Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\] 'Host Process for Windows Services' = 'C:\2356057292917\svchost.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run\] 'Host Process for Windows Services' = 'C:\2356057292917\svchost.exe'
- <Drive name for removable media>:\__\drivemgr.exe
- <Drive name for removable media>:\stoc13_ml_quoc_le.pptx
- <Drive name for removable media>:\file1.ppt
- <Drive name for removable media>:\sim_gametheory_to_finance.ppt
- <Drive name for removable media>:\sacs_presentation_sacs_qep_improving_rt_education_final.ppt
- <Drive name for removable media>:\proposaltemplates.ppt
- <Drive name for removable media>:\accountsreceivable.ppt
- <Drive name for removable media>:\bg_search_box.png
- <Drive name for removable media>:\arrow-down.png
- <Drive name for removable media>:\breakpoint.png
- <Drive name for removable media>:\dissolveanother.png
- <Drive name for removable media>:\asaprojectcompetition.pptx
- <Drive name for removable media>:\block.png
- <Drive name for removable media>:\cert.pem
- <Drive name for removable media>:\irgeek.pem
- <Drive name for removable media>:\hhhlcert.pem
- <Drive name for removable media>:\ck_ugo.pem
- <Drive name for removable media>:\dualectls.pdf
- <Drive name for removable media>:\lom602.pdf
- <Drive name for removable media>:\bc01.pdf
- <Drive name for removable media>:\spib_pima.pdf
- <Drive name for removable media>:\7790_preview.pdf
- <Drive name for removable media>:\ff_ot_user_guide.pdf
- <Drive name for removable media>:\ck.pem
- <Drive name for removable media>:\flower_trans_matte.wmv
- <Drive name for removable media>:\1sm_price.zip
- <Drive name for removable media>:\indogerman2010.pptx
- <Drive name for removable media>:\contractualdeadlines.zip
- <Drive name for removable media>:\price.zip
- <Drive name for removable media>:\national_autism_preparation_programs.xlsx
- <Drive name for removable media>:\al.xlsx
- <Drive name for removable media>:\2013_finalsummaryforweb.xlsx
- <Drive name for removable media>:\trtf_matrix2012_oct.xlsx
- <Drive name for removable media>:\disclosuredetails.xlsx
- <Drive name for removable media>:\highly_cited_2001.xlsx
- <Drive name for removable media>:\excel_example.xls
- <Drive name for removable media>:\removedtitles_records.xls
- <Drive name for removable media>:\video_1.mp4
- <Drive name for removable media>:\contractualdeadlines.xls
- <Drive name for removable media>:\babyboymaintonotesbackground_pal.wmv
- <Drive name for removable media>:\phytoremediation.rtf
- <Drive name for removable media>:\router_manual.rtf
- <Drive name for removable media>:\myhrvoldhanssenbiharfamine.rtf
- <Drive name for removable media>:\static_electricity_easy_and_quick_activities.rtf
- <Drive name for removable media>:\schema.rdf
- <Drive name for removable media>:\contenttypes.rdf
- <Drive name for removable media>:\20140114.rdf
- <Drive name for removable media>:\swc_2009-03-02.rdf
- <Drive name for removable media>:\foaf.rdf
- <Drive name for removable media>:\middaugh_keynote.pptx
- <Drive name for removable media>:\roozenedowebinar.pptx
- <Drive name for removable media>:\d0068197bb5a41fea16a220c45390606.mp4
- <Drive name for removable media>:\tcm851ax32.exe
- <Drive name for removable media>:\nwfieldnotes1966.docx
- <Drive name for removable media>:\aoc_saq_d_v3_merchant.docx
- <Drive name for removable media>:\glidescope_review_rev_010.docx
- <Drive name for removable media>:\hadac_newsletter_july_2010_final.docx
- <Drive name for removable media>:\cveuropeo.doc
- <Drive name for removable media>:\ovp25012015.doc
- <Drive name for removable media>:\508softwareandos.doc
- <Drive name for removable media>:\sdksampleprivdeveloper.cer
- <Drive name for removable media>:\contosoroot_1.cer
- <Drive name for removable media>:\contoso.cer
- <Drive name for removable media>:\sdszfo.docx
- <Drive name for removable media>:\sdkfailsafeemulator.cer
- <Drive name for removable media>:\dashborder_120.bmp
- <Drive name for removable media>:\coffee.bmp
- <Drive name for removable media>:\toolbar.bmp
- <Drive name for removable media>:\dashborder_96.bmp
- <Drive name for removable media>:\dashborder_144.bmp
- <Drive name for removable media>:\split.avi
- <Drive name for removable media>:\join.avi
- <Drive name for removable media>:\correct.avi
