbhiwuwu757.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Framework\v4.0_4.0.0.0__b03f5f7f11d50a3a\uanwuj780.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Tasks.v4.0\yiguan464.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\angonguma748.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Accessibility\yienpi713.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\System.Web\enguany615.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\ingaqlhshi.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\uengyunt712.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build\sikueng536.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build\v4.0_4.0.0.0__b03f5f7f11d50a3a\izogoanuen435.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\AspNetMMCExt\uenzwzi.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\AspNetMMCExt\v4.0_4.0.0.0__b03f5f7f11d50a3a\uangiangzru.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\ingnuan233.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\v4.0_10.0.0.0__b03f5f7f11d50a3a\jaangyun195.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\siiangpp.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\v4.0_10.0.0.0__b03f5f7f11d50a3a\ifquaning.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\ionguani670.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC.STLCLR\v4.0_2.0.0.0__b03f5f7f11d50a3a\phingian177.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Workflow.Compiler\qangshi517.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC\v4.0_10.0.0.0__b03f5f7f11d50a3a\wuyufjn.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualC.STLCLR\siiangfhiq407.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\tranguan.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\hmwuuan750.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Build.Utilities.v4.0\v4.0_4.0.0.0__b03f5f7f11d50a3a\ciqjlhuang397.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\riibgvzing921.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\wcbongang.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\ingshoyshi.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\yinguen.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\xmbciyi323.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\v4.0_4.0.0.0__b03f5f7f11d50a3a\uenguannrynq301.exe
  • %WINDIR%\Microsoft.NET\rbfusishi844.exe
  • %WINDIR%\Microsoft.NET\assembly\uangfxvniyun730.exe
  • %WINDIR%\java\trustlib\uenganspv.exe
  • %WINDIR%\Media\chihggluan.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\yusifock.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\ISymWrapper\iongyikv308.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\ISymWrapper\v4.0_4.0.0.0__b03f5f7f11d50a3a\yuvauen743.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\CustomMarshalers\sicyewsiang.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\angxthsi153.exe
  • %WINDIR%\ime\imkr6_1\elgpianian.exe
  • %WINDIR%\ime\imkr6_1\applets\yiwuon542.exe
  • %WINDIR%\ime\imjp8_1\cichij26.exe
  • %WINDIR%\ime\imjp8_1\applets\zickjueng.exe
  • %WINDIR%\ime\imkr6_1\dicts\langing.exe
  • %WINDIR%\java\anreng350.exe
  • %WINDIR%\java\classes\ciendreds3.exe
  • %WINDIR%\ime\shared\iangsfjfwu.exe
  • %WINDIR%\ime\shared\res\wkciuen438.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\System.Data.OracleClient\v4.0_4.0.0.0__b77a5c561934e089\yuncsvkvuang37.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\uengiangl.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\injmomzhi618.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\System.Data.OracleClient\ingyunnvwo511.exe
  • %WINDIR%\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_4.0.0.0_x-ww_29b51492\iongssi.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\System.Transactions\blcaenuan.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\zipkbhueng275.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\System.Printing\inguarpen.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\System.Printing\v4.0_4.0.0.0__31bf3856ad364e35\uenyiixabc154.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\ianinp.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\Microsoft.VisualBasic.Activities.Compiler\v4.0_10.0.0.0__b03f5f7f11d50a3a\oevcquenan.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\afxpyuang.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\v4.0_4.0.0.0__b03f5f7f11d50a3a\anzilok243.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\mscorlib\iangiongwt900.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\iangkjdwu272.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\System.Data\enangnpf.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\uangirghiang284.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_32\PresentationCore\ricquen770.exe
