Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Engine BitLocker Computer' = 'C:\lzkupsyls\yspobpm.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Link Registry Now Resolution Input Smart] 'Start' = '00000002'
- 'C:\lzkupsyls\mpkivswqtv.exe' "c:\lzkupsyls\yspobpm.exe"
- 'C:\lzkupsyls\yspobpm.exe'
- 'C:\lzkupsyls\tq39jrpcdiughiede.exe'
- C:\lzkupsyls\yspobpm.exe
- C:\lzkupsyls\mpkivswqtv.exe
- C:\lzkupsyls\uewvfb
- %WINDIR%\lzkupsyls\junm94zfj
- C:\lzkupsyls\junm94zfj
- C:\lzkupsyls\tq39jrpcdiughiede.exe
- C:\lzkupsyls\mpkivswqtv.exe
- C:\lzkupsyls\yspobpm.exe
- C:\lzkupsyls\tq39jrpcdiughiede.exe
- %WINDIR%\lzkupsyls\junm94zfj
- 'he###afraid.net':80
- 'di####ultafraid.net':80
- 'he###dinner.net':80
- 'di####ultcircle.net':80
- 'ne#####rymeasure.net':80
- 'pl####ntmeasure.net':80
- 'he###circle.net':80
- 'an####circle.net':80
- 'gl###afraid.net':80
- 'an####afraid.net':80
- 'gl###circle.net':80
- 'di####ultdinner.net':80
- 'he####easure.net':80
- 'di#####ltmeasure.net':80
- 'pl####ntdinner.net':80
- 'or###afraid.net':80
- 're####edinner.net':80
- 'or###dinner.net':80
- 're####eafraid.net':80
- 'le####measure.net':80
- 're####ecircle.net':80
- 'or###circle.net':80
- 'ne####aryafraid.net':80
- 'pl####ntafraid.net':80
- 'ne####arydinner.net':80
- 'pl####ntcircle.net':80
- 're####emeasure.net':80
- 'or####easure.net':80
- 'ne####arycircle.net':80
- 'va####sfather.net':80
- 'ge###ecarry.net':80
- 'he###carry.net':80
- 're####father.net':80
- 'va####sbuilt.net':80
- 're###napple.net':80
- 'va####sapple.net':80
- 'ge####father.net':80
- 'he###father.net':80
- 'he###ncarry.net':80
- 'he###apple.net':80
- 'ge###ebuilt.net':80
- 'he###built.net':80
- 'ge###eapple.net':80
- 're###nbuilt.net':80
- 'fo####dcircle.net':80
- 'de####circle.net':80
- 'fo####dafraid.net':80
- 'an####measure.net':80
- 'gl###dinner.net':80
- 'an####dinner.net':80
- 'gl####easure.net':80
- 'de####measure.net':80
- 're###ncarry.net':80
- 'va####scarry.net':80
- 'fo####dmeasure.net':80
- 'de####afraid.net':80
- 'fo####ddinner.net':80
- 'de####dinner.net':80
- http://he###afraid.net/index.php?me########
- http://di####ultafraid.net/index.php?me########
- http://he###dinner.net/index.php?me########
- http://di####ultcircle.net/index.php?me########
- http://ne#####rymeasure.net/index.php?me########
- http://pl####ntmeasure.net/index.php?me########
- http://he###circle.net/index.php?me########
- http://an####circle.net/index.php?me########
- http://gl###afraid.net/index.php?me########
- http://an####afraid.net/index.php?me########
- http://gl###circle.net/index.php?me########
- http://di####ultdinner.net/index.php?me########
- http://he####easure.net/index.php?me########
- http://di#####ltmeasure.net/index.php?me########
- http://pl####ntdinner.net/index.php?me########
- http://or###afraid.net/index.php?me########
- http://re####edinner.net/index.php?me########
- http://or###dinner.net/index.php?me########
- http://re####eafraid.net/index.php?me########
- http://le####measure.net/index.php?me########
- http://re####ecircle.net/index.php?me########
- http://or###circle.net/index.php?me########
- http://ne####aryafraid.net/index.php?me########
- http://pl####ntafraid.net/index.php?me########
- http://ne####arydinner.net/index.php?me########
