Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\caeucmwl.exe' = '<SYSTEM32>\caeucmwl.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\heitxqrc.exe' = '<SYSTEM32>\heitxqrc.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\ukvfgiko.exe' = '<SYSTEM32>\ukvfgiko.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\dgdhggnr.exe' = '<SYSTEM32>\dgdhggnr.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\jlymdadu.exe' = '<SYSTEM32>\jlymdadu.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\tgrkbkyf.exe' = '<SYSTEM32>\tgrkbkyf.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\vecjvpan.exe' = '<SYSTEM32>\vecjvpan.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\anmpsost.exe' = '<SYSTEM32>\anmpsost.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\qplbonki.exe' = '<SYSTEM32>\qplbonki.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\vxsxlcqu.exe' = '<SYSTEM32>\vxsxlcqu.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\rxmsvydu.exe' = '<SYSTEM32>\rxmsvydu.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\cdcwsekx.exe' = '<SYSTEM32>\cdcwsekx.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\mqwnqssq.exe' = '<SYSTEM32>\mqwnqssq.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\xpcsouck.exe' = '<SYSTEM32>\xpcsouck.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\kqlbyxck.exe' = '<SYSTEM32>\kqlbyxck.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\uxbbzjxi.exe' = '<SYSTEM32>\uxbbzjxi.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\nojxnjri.exe' = '<SYSTEM32>\nojxnjri.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] 'C:\\M66X2F9uwG.exe' = 'C:\\M66X2F9uwG.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DisableNotifications' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\npoymgtz.exe' = '<SYSTEM32>\npoymgtz.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\ijzuesxt.exe' = '<SYSTEM32>\ijzuesxt.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\fcjdzayl.exe' = '<SYSTEM32>\fcjdzayl.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\cdzxmixj.exe' = '<SYSTEM32>\cdzxmixj.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\pntqfzry.exe' = '<SYSTEM32>\pntqfzry.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\budgjohu.exe' = '<SYSTEM32>\budgjohu.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\yqrcieus.exe' = '<SYSTEM32>\yqrcieus.exe:*:Enabled:Microsoft (R) Internetal IExplore'
- '<SYSTEM32>\jlymdadu.exe' /c REG ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\caeucmwl.exe" /t REG_SZ /d "<SYSTEM32>\caeucmwl.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\jlymdadu.exe' /pid=4016
- '<SYSTEM32>\heitxqrc.exe'
- '<SYSTEM32>\cdzxmixj.exe' /pid=3960
- '<SYSTEM32>\yqrcieus.exe' /pid=1556
- '<SYSTEM32>\dgdhggnr.exe'
- '<SYSTEM32>\uxbbzjxi.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile /v DoNotAllowExceptions /t REG_DWORD /d 0 /f
- '<SYSTEM32>\ijzuesxt.exe' /pid=3536
- '<SYSTEM32>\caeucmwl.exe'
- '<SYSTEM32>\pntqfzry.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile /v EnableFirewall /t REG_DWORD /d 0 /f
- '<SYSTEM32>\anmpsost.exe'
- '<SYSTEM32>\rxmsvydu.exe'
- '<SYSTEM32>\qplbonki.exe'
- '<SYSTEM32>\xsatsqoz.exe'
- '<SYSTEM32>\vxsxlcqu.exe'
- '<SYSTEM32>\ukvfgiko.exe'
- '<SYSTEM32>\uxbbzjxi.exe' /c REG ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile /v DoNotAllowExceptions /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cdcwsekx.exe'
- '<SYSTEM32>\xpcsouck.exe'
- '<SYSTEM32>\mqwnqssq.exe'
- '<SYSTEM32>\vecjvpan.exe'
- '<SYSTEM32>\budgjohu.exe'
- '<SYSTEM32>\pntqfzry.exe'
- '<SYSTEM32>\yqrcieus.exe'
