General Info

File name

IMG-0004_Pdf.vbs

Full analysis
https://app.any.run/tasks/a7ee67c5-935b-473a-b1cd-8709dd7b0c1e
Verdict
Malicious activity
Analysis date
3/14/2019, 22:21:48
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
quasar
trojan
evasion
xpertrat
Indicators:

MIME:
text/plain
File info:
ASCII text, with very long lines, with CRLF line terminators
MD5

b39d7a67ee1d0fe23e9a42aa3d402fa5

SHA1

c013f956f12f7393141857175b3da32b60c18639

SHA256

20cffa5b0018fe877639e424cb7b1ebeafd72a420885e1bc3efc8a4715a07f07

SSDEEP

24576:z6E4u88sxzaJ8X1aPa/iFEQvmJC/F8yQQFAZVMiFkvW8tyld8YQOC5hFCf0PA6Fl:M1rhaTmJC/lIZjkPXWj7Wn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Writes to a start menu file
  • Host.exe (PID: 3768)
  • file1name.exe (PID: 2472)
  • WScript.exe (PID: 2708)
  • wscript.exe (PID: 3272)
QUASAR was detected
  • Client-built Quasar Mine Startup.exe (PID: 3736)
  • Client-built Quasar Mine Startup.exe (PID: 3092)
Application was dropped or rewritten from another process
  • Host.exe (PID: 2336)
  • server 2019.exe (PID: 2316)
  • server 2019.exe (PID: 3456)
  • Client-built Quasar Mine Startup.exe (PID: 3736)
  • Host.exe (PID: 3768)
  • server 2019.exe (PID: 3848)
  • server 2019.exe (PID: 3868)
  • file1name.exe (PID: 2544)
  • Client-built Quasar Mine Startup.exe (PID: 3092)
  • file1name.exe (PID: 2472)
XPERTRAT was detected
  • iexplore.exe (PID: 3044)
UAC/LUA settings modification
  • server 2019.exe (PID: 3456)
  • server 2019.exe (PID: 3848)
Connects to CnC server
  • iexplore.exe (PID: 3044)
  • wscript.exe (PID: 3272)
Changes the autorun value in the registry
  • WScript.exe (PID: 2708)
  • wscript.exe (PID: 3272)
Drops/Copies Quasar RAT executable
  • file1name.exe (PID: 2472)
Executable content was dropped or overwritten
  • Host.exe (PID: 3768)
  • file1name.exe (PID: 2544)
  • file1name.exe (PID: 2472)
  • WScript.exe (PID: 3060)
Checks for external IP
  • Client-built Quasar Mine Startup.exe (PID: 3736)
  • Client-built Quasar Mine Startup.exe (PID: 3092)
Application launched itself
  • Host.exe (PID: 3768)
  • file1name.exe (PID: 2472)
  • WScript.exe (PID: 2708)
  • WScript.exe (PID: 3060)
Connects to unusual port
  • iexplore.exe (PID: 3044)
  • Host.exe (PID: 2336)
  • wscript.exe (PID: 3272)
Creates files in the user directory
  • iexplore.exe (PID: 3044)
  • file1name.exe (PID: 2544)
  • file1name.exe (PID: 2472)
  • WScript.exe (PID: 2708)
Starts Internet Explorer
  • server 2019.exe (PID: 3848)
Executes scripts
  • WScript.exe (PID: 2708)
  • WScript.exe (PID: 3060)

No info indicators.