  • %WINDIR%\WinSxS\MSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5\yivkzviong879.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\entyiang648.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity.Design\yunuankwqdq.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\engvxbwmzi59.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\uengsyi947.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity.Design\v4.0_4.0.0.0__b77a5c561934e089\engcibc201.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services\wkguanri463.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services\v4.0_4.0.0.0__b77a5c561934e089\uencbsgshi.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\yucven888.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Data.Linq\v4.0_4.0.0.0__b77a5c561934e089\mnuryuing.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\uanpazhi.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\lyiwu.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\nhcuzziong285.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.DataAnnotations\v4.0_4.0.0.0__31bf3856ad364e35\driuan.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\wuiongrpoj81.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\risiayj.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\juanshi480.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\sinuang.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Core\whuanwu424.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Device\v4.0_4.0.0.0__b77a5c561934e089\mdopsiin459.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\riianb.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Design\v4.0_4.0.0.0__b03f5f7f11d50a3a\zklqoyuniang.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Device\uansiocv72.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\hjxuenen.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\qyitsriing779.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.Protocols\v4.0_4.0.0.0__b03f5f7f11d50a3a\ingcsmpyu.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\anguangc847.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices.AccountManagement\v4.0_4.0.0.0__b77a5c561934e089\rlmogiangsi773.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Design\yuninwhxu379.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Design\v4.0_4.0.0.0__b77a5c561934e089\zhicxdfiang542.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\kondianan.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Data.Services.Client\v4.0_4.0.0.0__b77a5c561934e089\yixsyu.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\uengengdeiv.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\enuenw.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Design\yizhiiuaas588.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Data.SqlXml\v4.0_4.0.0.0__b77a5c561934e089\anshijvuw917.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\uanongy.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\v4.0_4.0.0.0__31bf3856ad364e35\wuxjjoing888.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\gciuang.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\v4.0_4.0.0.0__31bf3856ad364e35\ybbiangri326.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Royale\ziuanhv655.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\PresentationUI\v4.0_4.0.0.0__31bf3856ad364e35\zlnrdanuan941.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\zhilrdzi980.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\ciduan.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\ianguanjr778.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\ReachFramework\v4.0_4.0.0.0__31bf3856ad364e35\ziuhawiyu.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\xrjvozien.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework\v4.0_4.0.0.0__31bf3856ad364e35\uanwajang907.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\PresentationBuildTasks\wianging.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\PresentationBuildTasks\v4.0_4.0.0.0__31bf3856ad364e35\ianglwu.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\zjcyuangyi941.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\v4.0_4.0.0.0__31bf3856ad364e35\euanen.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Luna\ingwudx508.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Aero\v4.0_4.0.0.0__31bf3856ad364e35\ingmatmzi388.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework.Classic\yipiong.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\nhtuanchi.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\qlhcsshiuen358.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\v4.0_4.0.0.0__31bf3856ad364e35\ziuengbrw225.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Presentation\ingmrnpan584.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.AddIn\v4.0_4.0.0.0__b77a5c561934e089\uangsip522.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\izhiong.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\uangins.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\tzzvyuanri.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.AddIn.Contract\v4.0_4.0.0.0__b03f5f7f11d50a3a\chisias476.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System\yuoibzuen69.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\riindshki737.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\sysglobl\zhiuenuw.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\sysglobl\v4.0_4.0.0.0__b03f5f7f11d50a3a\iangnuan574.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Activities\uensjuang.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\v4.0_4.0.0.0__31bf3856ad364e35\uenguengsawh216.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Activities.DurableInstancing\yusir.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Activities\v4.0_4.0.0.0__31bf3856ad364e35\vigyuyun.exe
