Technical Information
- '%HOMEPATH%\1x5hr9r\dccrp.exe'
- '%HOMEPATH%\1x5hr9r\set.exe' QrKEiCYzz.ZDS
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- %HOMEPATH%\v8ki2u7q\mse.exe
- %HOMEPATH%\v8ki2u7q\bhhVSifMdzTH.EXN
- %HOMEPATH%\v8ki2u7q\TfzMClpVJ.THA
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\_filelst.cfg
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\drivetable.txt
- %HOMEPATH%\1x5hr9r\set.exe
- %HOMEPATH%\1x5hr9r\qDLsVoJsK.LMQ
- %HOMEPATH%\1x5hr9r\QrKEiCYzz.ZDS
- %HOMEPATH%\1x5hr9r\dccrp.exe
- %HOMEPATH%\1x5hr9r\rYYO.XNU
- %HOMEPATH%\1x5hr9r\rYYO.XNU
- %HOMEPATH%\v8ki2u7q\bhhVSifMdzTH.EXN
- %HOMEPATH%\v8ki2u7q\mse.exe
- %HOMEPATH%\1x5hr9r\qDLsVoJsK.LMQ
- %HOMEPATH%\1x5hr9r\set.exe
- %HOMEPATH%\1x5hr9r\QrKEiCYzz.ZDS
- <SYSTEM32>\Restore\MachineGuid.txt
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'