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

Screenshots

Processes

Total processes
48
Monitored processes
14
Malicious processes
10
Suspicious processes
1

Behavior graph

+
drop and start start drop and start drop and start drop and start drop and start wscript.exe file1name.exe wscript.exe wscript.exe #QUASAR client-built quasar mine startup.exe server 2019.exe no specs server 2019.exe file1name.exe host.exe #XPERTRAT iexplore.exe #QUASAR client-built quasar mine startup.exe server 2019.exe no specs server 2019.exe host.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3060
CMD
"C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\IMG-0004_Pdf.vbs"
Path
C:\Windows\System32\WScript.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft ® Windows Based Script Host
Version
5.8.7600.16385
Modules
Image
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vbscript.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\msisip.dll
c:\windows\system32\wshext.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\scrobj.dll
c:\windows\system32\scrrun.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\system\ado\msado15.dll
c:\windows\system32\msdart.dll
c:\windows\system32\wshom.ocx
c:\windows\system32\mpr.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sspicli.dll
c:\users\admin\appdata\local\temp\file1name.exe

PID
2472
CMD
"C:\Users\admin\AppData\Local\Temp\file1name.exe"
Path
C:\Users\admin\AppData\Local\Temp\file1name.exe
Indicators
Parent process
WScript.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\file1name.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\mpr.dll
c:\windows\system32\wininet.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\psapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\sspicli.dll
c:\users\admin\appdata\roaming\client-built quasar mine startup.exe
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\users\admin\appdata\roaming\server 2019.exe

PID
2708
CMD
"C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\file2name.vbs"
Path
C:\Windows\System32\WScript.exe
Indicators
Parent process
WScript.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft ® Windows Based Script Host
Version
5.8.7600.16385
Modules
Image
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vbscript.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\msisip.dll
c:\windows\system32\wshext.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\scrobj.dll
c:\windows\system32\wshom.ocx
c:\windows\system32\mpr.dll
c:\windows\system32\scrrun.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\sspicli.dll

PID
3272
CMD
"C:\Windows\System32\wscript.exe" //B "C:\Users\admin\AppData\Roaming\file2name.vbs"
Path
C:\Windows\System32\wscript.exe
Indicators
Parent process
WScript.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Microsoft ® Windows Based Script Host
Version
5.8.7600.16385
Modules
Image
c:\windows\system32\wscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vbscript.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\msisip.dll
c:\windows\system32\wshext.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\scrobj.dll
c:\windows\system32\wshom.ocx
c:\windows\system32\mpr.dll
c:\windows\system32\scrrun.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wbem\wbemdisp.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll

PID
3092
CMD
"C:\Users\admin\AppData\Roaming\Client-built Quasar Mine Startup.exe"
Path
C:\Users\admin\AppData\Roaming\Client-built Quasar Mine Startup.exe
Indicators
Parent process
file1name.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
1.3.0.0
Modules
Image
c:\users\admin\appdata\roaming\client-built quasar mine startup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\system32\oleaut32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\646b4b01cb29986f8e076aa65c9e9753\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\5aac750b35b27770dccb1a43f83cced7\system.windows.forms.ni.dll
c:\windows\system32\uxtheme.dll
c:\windows\microsoft.net\assembly\gac_msil\system.windows.forms\v4.0_4.0.0.0__b77a5c561934e089\system.windows.forms.dll
c:\windows\system32\shell32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\55560c2014611e9119f99923c9ebdeef\system.core.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\system32\bcrypt.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.management\4dfa27fdd6a4cce26f99585e1c744f9b\system.management.ni.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\microsoft.net\framework\v4.0.30319\wminet_utils.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.runteb92aa12#\c56771a9cfb87e660d60453e232abe27\system.runtime.serialization.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\smdiagnostics\4a2a848ea1fea1a74d5aa2f1c21c5ce8\smdiagnostics.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\46957030830964165644b52b0696c5d9\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\d86b080a37c60a872c82b912a2a63dac\system.xml.ni.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.servd1dec626#\52e9ac689c75dd011f0f7e827551e985\system.servicemodel.internals.ni.dll

PID
3868
CMD
"C:\Users\admin\AppData\Roaming\server 2019.exe"
Path
C:\Users\admin\AppData\Roaming\server 2019.exe
Indicators
No indicators
Parent process
file1name.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Abronsius
Description
Update
Version
3.00.0010
Modules
Image
c:\users\admin\appdata\roaming\server 2019.exe
c:\systemroot\system32\ntdll.dll

