Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Sharing Software Redirector Receiver' = 'C:\wxruyazme\yberxdwzrvao.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Offline Support Connection] 'Start' = '00000002'
- 'C:\wxruyazme\qwpbxobjewx.exe' "c:\wxruyazme\yberxdwzrvao.exe"
- 'C:\wxruyazme\yberxdwzrvao.exe'
- 'C:\wxruyazme\pwdk3eddtvjmzklfora.exe'
- C:\wxruyazme\yberxdwzrvao.exe
- C:\wxruyazme\qwpbxobjewx.exe
- C:\wxruyazme\pwdk3eddtvjmzklfora.exe
- %WINDIR%\wxruyazme\g2pfrn
- C:\wxruyazme\g2pfrn
- C:\wxruyazme\qwpbxobjewx.exe
- C:\wxruyazme\yberxdwzrvao.exe
- C:\wxruyazme\pwdk3eddtvjmzklfora.exe
- %WINDIR%\wxruyazme\g2pfrn
- 'ri###needle.net':80
- 'wh####renough.net':80
- 'ri###nature.net':80
- 'wh####rneedle.net':80
- 'ri###govern.net':80
- 'fi####nature.net':80
- 'ri###enough.net':80
- 'wh####rgovern.net':80
- 'wh####rnature.net':80
- 'su####needle.net':80
- 'fo####nneedle.net':80
- 'su####nature.net':80
- 'fo####nnature.net':80
- 'su####govern.net':80
- 'fo####ngovern.net':80
- 'su####enough.net':80
- 'fo####nenough.net':80
- 'th####nature.net':80
- 'ci####tteenough.net':80
- 'pi####egovern.net':80
- 'ci####tteneedle.net':80
- 'pi####eenough.net':80
- 'fa####nature.net':80
- 'ch####enneedle.net':80
- 'ci####ttegovern.net':80
- 'ch####ennature.net':80
- 'pi####eneedle.net':80
- 'fi####enough.net':80
- 'th####enough.net':80
- 'fi####needle.net':80
- 'th####needle.net':80
- 'pi####enature.net':80
- 'ci####ttenature.net':80
- 'fi####govern.net':80
- 'th####govern.net':80
- 'ei####welcome.net':80
- 'en####hwelcome.net':80
- 'ch#####ncomplete.net':80
- 'fa####complete.net':80
- 'ei###rproud.net':80
- 'en####hproud.net':80
- 'ei####around.net':80
- 'en####haround.net':80
- 'fa###yproud.net':80
- 'ci#####tecomplete.net':80
- 'ch####enwelcome.net':80
- 'ci####tteproud.net':80
- 'pi####ecomplete.net':80
- 'fa####around.net':80
- 'ch####enproud.net':80
- 'fa####welcome.net':80
- 'ch####enaround.net':80
- 'ei####complete.net':80
- 'pe####needle.net':80
- 'ma####eneedle.net':80
- 'pe####nature.net':80
- 'ma####enature.net':80
- 'pe####govern.net':80
- 'ma####egovern.net':80
- 'pe####enough.net':80
- 'ma####eenough.net':80
- 'be####egovern.net':80
- 'be####enature.net':80
- 'ex####needle.net':80
- 'en####hcomplete.net':80
- 'ex####nature.net':80
- 'be####eenough.net':80
- 'ex####govern.net':80
- 'be####eneedle.net':80
- 'ex####enough.net':80
- http://ri###needle.net/index.php
- http://wh####renough.net/index.php
- http://ri###nature.net/index.php
- http://wh####rneedle.net/index.php
- http://ri###govern.net/index.php
- http://fi####nature.net/index.php
- http://ri###enough.net/index.php
- http://wh####rgovern.net/index.php
- http://wh####rnature.net/index.php
- http://su####needle.net/index.php
- http://fo####nneedle.net/index.php
- http://su####nature.net/index.php
- http://fo####nnature.net/index.php
- http://su####govern.net/index.php
- http://fo####ngovern.net/index.php
- http://su####enough.net/index.php
- http://fo####nenough.net/index.php
- http://th####nature.net/index.php
- http://ci####tteenough.net/index.php
- http://pi####egovern.net/index.php
- http://ci####tteneedle.net/index.php
- http://pi####eenough.net/index.php
- http://fa####nature.net/index.php
- http://ch####enneedle.net/index.php
- http://ci####ttegovern.net/index.php
- http://ch####ennature.net/index.php
- http://pi####eneedle.net/index.php
- http://fi####enough.net/index.php
- http://th####enough.net/index.php
- http://fi####needle.net/index.php