- http://pl####ntcircle.net/index.php?me########
- http://re####emeasure.net/index.php?me########
- http://or####easure.net/index.php?me########
- http://ne####arycircle.net/index.php?me########
- http://va####sfather.net/index.php?me########
- http://ge###ecarry.net/index.php?me########
- http://he###carry.net/index.php?me########
- http://re####father.net/index.php?me########
- http://va####sbuilt.net/index.php?me########
- http://re###napple.net/index.php?me########
- http://va####sapple.net/index.php?me########
- http://ge####father.net/index.php?me########
- http://he###father.net/index.php?me########
- http://he###ncarry.net/index.php?me########
- http://he###apple.net/index.php?me########
- http://ge###ebuilt.net/index.php?me########
- http://he###built.net/index.php?me########
- http://ge###eapple.net/index.php?me########
- http://re###nbuilt.net/index.php?me########
- http://fo####dcircle.net/index.php?me########
- http://de####circle.net/index.php?me########
- http://fo####dafraid.net/index.php?me########
- http://an####measure.net/index.php?me########
- http://gl###dinner.net/index.php?me########
- http://an####dinner.net/index.php?me########
- http://gl####easure.net/index.php?me########
- http://de####measure.net/index.php?me########
- http://re###ncarry.net/index.php?me########
- http://va####scarry.net/index.php?me########
- http://fo####dmeasure.net/index.php?me########
- http://de####afraid.net/index.php?me########
- http://fo####ddinner.net/index.php?me########
- http://de####dinner.net/index.php?me########
- DNS ASK di####ultcircle.net
- DNS ASK he###afraid.net
- DNS ASK di####ultafraid.net
- DNS ASK he###circle.net
- DNS ASK pl####ntdinner.net
- DNS ASK ne#####rymeasure.net
- DNS ASK pl####ntmeasure.net
- DNS ASK gl###circle.net
- DNS ASK an####circle.net
- DNS ASK gl###afraid.net
- DNS ASK di#####ltmeasure.net
- DNS ASK he###dinner.net
- DNS ASK di####ultdinner.net
- DNS ASK he####easure.net
- DNS ASK ne####arydinner.net
- DNS ASK re####eafraid.net
- DNS ASK or###afraid.net
- DNS ASK re####edinner.net
- DNS ASK or###circle.net
- DNS ASK he####measure.net
- DNS ASK le####measure.net
- DNS ASK re####ecircle.net
- DNS ASK pl####ntcircle.net
- DNS ASK ne####aryafraid.net
- DNS ASK pl####ntafraid.net
- DNS ASK ne####arycircle.net
- DNS ASK or###dinner.net
- DNS ASK re####emeasure.net
- DNS ASK or####easure.net
- DNS ASK an####afraid.net
- DNS ASK va####sfather.net
- DNS ASK ge###ecarry.net
- DNS ASK he###carry.net
- DNS ASK re####father.net
- DNS ASK va####sbuilt.net
- DNS ASK re###napple.net
- DNS ASK va####sapple.net
- DNS ASK ge####father.net
- DNS ASK he###father.net
- DNS ASK he###ncarry.net
- DNS ASK he###apple.net
- DNS ASK ge###ebuilt.net
- DNS ASK he###built.net
- DNS ASK ge###eapple.net
- DNS ASK re###nbuilt.net
- DNS ASK fo####dcircle.net
- DNS ASK de####circle.net
- DNS ASK fo####dafraid.net
- DNS ASK an####measure.net
- DNS ASK gl###dinner.net
- DNS ASK an####dinner.net
- DNS ASK gl####easure.net
- DNS ASK de####measure.net
- DNS ASK re###ncarry.net
- DNS ASK va####scarry.net
- DNS ASK fo####dmeasure.net
- DNS ASK de####afraid.net
- DNS ASK fo####ddinner.net
- DNS ASK de####dinner.net
- ClassName: 'Shell_TrayWnd' WindowName: ''