PID
3848
CMD
"C:\Users\admin\AppData\Roaming\server 2019.exe"
Path
C:\Users\admin\AppData\Roaming\server 2019.exe
Indicators
Parent process
file1name.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Abronsius
Description
Update
Version
3.00.0010
Modules
Image
c:\users\admin\appdata\roaming\server 2019.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\psapi.dll
c:\program files\internet explorer\iexplore.exe

PID
2544
CMD
"C:\Users\admin\AppData\Local\Temp\file1name.exe"
Path
C:\Users\admin\AppData\Local\Temp\file1name.exe
Indicators
Parent process
file1name.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\file1name.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\roaming\install\host.exe

PID
3768
CMD
"C:\Users\admin\AppData\Roaming\Install\Host.exe"
Path
C:\Users\admin\AppData\Roaming\Install\Host.exe
Indicators
Parent process
file1name.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\roaming\install\host.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\mpr.dll
c:\windows\system32\wininet.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\psapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\users\admin\appdata\roaming\client-built quasar mine startup.exe
c:\users\admin\appdata\roaming\server 2019.exe

PID
3044
CMD
C:\Users\admin\AppData\Roaming\server 2019.exe
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
server 2019.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shacct.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\samlib.dll
c:\windows\system32\propsys.dll
c:\windows\system32\scrrun.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wbem\wbemdisp.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\avicap32.dll
c:\windows\system32\msvfw32.dll

PID
3736
CMD
"C:\Users\admin\AppData\Roaming\Client-built Quasar Mine Startup.exe"
Path
C:\Users\admin\AppData\Roaming\Client-built Quasar Mine Startup.exe
Indicators
Parent process
Host.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
1.3.0.0
Modules
Image
c:\users\admin\appdata\roaming\client-built quasar mine startup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\system32\oleaut32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\646b4b01cb29986f8e076aa65c9e9753\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\5aac750b35b27770dccb1a43f83cced7\system.windows.forms.ni.dll
c:\windows\system32\uxtheme.dll
c:\windows\microsoft.net\assembly\gac_msil\system.windows.forms\v4.0_4.0.0.0__b77a5c561934e089\system.windows.forms.dll
c:\windows\system32\shell32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\55560c2014611e9119f99923c9ebdeef\system.core.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\system32\bcrypt.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.management\4dfa27fdd6a4cce26f99585e1c744f9b\system.management.ni.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\microsoft.net\framework\v4.0.30319\wminet_utils.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.runteb92aa12#\c56771a9cfb87e660d60453e232abe27\system.runtime.serialization.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\smdiagnostics\4a2a848ea1fea1a74d5aa2f1c21c5ce8\smdiagnostics.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\46957030830964165644b52b0696c5d9\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\d86b080a37c60a872c82b912a2a63dac\system.xml.ni.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.servd1dec626#\52e9ac689c75dd011f0f7e827551e985\system.servicemodel.internals.ni.dll

PID
2316
CMD
"C:\Users\admin\AppData\Roaming\server 2019.exe"
Path
C:\Users\admin\AppData\Roaming\server 2019.exe
Indicators
No indicators
Parent process
Host.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Abronsius
Description
Update
Version
3.00.0010
Modules
Image
c:\users\admin\appdata\roaming\server 2019.exe
c:\systemroot\system32\ntdll.dll

PID
3456
CMD
"C:\Users\admin\AppData\Roaming\server 2019.exe"
Path
C:\Users\admin\AppData\Roaming\server 2019.exe
Indicators
Parent process
Host.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Abronsius
Description
Update
Version
3.00.0010
Modules
Image
c:\users\admin\appdata\roaming\server 2019.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll

PID
2336
CMD
"C:\Users\admin\AppData\Roaming\Install\Host.exe"
Path
C:\Users\admin\AppData\Roaming\Install\Host.exe
Indicators
Parent process
Host.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\roaming\install\host.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wshtcpip.dll

