Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Procedure Discovery Information Now' = 'C:\qbpafjwr\wejnvekqkulr.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Center Authentication DCOM] 'ImagePath' = 'C:\qbpafjwr\wejnvekqkulr.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Center Authentication DCOM] 'Start' = '00000002'
- 'C:\qbpafjwr\rpeqzhvzgvym.exe' "c:\qbpafjwr\wejnvekqkulr.exe"
- 'C:\qbpafjwr\wejnvekqkulr.exe'
- 'C:\qbpafjwr\hcx62w0cpccbeqgtktyk.exe'
- C:\qbpafjwr\wejnvekqkulr.exe
- C:\qbpafjwr\rpeqzhvzgvym.exe
- C:\qbpafjwr\ebbnnlkhi
- %WINDIR%\qbpafjwr\m5yhdjr
- C:\qbpafjwr\m5yhdjr
- C:\qbpafjwr\hcx62w0cpccbeqgtktyk.exe
- C:\qbpafjwr\rpeqzhvzgvym.exe
- C:\qbpafjwr\wejnvekqkulr.exe
- C:\qbpafjwr\hcx62w0cpccbeqgtktyk.exe
- %WINDIR%\qbpafjwr\m5yhdjr
- 'wa###around.net':80
- 'th####tproud.net':80
- 'wa####elcome.net':80
- 'th####taround.net':80
- 'wa####omplete.net':80
- 'wo####elcome.net':80
- 'wa###proud.net':80
- 'th####tcomplete.net':80
- 'th####twelcome.net':80
- 'su####around.net':80
- 'cr###around.net':80
- 'su####welcome.net':80
- 'cr####elcome.net':80
- 'su####complete.net':80
- 'cr####omplete.net':80
- 'su###rproud.net':80
- 'cr###proud.net':80
- 'pa###proud.net':80
- 'fi###proud.net':80
- 'pa###around.net':80
- 'fi###around.net':80
- 'fr###nature.net':80
- 'ex#####ncenature.net':80
- 'pa####omplete.net':80
- 'fi####omplete.net':80
- 'fi####elcome.net':80
- 'sm###around.net':80
- 'wo###proud.net':80
- 'sm####elcome.net':80
- 'wo###around.net':80
- 'sm####omplete.net':80
- 'pa####elcome.net':80
- 'sm###proud.net':80
- 'wo####omplete.net':80
- 'kn####omplete.net':80
- 'ge#####anwelcome.net':80
- 'al####ywelcome.net':80
- 'fr####omplete.net':80
- 'ex#####ncecomplete.net':80
- 'ge####manproud.net':80
- 'al####yproud.net':80
- 'ge####manaround.net':80
- 'al####yaround.net':80
- 'ex####enceproud.net':80
- 'fi####robable.net':80
- 'fr####elcome.net':80
- 'fi####itchen.net':80
- 'pa####robable.net':80
- 'ex#####ncearound.net':80
- 'fr###proud.net':80
- 'ex#####ncewelcome.net':80
- 'fr###around.net':80
- 'kn####elcome.net':80
- 'be###around.net':80
- 'me####complete.net':80
- 'be####elcome.net':80
- 'kn###proud.net':80
- 'be####omplete.net':80
- 'kn###around.net':80
- 'be###proud.net':80
- 'fo####complete.net':80
- 'fo####welcome.net':80
- 'me####welcome.net':80
- 'ge#####ancomplete.net':80
- 'al####ycomplete.net':80
- 'fo###wproud.net':80
- 'me###rproud.net':80
- 'fo####around.net':80
- 'me####around.net':80
- http://wa###around.net/index.php
- http://th####tproud.net/index.php
- http://wa####elcome.net/index.php
- http://th####taround.net/index.php
- http://wa####omplete.net/index.php
- http://wo####elcome.net/index.php
- http://wa###proud.net/index.php
- http://th####tcomplete.net/index.php
- http://th####twelcome.net/index.php
- http://su####around.net/index.php
- http://cr###around.net/index.php
- http://su####welcome.net/index.php
- http://cr####elcome.net/index.php
- http://su####complete.net/index.php
- http://cr####omplete.net/index.php
- http://su###rproud.net/index.php
- http://cr###proud.net/index.php
- http://pa###proud.net/index.php
- http://fi###proud.net/index.php
- http://pa###around.net/index.php
- http://fi###around.net/index.php
- http://fr###nature.net/index.php
- http://ex#####ncenature.net/index.php
- http://pa####omplete.net/index.php
- http://fi####omplete.net/index.php
- http://fi####elcome.net/index.php
- http://sm###around.net/index.php
- http://wo###proud.net/index.php