- '<SYSTEM32>\npoymgtz.exe'
- '<SYSTEM32>\cdzxmixj.exe'
- 'C:\ё¶ё®їА±єАЗ_ё¶АОЕ©·ЎЗБЖ®_ЗС±ЫЖРДЎ_°ЈЖнјіДЎ±в___ЖчБц_1.5.2.exe'
- 'C:\M66X2F9uwG.exe'
- '<SYSTEM32>\kqlbyxck.exe'
- '<SYSTEM32>\nojxnjri.exe'
- '<SYSTEM32>\uxbbzjxi.exe'
- '<SYSTEM32>\nojxnjri.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile /v EnableFirewall /t REG_DWORD /d 0 /f
- '<SYSTEM32>\uxbbzjxi.exe' /pid=3476
- '<SYSTEM32>\jlymdadu.exe'
- '<SYSTEM32>\tgrkbkyf.exe'
- '<SYSTEM32>\budgjohu.exe' /pid=2364
- 'C:\M66X2F9uwG.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile /v DoNotAllowExceptions /t REG_DWORD /d 0 /f
- '<SYSTEM32>\kqlbyxck.exe' /c REG ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile /v DoNotAllowExceptions /t REG_DWORD /d 0 /f
- '<SYSTEM32>\ijzuesxt.exe'
- '<SYSTEM32>\nojxnjri.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\ijzuesxt.exe" /t REG_SZ /d "<SYSTEM32>\ijzuesxt.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\fcjdzayl.exe'
- '<SYSTEM32>\reg.exe'
- '<SYSTEM32>\reg.exe' /pid=3176
- '<SYSTEM32>\reg.exe' /pid=3864
- '<SYSTEM32>\reg.exe' /pid=3580
- '<SYSTEM32>\reg.exe' /pid=3328
- '<SYSTEM32>\reg.exe' /pid=112
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\tgrkbkyf.exe" /t REG_SZ /d "<SYSTEM32>\tgrkbkyf.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' /pid=2940
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\vecjvpan.exe" /t REG_SZ /d "<SYSTEM32>\vecjvpan.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\caeucmwl.exe" /t REG_SZ /d "<SYSTEM32>\caeucmwl.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\anmpsost.exe" /t REG_SZ /d "<SYSTEM32>\anmpsost.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\rxmsvydu.exe" /t REG_SZ /d "<SYSTEM32>\rxmsvydu.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\vxsxlcqu.exe" /t REG_SZ /d "<SYSTEM32>\vxsxlcqu.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\qplbonki.exe" /t REG_SZ /d "<SYSTEM32>\qplbonki.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\xpcsouck.exe" /t REG_SZ /d "<SYSTEM32>\xpcsouck.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\ukvfgiko.exe" /t REG_SZ /d "<SYSTEM32>\ukvfgiko.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' /pid=2716
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\mqwnqssq.exe" /t REG_SZ /d "<SYSTEM32>\mqwnqssq.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\cdcwsekx.exe" /t REG_SZ /d "<SYSTEM32>\cdcwsekx.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' /pid=2436
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\nojxnjri.exe" /t REG_SZ /d "<SYSTEM32>\nojxnjri.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\uxbbzjxi.exe" /t REG_SZ /d "<SYSTEM32>\uxbbzjxi.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\budgjohu.exe" /t REG_SZ /d "<SYSTEM32>\budgjohu.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\pntqfzry.exe" /t REG_SZ /d "<SYSTEM32>\pntqfzry.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\kqlbyxck.exe" /t REG_SZ /d "<SYSTEM32>\kqlbyxck.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile /v EnableFirewall /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile /v DisableNotifications /t REG_DWORD /d 1 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "C:\\M66X2F9uwG.exe" /t REG_SZ /d "C:\\M66X2F9uwG.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile /v DoNotAllowExceptions /t REG_DWORD /d 0 /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\yqrcieus.exe" /t REG_SZ /d "<SYSTEM32>\yqrcieus.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\fcjdzayl.exe" /t REG_SZ /d "<SYSTEM32>\fcjdzayl.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' /pid=3104