Registry activity

Total events
2863
Read events
1408
Write events
1455
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
3060
WScript.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3060
WScript.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2472
file1name.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2472
file1name.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2708
WScript.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\file2name
false - 3/14/2019
2708
WScript.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
file2name
wscript.exe //B "C:\Users\admin\AppData\Roaming\file2name.vbs"
2708
WScript.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
file2name
wscript.exe //B "C:\Users\admin\AppData\Roaming\file2name.vbs"
2708
WScript.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2708
WScript.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3272
wscript.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
file2name
wscript.exe //B "C:\Users\admin\AppData\Roaming\file2name.vbs"
3272
wscript.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
file2name
wscript.exe //B "C:\Users\admin\AppData\Roaming\file2name.vbs"
3272
wscript.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wscript_RASAPI32
EnableFileTracing
0
3272
wscript.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wscript_RASAPI32
EnableConsoleTracing
0
3272
wscript.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wscript_RASAPI32
FileTracingMask
4294901760
3272
wscript.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wscript_RASAPI32
ConsoleTracingMask
4294901760
3272
wscript.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wscript_RASAPI32
MaxFileSize
1048576
3272
wscript.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wscript_RASAPI32
FileDirectory
%windir%\tracing
3272
wscript.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wscript_RASMANCS
EnableFileTracing
0
3272
wscript.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wscript_RASMANCS
EnableConsoleTracing
0
3272
wscript.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wscript_RASMANCS
FileTracingMask
4294901760
3272
wscript.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wscript_RASMANCS
ConsoleTracingMask
4294901760
3272
wscript.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wscript_RASMANCS
MaxFileSize
1048576
3272
wscript.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\wscript_RASMANCS
FileDirectory
%windir%\tracing
3272
wscript.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3272
wscript.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3272
wscript.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3272
wscript.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3092
Client-built Quasar Mine Startup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Client-built Quasar Mine Startup_RASAPI32
EnableFileTracing
0
3092
Client-built Quasar Mine Startup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Client-built Quasar Mine Startup_RASAPI32
EnableConsoleTracing
0
3092
Client-built Quasar Mine Startup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Client-built Quasar Mine Startup_RASAPI32
FileTracingMask
4294901760
3092
Client-built Quasar Mine Startup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Client-built Quasar Mine Startup_RASAPI32
ConsoleTracingMask
4294901760
3092
Client-built Quasar Mine Startup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Client-built Quasar Mine Startup_RASAPI32
MaxFileSize
1048576
3092
Client-built Quasar Mine Startup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Client-built Quasar Mine Startup_RASAPI32
FileDirectory
%windir%\tracing
3092
Client-built Quasar Mine Startup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Client-built Quasar Mine Startup_RASMANCS
EnableFileTracing
0
3092
Client-built Quasar Mine Startup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Client-built Quasar Mine Startup_RASMANCS
EnableConsoleTracing
0
3092
Client-built Quasar Mine Startup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Client-built Quasar Mine Startup_RASMANCS
FileTracingMask
4294901760
3092
Client-built Quasar Mine Startup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Client-built Quasar Mine Startup_RASMANCS
ConsoleTracingMask
4294901760
3092
Client-built Quasar Mine Startup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Client-built Quasar Mine Startup_RASMANCS
MaxFileSize
1048576
3092
Client-built Quasar Mine Startup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Client-built Quasar Mine Startup_RASMANCS
FileDirectory
%windir%\tracing
3848
server 2019.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
UACDisableNotify
0
3848
server 2019.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
EnableLUA
0
3768
Host.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3768
Host.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3456
server 2019.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
UACDisableNotify
0
3456
server 2019.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
EnableLUA
0

