Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Launcher Engine Protection Themes Store Keying' = 'C:\ksiggth\qlvgxrvni.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Virtual Font Now Update Certificate] 'ImagePath' = 'C:\ksiggth\qlvgxrvni.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Virtual Font Now Update Certificate] 'Start' = '00000002'
- 'C:\ksiggth\dezdhmtv.exe' "c:\ksiggth\qlvgxrvni.exe"
- 'C:\ksiggth\qlvgxrvni.exe'
- 'C:\ksiggth\mxuaf2gy9fykf8yagp.exe'
- C:\ksiggth\qlvgxrvni.exe
- C:\ksiggth\dezdhmtv.exe
- C:\ksiggth\fbajfx
- %WINDIR%\ksiggth\duzigk5
- C:\ksiggth\duzigk5
- C:\ksiggth\mxuaf2gy9fykf8yagp.exe
- C:\ksiggth\dezdhmtv.exe
- C:\ksiggth\qlvgxrvni.exe
- C:\ksiggth\mxuaf2gy9fykf8yagp.exe
- %WINDIR%\ksiggth\duzigk5
- 'fo####ndistance.net':80
- 'su####office.net':80
- 'fo####nsupply.net':80
- 'su####distance.net':80
- 'fo####narrive.net':80
- 'wh####rsupply.net':80
- 'fo####noffice.net':80
- 'su####arrive.net':80
- 'ma####edistance.net':80
- 'pe####office.net':80
- 'ma####esupply.net':80
- 'pe####distance.net':80
- 'ma####earrive.net':80
- 'su####supply.net':80
- 'ma####eoffice.net':80
- 'pe####arrive.net':80
- 'th####distance.net':80
- 'fi####office.net':80
- 'th####supply.net':80
- 'fi####distance.net':80
- 'th####arrive.net':80
- 'pi####esupply.net':80
- 'th####office.net':80
- 'fi####arrive.net':80
- 'ri####istance.net':80
- 'wh####roffice.net':80
- 'ri###supply.net':80
- 'wh####rdistance.net':80
- 'ri###arrive.net':80
- 'fi####supply.net':80
- 'ri###office.net':80
- 'wh####rarrive.net':80
- 'pe####supply.net':80
- 'ch####enshort.net':80
- 'fa###yshort.net':80
- 'ch####enshould.net':80
- 'fa####should.net':80
- 'ch####enpromise.net':80
- 'fa####promise.net':80
- 'ch####enopinion.net':80
- 'fa####opinion.net':80
- 'pi####eshort.net':80
- 'ci####tteshort.net':80
- 'pi####eshould.net':80
- 'ci####tteshould.net':80
- 'pi####epromise.net':80
- 'ci#####tepromise.net':80
- 'pi####eopinion.net':80
- 'ci#####teopinion.net':80
- 'ex####distance.net':80
- 'be####edistance.net':80
- 'ex####supply.net':80
- 'be####esupply.net':80
- 'ex####arrive.net':80
- 'be####earrive.net':80
- 'ex####office.net':80
- 'be####eoffice.net':80
- 'ei###rshort.net':80
- 'en####hshort.net':80
- 'ei####should.net':80
- 'en####hshould.net':80
- 'ei####promise.net':80
- 'en####hpromise.net':80
- 'ei####opinion.net':80
- 'en####hopinion.net':80
- http://fo####ndistance.net/index.php?me########
- http://su####office.net/index.php?me########
- http://fo####nsupply.net/index.php?me########
- http://su####distance.net/index.php?me########
- http://fo####narrive.net/index.php?me########
- http://wh####rsupply.net/index.php?me########
- http://fo####noffice.net/index.php?me########
- http://su####arrive.net/index.php?me########
- http://ma####edistance.net/index.php?me########
- http://pe####office.net/index.php?me########
- http://ma####esupply.net/index.php?me########
- http://pe####distance.net/index.php?me########
- http://ma####earrive.net/index.php?me########
- http://su####supply.net/index.php?me########
- http://ma####eoffice.net/index.php?me########
- http://pe####arrive.net/index.php?me########
- http://th####distance.net/index.php?me########
- http://fi####office.net/index.php?me########
- http://th####supply.net/index.php?me########
- http://fi####distance.net/index.php?me########
- http://th####arrive.net/index.php?me########
- http://pi####esupply.net/index.php?me########
- http://th####office.net/index.php?me########
- http://fi####arrive.net/index.php?me########
- http://ri####istance.net/index.php?me########
- http://wh####roffice.net/index.php?me########
- http://ri###supply.net/index.php?me########