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\jlymdadu.exe" /t REG_SZ /d "<SYSTEM32>\jlymdadu.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' /pid=3808
- '<SYSTEM32>\reg.exe' /pid=2844
- '<SYSTEM32>\reg.exe' /pid=2896
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\cdzxmixj.exe" /t REG_SZ /d "<SYSTEM32>\cdzxmixj.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' ADD HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List /v "<SYSTEM32>\npoymgtz.exe" /t REG_SZ /d "<SYSTEM32>\npoymgtz.exe:*:Enabled:Microsoft (R) Internetal IExplore" /f
- '<SYSTEM32>\reg.exe' /pid=2916
- <SYSTEM32>\reg.exe
- <SYSTEM32>\cmd.exe
- <SYSTEM32>\dgdhggnr.exe
- <SYSTEM32>\vecjvpan.exe
- <SYSTEM32>\heitxqrc.exe
- <SYSTEM32>\caeucmwl.exe
- <SYSTEM32>\fcjdzayl.exe
- <SYSTEM32>\ijzuesxt.exe
- <SYSTEM32>\tgrkbkyf.exe
- <SYSTEM32>\jlymdadu.exe
- <SYSTEM32>\ukvfgiko.exe
- <SYSTEM32>\qplbonki.exe
- <SYSTEM32>\anmpsost.exe
- <SYSTEM32>\xsatsqoz.exe
- <SYSTEM32>\vxsxlcqu.exe
- <SYSTEM32>\mqwnqssq.exe
- <SYSTEM32>\cdcwsekx.exe
- <SYSTEM32>\rxmsvydu.exe
- <SYSTEM32>\xpcsouck.exe
- <SYSTEM32>\npoymgtz.exe
- <SYSTEM32>\MSWINSCK.ocx
- %TEMP%\nsh3.tmp\ioSpecial.ini
- <SYSTEM32>\kqlbyxck.exe
- C:\ё¶ё®їА±єАЗ_ё¶АОЕ©·ЎЗБЖ®_ЗС±ЫЖРДЎ_°ЈЖнјіДЎ±в___ЖчБц_1.5.2.exe
- C:\M66X2F9uwG.exe
- %TEMP%\nsh3.tmp\AdvSplash.dll
- %TEMP%\splash.bmp
- %TEMP%\nsh3.tmp\modern-wizard.bmp
- <SYSTEM32>\budgjohu.exe
- <SYSTEM32>\pntqfzry.exe
- <SYSTEM32>\cdzxmixj.exe
- <SYSTEM32>\yqrcieus.exe
- %TEMP%\nsh3.tmp\InstallOptions.dll
- %TEMP%\nsh3.tmp\Aero.dll
- <SYSTEM32>\nojxnjri.exe
- <SYSTEM32>\uxbbzjxi.exe
- <SYSTEM32>\ukvfgiko.exe
- <SYSTEM32>\cdcwsekx.exe
- <SYSTEM32>\mqwnqssq.exe
- <SYSTEM32>\dgdhggnr.exe
- <SYSTEM32>\caeucmwl.exe
- <SYSTEM32>\heitxqrc.exe
- <SYSTEM32>\qplbonki.exe
- <SYSTEM32>\vxsxlcqu.exe
- <SYSTEM32>\xsatsqoz.exe
- <SYSTEM32>\xpcsouck.exe
- <SYSTEM32>\rxmsvydu.exe
- <SYSTEM32>\anmpsost.exe
- <SYSTEM32>\vecjvpan.exe
- <SYSTEM32>\pntqfzry.exe
- <SYSTEM32>\budgjohu.exe
- <SYSTEM32>\yqrcieus.exe
- <SYSTEM32>\kqlbyxck.exe
- <SYSTEM32>\uxbbzjxi.exe
- <SYSTEM32>\nojxnjri.exe
- <SYSTEM32>\fcjdzayl.exe
- <SYSTEM32>\jlymdadu.exe
- <SYSTEM32>\tgrkbkyf.exe
- <SYSTEM32>\cdzxmixj.exe
- <SYSTEM32>\npoymgtz.exe
- <SYSTEM32>\ijzuesxt.exe
- %TEMP%\~DFC512.tmp
- %TEMP%\~DFC401.tmp
- %TEMP%\~DF97D1.tmp
- %TEMP%\~DFF27B.tmp
- %TEMP%\~DF47F.tmp
- %TEMP%\~DFE721.tmp
- %TEMP%\~DF6812.tmp
- %TEMP%\~DF359E.tmp
- %TEMP%\~DF1F9E.tmp
- %TEMP%\~DFFD9E.tmp
- %TEMP%\~DF68B1.tmp
- %TEMP%\~DF45B9.tmp
- %TEMP%\~DF22D9.tmp
- %TEMP%\~DF20FE.tmp
- %TEMP%\~DF7DB5.tmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\MSWINSCK[1].OCX
- %TEMP%\~DFAD39.tmp
- %TEMP%\~DF5E8F.tmp
- %TEMP%\splash.bmp
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\MSWINSCK[1].OCX
- %TEMP%\~DF9B75.tmp
- %TEMP%\~DF2D1C.tmp
- %TEMP%\~DF414E.tmp
- %TEMP%\~DF2234.tmp
- %TEMP%\~DF75A8.tmp
- %TEMP%\~DF71CB.tmp
- %TEMP%\~DF4E30.tmp
- 'localhost':1087
- 'localhost':1090
- 'localhost':1093
- 'localhost':1078
- 'localhost':1081
- 'localhost':1084
- 'localhost':1096
- 'localhost':1108
- 'localhost':1111
- 'localhost':1114
- 'localhost':1099
- 'localhost':1102
- 'localhost':1105
- 'localhost':1075
- 'localhost':1045
- 'localhost':1048
- 'localhost':1051
- 'localhost':1036
- 'pd###.egloos.com':80
- 'localhost':1041
- 'localhost':1054
- 'localhost':1066
- 'localhost':1069
- 'localhost':1072
- 'localhost':1057
- 'localhost':1060
- 'localhost':1063
- pd###.egloos.com/pds/201401/25/40/MSWINSCK.OCX
- DNS ASK pd###.egloos.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''