Files activity

Executable files
6
Suspicious files
2
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
2472
file1name.exe
C:\Users\admin\autoplay\lpkinstall.exe
executable
MD5: ccd6ec17da46f8284677a341a8b298d7
SHA256: ef4a7b11f58bff81221253bdcc98267d5a2fc2dd30f74c8606d9b32d6d219e1c
2544
file1name.exe
C:\Users\admin\AppData\Roaming\Install\Host.exe
executable
MD5: 8a7460a38686b86cca4eef2cf917e2f5
SHA256: 5ef69ae84192946a72b92582acaf23153cd07c9010c1c86fead98daed052d120
2472
file1name.exe
C:\Users\admin\AppData\Roaming\server 2019.exe
executable
MD5: 3146f4dd38096e1fe25844d859098f7b
SHA256: feef025eaebb31b58e46d7d0e8db5f0e0352f26bb210874a540b514545940365
2472
file1name.exe
C:\Users\admin\AppData\Roaming\Client-built Quasar Mine Startup.exe
executable
MD5: 408ca61e9af4b5bd019f76a9a9aad115
SHA256: 6044f2494a476c978e606ef185bd6ec5a12e1286161a217f220895540a829760
3060
WScript.exe
C:\Users\admin\AppData\Local\Temp\file1name.exe
executable
MD5: 8a7460a38686b86cca4eef2cf917e2f5
SHA256: 5ef69ae84192946a72b92582acaf23153cd07c9010c1c86fead98daed052d120
3768
Host.exe
C:\Users\admin\autoplay\lpkinstall.exe
executable
MD5: 45fbb926d893bd14ba7c652cb86f2e32
SHA256: 2bc5948f0f737454b7b3500e618420850914c5fab68fb321918fa2d4179e63db
3044
iexplore.exe
C:\Users\admin\AppData\Roaming\Q4V8N5Y3-O0F7-Q7T5-B113-K7R6L4T0H6H6
binary
MD5: 6c0a13d08a0083e44facde90203edc18
SHA256: 415378a93b19695ec2a833daa8c3063a5f5b7f86ddec5f17840e75049ffcae31
2472
file1name.exe
C:\Users\admin\autoplay\WSManHTTPConfig.vbs
text
MD5: 5d8e8cdcdde5e0994615b01f50e92cb8
SHA256: 2c5eccb72f7a472a5dab91be50b5deead68105dde78eae755fb878d1373cf4be
3456
server 2019.exe
C:\Users\admin\AppData\Local\Temp\~DF58FE3387DF003D70.TMP
––
MD5:  ––
SHA256:  ––
3848
server 2019.exe
C:\Users\admin\AppData\Local\Temp\~DFB52C93A6B63FCBCA.TMP
––
MD5:  ––
SHA256:  ––
3060
WScript.exe
C:\Users\admin\AppData\Local\Temp\file2name.vbs
text
MD5: 03172be4fac787dbda0fb5f55340f366
SHA256: 76fc99f14c62184745594f3c1557883a9739f94449e001015b4b7a33d6dcba1f
3044
iexplore.exe
C:\Users\admin\AppData\Roaming\ut
image
MD5: a634cb7eb39b833d885186b5ba1023f2
SHA256: 8806d6fd705d67f18eaa6c95806d405cd3a3a56e41636958a408973f602daebf
3044
iexplore.exe
C:\Users\admin\AppData\Local\Temp\admin.bmp
image
MD5: 343fa15c150a516b20cc9f787cfd530e
SHA256: d632e9dbacdcd8f6b86ba011ed6b23f961d104869654caa764216ea57a916524
3768
Host.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WSManHTTPConfig.url
text
MD5: 29085ba014dfcdefdbd88a222c469570
SHA256: c9b5c898cb635ec569b1afcc6dcdc0d3a186e4dfda267d18dcd4508e2bb63d47
3272
wscript.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\file2name.vbs
text
MD5: 03172be4fac787dbda0fb5f55340f366
SHA256: 76fc99f14c62184745594f3c1557883a9739f94449e001015b4b7a33d6dcba1f
3044
iexplore.exe
C:\Users\admin\AppData\Roaming\Q4V8N5Y3-O0F7-Q7T5-B113-K7R6L4T0H6H6.pas
binary
MD5: 676a200b4123806b775df9ec5cc6b10c
SHA256: 6a9adf7b6a91080b55db9c90c2ae30c186645378798f7b8ad1e636775f19e828
3272
wscript.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\file2name.vbs
––
MD5:  ––
SHA256:  ––
2708
WScript.exe
C:\Users\admin\AppData\Roaming\file2name.vbs
text
MD5: 03172be4fac787dbda0fb5f55340f366
SHA256: 76fc99f14c62184745594f3c1557883a9739f94449e001015b4b7a33d6dcba1f
2708
WScript.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\file2name.vbs
text
MD5: 03172be4fac787dbda0fb5f55340f366
SHA256: 76fc99f14c62184745594f3c1557883a9739f94449e001015b4b7a33d6dcba1f
2472
file1name.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WSManHTTPConfig.url
text
MD5: 29085ba014dfcdefdbd88a222c469570
SHA256: c9b5c898cb635ec569b1afcc6dcdc0d3a186e4dfda267d18dcd4508e2bb63d47
3768
Host.exe
C:\Users\admin\autoplay\WSManHTTPConfig.vbs
text
MD5: 5d8e8cdcdde5e0994615b01f50e92cb8
SHA256: 2c5eccb72f7a472a5dab91be50b5deead68105dde78eae755fb878d1373cf4be

