Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Portable Virtual Machine Spooler' = 'C:\klvilibev\mxiyzldavuj.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Internet Thread Modules Session Windows DHCP SNMP] 'Start' = '00000002'
- 'C:\klvilibev\xqklvdltye.exe' "c:\klvilibev\mxiyzldavuj.exe"
- 'C:\klvilibev\mxiyzldavuj.exe'
- 'C:\klvilibev\jka2ppdh6fygij7.exe'
- C:\klvilibev\mxiyzldavuj.exe
- C:\klvilibev\xqklvdltye.exe
- C:\klvilibev\kzihob
- %WINDIR%\klvilibev\cgtswjv6hug
- C:\klvilibev\cgtswjv6hug
- C:\klvilibev\jka2ppdh6fygij7.exe
- C:\klvilibev\xqklvdltye.exe
- C:\klvilibev\mxiyzldavuj.exe
- C:\klvilibev\jka2ppdh6fygij7.exe
- %WINDIR%\klvilibev\cgtswjv6hug
- 'de####yafraid.net':80
- 'li####dinner.net':80
- 'de####ycircle.net':80
- 'li####afraid.net':80
- 'de####ymeasure.net':80
- 'hu####dcircle.net':80
- 'de####ydinner.net':80
- 'li####measure.net':80
- 'ri####afraid.net':80
- 'be####dinner.net':80
- 'ri####circle.net':80
- 'be####afraid.net':80
- 'ri####measure.net':80
- 'li####circle.net':80
- 'ri####dinner.net':80
- 'be####measure.net':80
- 'jo####ycircle.net':80
- 're####erapple.net':80
- 'wo###apple.net':80
- 're####erbuilt.net':80
- 'wo###built.net':80
- 'in####secarry.net':80
- 'fo###tcarry.net':80
- 're####erfather.net':80
- 'wo###father.net':80
- 'hu####ddinner.net':80
- 'jo####ydinner.net':80
- 'hu####dafraid.net':80
- 'jo####yafraid.net':80
- 're####ercarry.net':80
- 'wo###carry.net':80
- 'hu####dmeasure.net':80
- 'jo####ymeasure.net':80
- http://de####yafraid.net/index.php?me########
- http://li####dinner.net/index.php?me########
- http://de####ycircle.net/index.php?me########
- http://li####afraid.net/index.php?me########
- http://de####ymeasure.net/index.php?me########
- http://hu####dcircle.net/index.php?me########
- http://de####ydinner.net/index.php?me########
- http://li####measure.net/index.php?me########
- http://ri####afraid.net/index.php?me########
- http://be####dinner.net/index.php?me########
- http://ri####circle.net/index.php?me########
- http://be####afraid.net/index.php?me########
- http://ri####measure.net/index.php?me########
- http://li####circle.net/index.php?me########
- http://ri####dinner.net/index.php?me########
- http://be####measure.net/index.php?me########
- http://jo####ycircle.net/index.php?me########
- http://re####erapple.net/index.php?me########
- http://wo###apple.net/index.php?me########
- http://re####erbuilt.net/index.php?me########
- http://wo###built.net/index.php?me########
- http://in####secarry.net/index.php?me########
- http://fo###tcarry.net/index.php?me########
- http://re####erfather.net/index.php?me########
- http://wo###father.net/index.php?me########
- http://hu####ddinner.net/index.php?me########
- http://jo####ydinner.net/index.php?me########
- http://hu####dafraid.net/index.php?me########
- http://jo####yafraid.net/index.php?me########
- http://re####ercarry.net/index.php?me########
- http://wo###carry.net/index.php?me########
- http://hu####dmeasure.net/index.php?me########
- http://jo####ymeasure.net/index.php?me########
- DNS ASK de####yafraid.net
- DNS ASK li####dinner.net
- DNS ASK de####ycircle.net
- DNS ASK li####afraid.net
- DNS ASK de####ymeasure.net
- DNS ASK hu####dcircle.net
- DNS ASK de####ydinner.net
- DNS ASK li####measure.net
- DNS ASK li####circle.net
- DNS ASK be####afraid.net
- DNS ASK ri####afraid.net
- DNS ASK be####circle.net
- DNS ASK ri####circle.net
- DNS ASK be####measure.net
- DNS ASK ri####measure.net
- DNS ASK be####dinner.net
- DNS ASK ri####dinner.net
- DNS ASK re####erapple.net
- DNS ASK wo###apple.net
- DNS ASK re####erbuilt.net
- DNS ASK wo###built.net
- DNS ASK in####secarry.net
- DNS ASK fo###tcarry.net
- DNS ASK re####erfather.net
- DNS ASK wo###father.net
- DNS ASK wo###carry.net
- DNS ASK jo####yafraid.net
- DNS ASK hu####ddinner.net
- DNS ASK jo####ycircle.net
- DNS ASK hu####dafraid.net
- DNS ASK jo####ymeasure.net
- DNS ASK re####ercarry.net
- DNS ASK jo####ydinner.net
- DNS ASK hu####dmeasure.net
- ClassName: 'Shell_TrayWnd' WindowName: ''