- <Drive name for removable media>:\000814251_video_01.avi
- <Drive name for removable media>:\.lnk
- <Drive name for removable media>:\default.bmp
- <Drive name for removable media>:\trivial-merge.html
- <Drive name for removable media>:\spanner.mov
- <Drive name for removable media>:\calc.exe
- <Drive name for removable media>:\dag2_panel1_320_ref.mov
- <Drive name for removable media>:\firefly1.mov
- <Drive name for removable media>:\pushkin.jpg
- <Drive name for removable media>:\210252809.jpg
- <Drive name for removable media>:\1189.jpg
- <Drive name for removable media>:\4f0bf7ff71f28.jpg
- <Drive name for removable media>:\2.jpg
- <Drive name for removable media>:\3.jpeg
- <Drive name for removable media>:\210252809.jpeg
- <Drive name for removable media>:\about.html
- <Drive name for removable media>:\51.mp4
- <Drive name for removable media>:\howto-index.html
- <Drive name for removable media>:\adadsi.html
- <Drive name for removable media>:\api-hashmap.html
- <Drive name for removable media>:\alert.html
- <Drive name for removable media>:\about.htm
- <Drive name for removable media>:\alert.htm
- <Drive name for removable media>:\advice_process.htm
- <Drive name for removable media>:\iisstart.htm
- <Drive name for removable media>:\tree_view.htm
- <Drive name for removable media>:\notepad.exe
- <Drive name for removable media>:\winmine.exe
- <Drive name for removable media>:\wrar520.exe
- <Drive name for removable media>:\productos.zip
- Windows Security Center
- '' (downloaded from the Internet)
- %TEMP%\4172.exe
- C:\2356057292917\svchost.exe
- %TEMP%\1320815914.exe
- %TEMP%\2632627420.exe
- C:\2356057292917\svchost.exe
- <Drive name for removable media>:\.lnk
- http://tl##net.top/pe/64.exe
- http://ef####uhdehduhgk.ws/3
- http://ef####uhdehduhgk.ws/2
- http://ef####uhdehduhgk.ws/1
- http://ok####eoehghaoek.ws/6
- http://ok####eoehghaoek.ws/5
- http://ok####eoehghaoek.ws/4
- http://fa####azdezgzgfk.ws/6
- http://ok####eoehghaoek.ws/3
- http://ok####eoehghaoek.ws/1
- http://wd####aueeubffgk.ws/6
- http://wd####aueeubffgk.ws/5
- http://wd####aueeubffgk.ws/4
- http://wd####aueeubffgk.ws/3
- http://wd####aueeubffgk.ws/2
- http://ok####eoehghaoek.ws/2
- http://wd####aueeubffgk.ws/1
- http://ef####uhdehduhgk.ws/4
- http://de####afzgezzfgk.ws/1
- http://ga####buwdbuguuk.ws/2
- http://ga####buwdbuguuk.ws/1
- http://de####afzgezzfgk.ws/6
- http://de####afzgezzfgk.ws/5
- http://de####afzgezzfgk.ws/4
- http://de####afzgezzfgk.ws/3
- http://ef####uhdehduhgk.ws/6
- http://ef####uhdehduhgk.ws/5
- http://ea####dzefverrgk.ws/6
- http://ea####dzefverrgk.ws/5
- http://ea####dzefverrgk.ws/4
- http://ea####dzefverrgk.ws/3
- http://ea####dzefverrgk.ws/2
- http://ea####dzefverrgk.ws/1
- http://de####afzgezzfgk.ws/2
- http://fa####azdezgzgfk.ws/5
- http://fa####azdezgzgfk.ws/4
- http://fa####azdezgzgfk.ws/3
- http://se####ehfueughek.ws/6
- http://se####ehfueughek.ws/5
- http://se####ehfueughek.ws/4
- http://se####ehfueughek.ws/3
- http://se####ehfueughek.ws/2
- http://fe####uhduhuehdk.ws/2
- http://se####ehfueughek.ws/1
- http://wo#m.ws/5
- http://wo#m.ws/4
- http://wo#m.ws/3
- http://wo#m.ws/2
- http://wo#m.ws/1
- http://ap#.##pmania.com/
- http://wo#m.ws/6
- http://fe####uhduhuehdk.ws/3
- http://fe####uhduhuehdk.ws/1
- http://fe####uhduhuehdk.ws/4
- http://fa####azdezgzgfk.ws/2
- http://fh####wdzwgzdggk.ws/1
- http://fa####azdezgzgfk.ws/1
- http://fh####wdzwgzdggk.ws/6
- http://fh####wdzwgzdggk.ws/5
- http://fh####wdzwgzdggk.ws/4
- http://fh####wdzwgzdggk.ws/3
- http://fh####wdzwgzdggk.ws/2
- http://fe####eudughuurk.ws/6
- http://fe####uhduhuehdk.ws/5
- http://fe####eudughuurk.ws/5
- http://fe####eudughuurk.ws/4
- http://fe####eudughuurk.ws/3
- http://fe####eudughuurk.ws/2
- http://fe####eudughuurk.ws/1
- http://fe####uhduhuehdk.ws/6
- http://ga####buwdbuguuk.ws/3
- http://ga####buwdbuguuk.ws/4
- DNS ASK tl##net.top
- DNS ASK ap#.##pmania.com
- DNS ASK wo#m.ws
- DNS ASK se####ehfueughek.ws
- DNS ASK fe####uhduhuehdk.ws
- DNS ASK fe####eudughuurk.ws
- DNS ASK fh####wdzwgzdggk.ws
- DNS ASK fa####azdezgzgfk.ws
- DNS ASK wd####aueeubffgk.ws
- DNS ASK ok####eoehghaoek.ws
- DNS ASK ef####uhdehduhgk.ws
- DNS ASK ea####dzefverrgk.ws
- DNS ASK de####afzgezzfgk.ws
- DNS ASK ga####buwdbuguuk.ws
- '%TEMP%\4172.exe'
- 'C:\2356057292917\svchost.exe'
- '%TEMP%\1320815914.exe'
- '%TEMP%\2632627420.exe'