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
702
TCP/UDP connections
711
DNS requests
5
Threats
737

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3092 Client-built Quasar Mine Startup.exe GET 200 185.194.141.58:80 http://ip-api.com/json/ DE
text
shared
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3736 Client-built Quasar Mine Startup.exe GET 200 185.194.141.58:80 http://ip-api.com/json/ DE
text
shared
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST 200 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
text
malicious
3272 wscript.exe POST –– 51.89.0.136:1077 http://leew.linkpc.net:1077/is-ready GB
text
––
––
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3272 wscript.exe 51.89.0.136:1077 GB malicious
3092 Client-built Quasar Mine Startup.exe 185.194.141.58:80 netcup GmbH DE suspicious
3044 iexplore.exe 51.89.0.136:1011 GB malicious
2336 Host.exe 51.89.0.136:3366 GB malicious
3736 Client-built Quasar Mine Startup.exe 185.194.141.58:80 netcup GmbH DE suspicious

DNS requests

Domain IP Reputation
leew.linkpc.net 51.89.0.136
malicious
manuel3.publicvm.com 51.89.0.136
malicious
ip-api.com 185.194.141.58
shared

Threats

PID Process Class Message
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3092 Client-built Quasar Mine Startup.exe Potential Corporate Privacy Violation ET POLICY External IP Lookup ip-api.com
3092 Client-built Quasar Mine Startup.exe A Network Trojan was detected MALWARE [PTsecurity] Quasar 1.3 RAT IP Lookup ip-api.com (HTTP headeer)
3044 iexplore.exe A Network Trojan was detected MALWARE [PTsecurity] XpertRAT
3044 iexplore.exe A Network Trojan was detected MALWARE [PTsecurity] XpertRAT
3736 Client-built Quasar Mine Startup.exe Potential Corporate Privacy Violation ET POLICY External IP Lookup ip-api.com
3736 Client-built Quasar Mine Startup.exe A Network Trojan was detected MALWARE [PTsecurity] Quasar 1.3 RAT IP Lookup ip-api.com (HTTP headeer)
3044 iexplore.exe A Network Trojan was detected MALWARE [PTsecurity] XpertRAT
3044 iexplore.exe A Network Trojan was detected MALWARE [PTsecurity] XpertRAT
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3044 iexplore.exe A Network Trojan was detected MALWARE [PTsecurity] XpertRAT
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3044 iexplore.exe A Network Trojan was detected MALWARE [PTsecurity] XpertRAT
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3044 iexplore.exe A Network Trojan was detected MALWARE [PTsecurity] XpertRAT
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3044 iexplore.exe A Network Trojan was detected MALWARE [PTsecurity] XpertRAT
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3044 iexplore.exe A Network Trojan was detected MALWARE [PTsecurity] XpertRAT
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Worm Checkin 1
3272 wscript.exe A Network Trojan was detected ET TROJAN Worm.VBS Dunihi/Houdini/H-Wor