- http://sm####elcome.net/index.php
- http://wo###around.net/index.php
- http://sm####omplete.net/index.php
- http://pa####elcome.net/index.php
- http://sm###proud.net/index.php
- http://wo####omplete.net/index.php
- http://kn####omplete.net/index.php
- http://ge#####anwelcome.net/index.php
- http://al####ywelcome.net/index.php
- http://fr####omplete.net/index.php
- http://ex#####ncecomplete.net/index.php
- http://ge####manproud.net/index.php
- http://al####yproud.net/index.php
- http://ge####manaround.net/index.php
- http://al####yaround.net/index.php
- http://ex####enceproud.net/index.php
- http://fi####robable.net/index.php
- http://fr####elcome.net/index.php
- http://fi####itchen.net/index.php
- http://pa####robable.net/index.php
- http://ex#####ncearound.net/index.php
- http://fr###proud.net/index.php
- http://ex#####ncewelcome.net/index.php
- http://fr###around.net/index.php
- http://kn####elcome.net/index.php
- http://be###around.net/index.php
- http://me####complete.net/index.php
- http://be####elcome.net/index.php
- http://kn###proud.net/index.php
- http://be####omplete.net/index.php
- http://kn###around.net/index.php
- http://be###proud.net/index.php
- http://fo####complete.net/index.php
- http://fo####welcome.net/index.php
- http://me####welcome.net/index.php
- http://ge#####ancomplete.net/index.php
- http://al####ycomplete.net/index.php
- http://fo###wproud.net/index.php
- http://me###rproud.net/index.php
- http://fo####around.net/index.php
- http://me####around.net/index.php
- DNS ASK wa###around.net
- DNS ASK th####tproud.net
- DNS ASK wa####elcome.net
- DNS ASK th####taround.net
- DNS ASK wa####omplete.net
- DNS ASK wo####elcome.net
- DNS ASK wa###proud.net
- DNS ASK th####tcomplete.net
- DNS ASK th####twelcome.net
- DNS ASK su####around.net
- DNS ASK cr###around.net
- DNS ASK su####welcome.net
- DNS ASK cr####elcome.net
- DNS ASK su####complete.net
- DNS ASK cr####omplete.net
- DNS ASK su###rproud.net
- DNS ASK cr###proud.net
- DNS ASK sm####elcome.net
- DNS ASK fi###proud.net
- DNS ASK pa####omplete.net
- DNS ASK fi###around.net
- DNS ASK pa###proud.net
- DNS ASK ex#####ncenature.net
- DNS ASK fr###needle.net
- DNS ASK fi####omplete.net
- DNS ASK fr###nature.net
- DNS ASK pa###around.net
- DNS ASK wo###proud.net
- DNS ASK sm###proud.net
- DNS ASK wo###around.net
- DNS ASK sm###around.net
- DNS ASK pa####elcome.net
- DNS ASK fi####elcome.net
- DNS ASK wo####omplete.net
- DNS ASK sm####omplete.net
- DNS ASK ge#####anwelcome.net
- DNS ASK al####ywelcome.net
- DNS ASK fr####omplete.net
- DNS ASK ex#####ncecomplete.net
- DNS ASK ge####manproud.net
- DNS ASK al####yproud.net
- DNS ASK ge####manaround.net
- DNS ASK al####yaround.net
- DNS ASK ex####enceproud.net
- DNS ASK fi####robable.net
- DNS ASK fr####elcome.net
- DNS ASK fi####itchen.net
- DNS ASK pa####robable.net
- DNS ASK ex#####ncearound.net
- DNS ASK fr###proud.net
- DNS ASK ex#####ncewelcome.net
- DNS ASK fr###around.net
- DNS ASK ge#####ancomplete.net
- DNS ASK be###around.net
- DNS ASK kn###around.net
- DNS ASK be####elcome.net
- DNS ASK kn####elcome.net
- DNS ASK be####omplete.net
- DNS ASK kn####omplete.net
- DNS ASK be###proud.net
- DNS ASK kn###proud.net
- DNS ASK me####complete.net
- DNS ASK me####welcome.net
- DNS ASK fo####around.net
- DNS ASK al####ycomplete.net
- DNS ASK fo####welcome.net
- DNS ASK me###rproud.net
- DNS ASK fo####complete.net
- DNS ASK me####around.net
- DNS ASK fo###wproud.net
- ClassName: 'Shell_TrayWnd' WindowName: ''