- http://wh####rdistance.net/index.php?me########
- http://ri###arrive.net/index.php?me########
- http://fi####supply.net/index.php?me########
- http://ri###office.net/index.php?me########
- http://wh####rarrive.net/index.php?me########
- http://pe####supply.net/index.php?me########
- http://ch####enshort.net/index.php?me########
- http://fa###yshort.net/index.php?me########
- http://ch####enshould.net/index.php?me########
- http://fa####should.net/index.php?me########
- http://ch####enpromise.net/index.php?me########
- http://fa####promise.net/index.php?me########
- http://ch####enopinion.net/index.php?me########
- http://fa####opinion.net/index.php?me########
- http://pi####eshort.net/index.php?me########
- http://ci####tteshort.net/index.php?me########
- http://pi####eshould.net/index.php?me########
- http://ci####tteshould.net/index.php?me########
- http://pi####epromise.net/index.php?me########
- http://ci#####tepromise.net/index.php?me########
- http://pi####eopinion.net/index.php?me########
- http://ci#####teopinion.net/index.php?me########
- http://ex####distance.net/index.php?me########
- http://be####edistance.net/index.php?me########
- http://ex####supply.net/index.php?me########
- http://be####esupply.net/index.php?me########
- http://ex####arrive.net/index.php?me########
- http://be####earrive.net/index.php?me########
- http://ex####office.net/index.php?me########
- http://be####eoffice.net/index.php?me########
- http://ei###rshort.net/index.php?me########
- http://en####hshort.net/index.php?me########
- http://ei####should.net/index.php?me########
- http://en####hshould.net/index.php?me########
- http://ei####promise.net/index.php?me########
- http://en####hpromise.net/index.php?me########
- http://ei####opinion.net/index.php?me########
- http://en####hopinion.net/index.php?me########
- DNS ASK fo####ndistance.net
- DNS ASK su####office.net
- DNS ASK fo####nsupply.net
- DNS ASK su####distance.net
- DNS ASK fo####narrive.net
- DNS ASK wh####rsupply.net
- DNS ASK fo####noffice.net
- DNS ASK su####arrive.net
- DNS ASK ma####edistance.net
- DNS ASK pe####office.net
- DNS ASK ma####esupply.net
- DNS ASK pe####distance.net
- DNS ASK ma####earrive.net
- DNS ASK su####supply.net
- DNS ASK ma####eoffice.net
- DNS ASK pe####arrive.net
- DNS ASK ri###supply.net
- DNS ASK fi####office.net
- DNS ASK th####office.net
- DNS ASK fi####distance.net
- DNS ASK th####distance.net
- DNS ASK pi####esupply.net
- DNS ASK ci####ttesupply.net
- DNS ASK fi####arrive.net
- DNS ASK th####arrive.net
- DNS ASK wh####roffice.net
- DNS ASK ri###office.net
- DNS ASK wh####rdistance.net
- DNS ASK ri####istance.net
- DNS ASK fi####supply.net
- DNS ASK th####supply.net
- DNS ASK wh####rarrive.net
- DNS ASK ri###arrive.net
- DNS ASK ch####enshort.net
- DNS ASK fa###yshort.net
- DNS ASK ch####enshould.net
- DNS ASK fa####should.net
- DNS ASK ch####enpromise.net
- DNS ASK fa####promise.net
- DNS ASK ch####enopinion.net
- DNS ASK fa####opinion.net
- DNS ASK pi####eshort.net
- DNS ASK ci####tteshort.net
- DNS ASK pi####eshould.net
- DNS ASK ci####tteshould.net
- DNS ASK pi####epromise.net
- DNS ASK ci#####tepromise.net
- DNS ASK pi####eopinion.net
- DNS ASK ci#####teopinion.net
- DNS ASK ei####should.net
- DNS ASK be####edistance.net
- DNS ASK ex####office.net
- DNS ASK be####esupply.net
- DNS ASK ex####distance.net
- DNS ASK be####earrive.net
- DNS ASK pe####supply.net
- DNS ASK be####eoffice.net
- DNS ASK ex####arrive.net
- DNS ASK en####hshort.net
- DNS ASK ei####opinion.net
- DNS ASK en####hshould.net
- DNS ASK ei###rshort.net
- DNS ASK en####hpromise.net
- DNS ASK ex####supply.net
- DNS ASK en####hopinion.net
- DNS ASK ei####promise.net
- ClassName: 'Shell_TrayWnd' WindowName: ''