  • %WINDIR%\Microsoft.NET\assembly\GAC_MSIL\System.Activities.Core.Presentation\inghkbong694.exe
  • %WINDIR%\ime\imejp98\ingcicje112.exe
  • %PROGRAM_FILES%\FireFox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\ziuenmknlb.exe
  • %PROGRAM_FILES%\FireFox\modules\uenycan.exe
  • %PROGRAM_FILES%\FireFox\dictionaries\uanydxneng.exe
  • %PROGRAM_FILES%\FireFox\extensions\chiuhcang955.exe
  • %PROGRAM_FILES%\FireFox\modules\services-crypto\zighmrian178.exe
  • %PROGRAM_FILES%\FireFox\modules\services-sync\ext\chiingijkn.exe
  • %PROGRAM_FILES%\FireFox\modules\tabview\wuingxdz.exe
  • %PROGRAM_FILES%\FireFox\modules\services-sync\anruang.exe
  • %PROGRAM_FILES%\FireFox\modules\services-sync\engines\shiyunxjm.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\xpinstall\yucori.exe
  • %PROGRAM_FILES%\FireFox\components\ianghuan295.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\update\yuqvlhbzhi.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\viewsource\uuueninwu.exe
  • %PROGRAM_FILES%\FireFox\defaults\zkinuen.exe
  • %PROGRAM_FILES%\FireFox\defaults\profile\pqerianging372.exe
  • %PROGRAM_FILES%\FireFox\defaults\profile\chrome\uenyunu781.exe
  • %PROGRAM_FILES%\FireFox\defaults\autoconfig\sicrhqsi.exe
  • %PROGRAM_FILES%\FireFox\defaults\pref\uenzizyc990.exe
  • %PROGRAM_FILES%\Internet Explorer\MUI\0409\shiingwznca165.exe
  • %PROGRAM_FILES%\Internet Explorer\PLUGINS\uenyiiyu.exe
  • %PROGRAM_FILES%\Internet Explorer\Connection Wizard\yidtmsong.exe
  • %PROGRAM_FILES%\Internet Explorer\MUI\xcaonging.exe
  • %PROGRAM_FILES%\Internet Explorer\SIGNUP\lndcongyun850.exe
  • %PROGRAM_FILES%\microsoft frontpage\version3.0\cixxeng.exe
  • %PROGRAM_FILES%\microsoft frontpage\version3.0\bin\uanguengjphe.exe
  • %PROGRAM_FILES%\Messenger\otkfenguen.exe
  • %PROGRAM_FILES%\microsoft frontpage\shiuenwubo.exe
  • %PROGRAM_FILES%\FireFox\res\dtd\uanvgiishi.exe
  • %PROGRAM_FILES%\FireFox\res\entityTables\gengyi.exe
  • %PROGRAM_FILES%\FireFox\plugins\ongkyun.exe
  • %PROGRAM_FILES%\FireFox\res\angqwu357.exe
  • %PROGRAM_FILES%\FireFox\res\fonts\anenssojr.exe
  • %PROGRAM_FILES%\FireFox\uninstall\incan.exe
  • %PROGRAM_FILES%\Internet Explorer\ansxbden768.exe
  • %PROGRAM_FILES%\FireFox\res\html\iongyizxh.exe
  • %PROGRAM_FILES%\FireFox\searchplugins\dmfangong187.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\update\chiiangfhwgs.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\viewsource\uanzing.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\plugins\aniangs702.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\profile\onggrkfbci150.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\xpinstall\uenziwk.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\arrow\chiyikcpv233.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\checkbox\suvwyiian600.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\iangagaehzhi428.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\alerts\chienge728.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\tree\yuninlbrp939.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\fqkiyuing924.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\splitter\eqxjnanguan.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\global\toolbar\yienocc.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\downloads\uangziv.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\passwordmgr\xsyuci.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\places\pgcanuan.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\extensions\ozizhi.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\aero\mozapps\handling\yuianl.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\downloads\uangvyun.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\extensions\anguzi100.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\tree\ribmchi296.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\kaxzhiri.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\handling\qlpfiangwu.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\plugins\vnjinuan.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\profile\zhiyuniawen417.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\passwordmgr\ciuango936.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\mozapps\places\shishiko.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\icons\yiuans.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\media\engtbgyaang.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\console\uenvykwgen.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\dirListing\riveoeng828.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\printpreview\sitnchi300.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\splitter\enianguzvig.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\toolbar\xvoingci839.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\radio\zdpfcichi664.exe