- http://th####needle.net/index.php
- http://pi####enature.net/index.php
- http://ci####ttenature.net/index.php
- http://fi####govern.net/index.php
- http://th####govern.net/index.php
- http://ei####welcome.net/index.php
- http://en####hwelcome.net/index.php
- http://ch#####ncomplete.net/index.php
- http://fa####complete.net/index.php
- http://ei###rproud.net/index.php
- http://en####hproud.net/index.php
- http://ei####around.net/index.php
- http://en####haround.net/index.php
- http://fa###yproud.net/index.php
- http://ci#####tecomplete.net/index.php
- http://ch####enwelcome.net/index.php
- http://ci####tteproud.net/index.php
- http://pi####ecomplete.net/index.php
- http://fa####around.net/index.php
- http://ch####enproud.net/index.php
- http://fa####welcome.net/index.php
- http://ch####enaround.net/index.php
- http://ei####complete.net/index.php
- http://pe####needle.net/index.php
- http://ma####eneedle.net/index.php
- http://pe####nature.net/index.php
- http://ma####enature.net/index.php
- http://pe####govern.net/index.php
- http://ma####egovern.net/index.php
- http://pe####enough.net/index.php
- http://ma####eenough.net/index.php
- http://be####egovern.net/index.php
- http://be####enature.net/index.php
- http://ex####needle.net/index.php
- http://en####hcomplete.net/index.php
- http://ex####nature.net/index.php
- http://be####eenough.net/index.php
- http://ex####govern.net/index.php
- http://be####eneedle.net/index.php
- http://ex####enough.net/index.php
- DNS ASK wh####renough.net
- DNS ASK ri###enough.net
- DNS ASK wh####rneedle.net
- DNS ASK ri###needle.net
- DNS ASK fi####nature.net
- DNS ASK th####nature.net
- DNS ASK wh####rgovern.net
- DNS ASK ri###govern.net
- DNS ASK ri###nature.net
- DNS ASK fo####nneedle.net
- DNS ASK su####enough.net
- DNS ASK fo####nnature.net
- DNS ASK su####needle.net
- DNS ASK fo####ngovern.net
- DNS ASK wh####rnature.net
- DNS ASK fo####nenough.net
- DNS ASK su####govern.net
- DNS ASK fi####needle.net
- DNS ASK pi####egovern.net
- DNS ASK ci####ttegovern.net
- DNS ASK pi####eenough.net
- DNS ASK ci####tteenough.net
- DNS ASK ch####enneedle.net
- DNS ASK fa####needle.net
- DNS ASK ch####ennature.net
- DNS ASK fa####nature.net
- DNS ASK ci####tteneedle.net
- DNS ASK th####enough.net
- DNS ASK fi####govern.net
- DNS ASK th####needle.net
- DNS ASK fi####enough.net
- DNS ASK ci####ttenature.net
- DNS ASK pi####eneedle.net
- DNS ASK th####govern.net
- DNS ASK pi####enature.net
- DNS ASK su####nature.net
- DNS ASK ei####welcome.net
- DNS ASK en####hwelcome.net
- DNS ASK ch#####ncomplete.net
- DNS ASK fa####complete.net
- DNS ASK ei###rproud.net
- DNS ASK en####hproud.net
- DNS ASK ei####around.net
- DNS ASK en####haround.net
- DNS ASK fa###yproud.net
- DNS ASK ci#####tecomplete.net
- DNS ASK ch####enwelcome.net
- DNS ASK ci####tteproud.net
- DNS ASK pi####ecomplete.net
- DNS ASK fa####around.net
- DNS ASK ch####enproud.net
- DNS ASK fa####welcome.net
- DNS ASK ch####enaround.net
- DNS ASK ei####complete.net
- DNS ASK pe####needle.net
- DNS ASK ma####eneedle.net
- DNS ASK pe####nature.net
- DNS ASK ma####enature.net
- DNS ASK pe####govern.net
- DNS ASK ma####egovern.net
- DNS ASK pe####enough.net
- DNS ASK ma####eenough.net
- DNS ASK be####egovern.net
- DNS ASK be####enature.net
- DNS ASK ex####needle.net
- DNS ASK en####hcomplete.net
- DNS ASK ex####nature.net
- DNS ASK be####eenough.net
- DNS ASK ex####govern.net
- DNS ASK be####eneedle.net
- DNS ASK ex####enough.net
- ClassName: 'Shell_TrayWnd' WindowName: ''