  • %PROGRAM_FILES%\FireFox\chrome\toolkit\skin\classic\global\scrollbar\fvrainan524.exe
  • %PROGRAM_FILES%\Microsoft.NET\anincs.exe
  • %WINDIR%\Debug\UserMode\ynduziueng.exe
  • %WINDIR%\Driver Cache\ingiangavvdh311.exe
  • %WINDIR%\Cursors\kwnriyu71.exe
  • %WINDIR%\Debug\fxqvzizhi.exe
  • %WINDIR%\Driver Cache\i386\yufyun262.exe
  • %WINDIR%\Help\Tours\jejjfyunian954.exe
  • %WINDIR%\Help\Tours\htmlTour\znfuansi219.exe
  • %WINDIR%\ehome\anskiong.exe
  • %WINDIR%\Help\shinlppoiong.exe
  • %PROGRAM_FILES%\xerox\yunano.exe
  • %PROGRAM_FILES%\xerox\nwwia\uaneuan.exe
  • %PROGRAM_FILES%\Windows NT\Accessories\skcxanguan.exe
  • %PROGRAM_FILES%\Windows NT\Pinball\sezchizi.exe
  • %WINDIR%\qyishi871.exe
  • %WINDIR%\Config\yutzhi.exe
  • %WINDIR%\Connection Wizard\cisin.exe
  • %WINDIR%\addins\uanuancuag.exe
  • %WINDIR%\AppPatch\jiylyiongeng.exe
  • %WINDIR%\ime\risikttpo.exe
  • %WINDIR%\ime\chsime\qshiueng344.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Scr\xhuanin.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Video\shizidnqy416.exe
  • %WINDIR%\ime\chsime\applets\iongqqvuan.exe
  • %WINDIR%\ime\imejp\enjuneing199.exe
  • %WINDIR%\ime\imejp\applets\zhizhiatxl243.exe
  • %WINDIR%\ime\CHTIME\inianyj957.exe
  • %WINDIR%\ime\CHTIME\Applets\yizhika.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\mikoizhizhi.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Audio\Wav\shiwudc.exe
  • %WINDIR%\Help\Tours\mmTour\anftjviang662.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\gomciuan421.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Cnt\yuninfftf.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\Btn\fvslangan363.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\WMarks\ianuanga.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Css\zizhizz.exe
  • %WINDIR%\Help\Tours\WindowsMediaPlayer\Img\xqsxtriuan.exe
  • %PROGRAM_FILES%\MSN\qszchiwu.exe
  • %PROGRAM_FILES%\MSN\MSNCoreFiles\uangtobzowu.exe
  • %PROGRAM_FILES%\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\zhiziynhjg.exe
  • %PROGRAM_FILES%\MSBuild\Microsoft\Windows Workflow Foundation\v3.5\rchizhi.exe
  • %PROGRAM_FILES%\MSN\MSNCoreFiles\Install\ginguan.exe
  • %PROGRAM_FILES%\MSN Gaming Zone\jpdhiongwu606.exe
  • %PROGRAM_FILES%\MSN Gaming Zone\Windows\muengzi272.exe
  • %PROGRAM_FILES%\MSN\MSNCoreFiles\Install\MSN9Components\ziengmrgrs504.exe
  • %PROGRAM_FILES%\MSN\MSNCoreFiles\OOBE\eziiang.exe
  • %PROGRAM_FILES%\Movie Maker\MUI\vcengzhi145.exe
  • %PROGRAM_FILES%\Movie Maker\MUI\0409\cidyodqyu.exe
  • %PROGRAM_FILES%\Microsoft.NET\RedistList\uanyuuw627.exe
  • %PROGRAM_FILES%\Movie Maker\anuenge843.exe
  • %PROGRAM_FILES%\Movie Maker\Shared\uangelfueng818.exe
  • %PROGRAM_FILES%\MSBuild\Microsoft\cizexysuen.exe
  • %PROGRAM_FILES%\MSBuild\Microsoft\Windows Workflow Foundation\iyiongri.exe
  • %PROGRAM_FILES%\Movie Maker\Shared\Profiles\ciingm.exe
  • %PROGRAM_FILES%\MSBuild\engshii.exe
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.5\SubsetList\tvnjyyuniang.exe
  • %PROGRAM_FILES%\Windows Media Player\angenjmd365.exe
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.5\yimvwu308.exe
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\iangwueng401.exe
  • %PROGRAM_FILES%\Windows Media Player\Icons\vzhiuan.exe
  • %PROGRAM_FILES%\Windows Media Player\Visualizations\ocsian.exe
  • %PROGRAM_FILES%\Windows NT\yunrrmxing.exe
  • %PROGRAM_FILES%\Windows Media Player\Sample Playlists\uizlwuang671.exe
  • %PROGRAM_FILES%\Windows Media Player\Skins\yupulcbyi.exe
  • %PROGRAM_FILES%\Outlook Express\angiiong205.exe
  • %PROGRAM_FILES%\Reference Assemblies\yizinwzsg.exe
  • %PROGRAM_FILES%\NetMeeting\hqnhingen.exe
  • %PROGRAM_FILES%\Online Services\uanhzbyi397.exe
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\lengzhi.exe
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\ingritx.exe
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.0\SubsetList\engitazri.exe
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\tyueng283.exe
  • %PROGRAM_FILES%\Reference Assemblies\Microsoft\Framework\v3.0\sipong.exe
Удаляет следующие файлы:
  • %TEMP%\~DFBD96.tmp
  • %WINDIR%\Temp\tmp1.tmp
Перемещает следующие файлы:
  • <SYSTEM32>\wbem\mof\ianysi.exe в <SYSTEM32>\wbem\mof\bad\ianysi.exe
Сетевая активность:
Подключается к:
  • 's.###gon128.com':80
  • 's.###gon128.net':80
TCP:
Запросы HTTP GET:
  • s.###gon128.com/ie2007/ie/login.asp?ad################################
  • s.###gon128.net/ie2007/ie/login.asp?ad################################
UDP:
  • DNS ASK s.###gon128.com
  • DNS ASK s.###gon128.net
Другое:
Ищет следующие окна:
  • ClassName: 'Indicator' WindowName: ''

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке