Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Filtering Image Netlogon WLAN' = 'C:\phyfsns\clmawzkqjp.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Accounts Bluetooth Transaction Visual] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\Accounts Bluetooth Transaction Visual] 'ImagePath' = 'C:\phyfsns\clmawzkqjp.exe'
- %WINDIR%\phyfsns\puu3ionxxo
- C:\phyfsns\puu3ionxxo
- C:\phyfsns\sk30yqthsztddvisuj.exe
- C:\phyfsns\clmawzkqjp.exe
- C:\phyfsns\msxnbtcpfs.exe
- C:\phyfsns\clmawzkqjp.exe
- C:\phyfsns\msxnbtcpfs.exe
- %WINDIR%\phyfsns\puu3ionxxo
- C:\phyfsns\sk30yqthsztddvisuj.exe
- %WINDIR%\phyfsns\puu3ionxxo
- 're####erobject.net':80
- 'wo###space.net':80
- 'in####seclose.net':80
- 'fo###tclose.net':80
- 'in####seyellow.net':80
- 'fo####yellow.net':80
- 'in####setravel.net':80
- 'fo####travel.net':80
- 'in####sespace.net':80
- 'fo###tspace.net':80
- 'th####hclose.net':80
- 'ef###tclose.net':80
- 'th####hyellow.net':80
- 'ef####yellow.net':80
- 'th####htravel.net':80
- 'ef####travel.net':80
- 'th####hspace.net':80
- 'ef###tspace.net':80
- 're####erspace.net':80
- 're####ertravel.net':80
- 'an####bottom.net':80
- 'wo###yellow.net':80
- 'gl####orever.net':80
- 'an####forever.net':80
- 'gl###being.net':80
- 'an###rbeing.net':80
- 'gl###beyond.net':80
- 'an####beyond.net':80
- 'fo####dbottom.net':80
- 'de####bottom.net':80
- 'fo####dforever.net':80
- 'de####forever.net':80
- 'fo####dbeing.net':80
- 'de###ebeing.net':80
- 'fo####dbeyond.net':80
- 'de####beyond.net':80
- 're####erclose.net':80
- 'wo###close.net':80
- 're####eryellow.net':80
- 'su###rclose.net':80
- 'wo###travel.net':80
- 'wi###nclose.net':80
- 'ri###nspace.net':80
- 'de####yclose.net':80
- 'li####yellow.net':80
- 'de####yyellow.net':80
- 'li####travel.net':80
- 'de####ytravel.net':80
- 'li###espace.net':80
- 'de####yspace.net':80
- 'hu####dclose.net':80
- 'jo####yclose.net':80
- 'hu####dyellow.net':80
- 'jo####yyellow.net':80
- 'hu####dtravel.net':80
- 'jo####ytravel.net':80
- 'hu####dspace.net':80
- 'jo####yspace.net':80
- 're#####rchildhood.net':80
- 'wo####hildhood.net':80
- 'li###eclose.net':80
- 'be###gspace.net':80
- 'wi####yellow.net':80
- 'ri####travel.net':80
- 'su####travel.net':80
- 'wi####travel.net':80
- 'su###rspace.net':80
- 'wi###nspace.net':80
- 'th###close.net':80
- 'ch###close.net':80
- 'th###yellow.net':80
- 'ch###yellow.net':80
- 'th###travel.net':80
- 'ch###travel.net':80
- 'th###space.net':80
- 'ch###space.net':80
- 'be###gclose.net':80
- 'ri###nclose.net':80
- 'be####yellow.net':80
- 'ri####yellow.net':80
- 'be####travel.net':80
- 'su####yellow.net':80
- 'gl###bottom.net':80
- http://re####erobject.net/index.php
- http://wo###space.net/index.php
- http://in####seclose.net/index.php
- http://fo###tclose.net/index.php
- http://in####seyellow.net/index.php
- http://fo####yellow.net/index.php
- http://in####setravel.net/index.php
- http://fo####travel.net/index.php
- http://in####sespace.net/index.php
- http://fo###tspace.net/index.php
- http://th####hclose.net/index.php
- http://ef###tclose.net/index.php
- http://th####hyellow.net/index.php
- http://ef####yellow.net/index.php
- http://th####htravel.net/index.php
- http://ef####travel.net/index.php
- http://th####hspace.net/index.php
- http://ef###tspace.net/index.php
- http://re####erspace.net/index.php
- http://re####ertravel.net/index.php
- http://an####bottom.net/index.php
- http://wo###yellow.net/index.php
- http://gl####orever.net/index.php
- http://an####forever.net/index.php
- http://gl###being.net/index.php
- http://an###rbeing.net/index.php
- http://gl###beyond.net/index.php
- http://an####beyond.net/index.php
- http://fo####dbottom.net/index.php
- http://de####bottom.net/index.php
- http://fo####dforever.net/index.php
- http://de####forever.net/index.php
- http://fo####dbeing.net/index.php
- http://de###ebeing.net/index.php
- http://fo####dbeyond.net/index.php
- http://de####beyond.net/index.php
- http://re####erclose.net/index.php
- http://wo###close.net/index.php
- http://re####eryellow.net/index.php
- http://su###rclose.net/index.php
- http://wo###travel.net/index.php
- http://wi###nclose.net/index.php
- http://ri###nspace.net/index.php
- http://de####yclose.net/index.php
- http://li####yellow.net/index.php
- http://de####yyellow.net/index.php
- http://li####travel.net/index.php
- http://de####ytravel.net/index.php
- http://li###espace.net/index.php
- http://de####yspace.net/index.php
- http://hu####dclose.net/index.php
- http://jo####yclose.net/index.php
- http://hu####dyellow.net/index.php
- http://jo####yyellow.net/index.php
- http://hu####dtravel.net/index.php
- http://jo####ytravel.net/index.php
- http://hu####dspace.net/index.php
- http://jo####yspace.net/index.php
- http://re#####rchildhood.net/index.php
- http://wo####hildhood.net/index.php
- http://li###eclose.net/index.php
- http://be###gspace.net/index.php
- http://wi####yellow.net/index.php
- http://ri####travel.net/index.php
- http://su####travel.net/index.php
- http://wi####travel.net/index.php
- http://su###rspace.net/index.php
- http://wi###nspace.net/index.php
- http://th###close.net/index.php
- http://ch###close.net/index.php
- http://th###yellow.net/index.php
- http://ch###yellow.net/index.php
- http://th###travel.net/index.php
- http://ch###travel.net/index.php
- http://th###space.net/index.php
- http://ch###space.net/index.php
- http://be###gclose.net/index.php
- http://ri###nclose.net/index.php
- http://be####yellow.net/index.php
- http://ri####yellow.net/index.php
- http://be####travel.net/index.php
- http://su####yellow.net/index.php
- http://gl###bottom.net/index.php
- DNS ASK re####erobject.net
- DNS ASK wo###travel.net
- DNS ASK re####erspace.net
- DNS ASK wo###space.net
- DNS ASK in####seclose.net
- DNS ASK fo###tclose.net
- DNS ASK in####seyellow.net
- DNS ASK fo####yellow.net
- DNS ASK in####setravel.net
- DNS ASK fo####travel.net
- DNS ASK in####sespace.net
- DNS ASK fo###tspace.net
- DNS ASK th####hclose.net
- DNS ASK ef###tclose.net
- DNS ASK th####hyellow.net
- DNS ASK ef####yellow.net
- DNS ASK th####htravel.net
- DNS ASK ef####travel.net
- DNS ASK ef###tspace.net
- DNS ASK th####hspace.net
- DNS ASK re####ertravel.net
- DNS ASK wo###yellow.net
- DNS ASK an####bottom.net
- DNS ASK gl####orever.net
- DNS ASK an####forever.net
- DNS ASK gl###being.net
- DNS ASK an###rbeing.net
- DNS ASK gl###beyond.net
- DNS ASK an####beyond.net
- DNS ASK fo####dbottom.net
- DNS ASK fo####dforever.net
- DNS ASK th###travel.net
- DNS ASK de####forever.net
- DNS ASK fo####dbeing.net
- DNS ASK de###ebeing.net
- DNS ASK fo####dbeyond.net
- DNS ASK de####beyond.net
- DNS ASK re####erclose.net
- DNS ASK wo###close.net
- DNS ASK re####eryellow.net
- DNS ASK su###rclose.net
- DNS ASK wi###nclose.net
- DNS ASK su####yellow.net
- DNS ASK li####yellow.net
- DNS ASK de####yyellow.net
- DNS ASK li####travel.net
- DNS ASK de####ytravel.net
- DNS ASK li###espace.net
- DNS ASK de####yspace.net
- DNS ASK hu####dclose.net
- DNS ASK jo####yclose.net
- DNS ASK hu####dyellow.net
- DNS ASK jo####yyellow.net
- DNS ASK hu####dtravel.net
- DNS ASK jo####ytravel.net
- DNS ASK hu####dspace.net
- DNS ASK jo####yspace.net
- DNS ASK re#####rchildhood.net
- DNS ASK wo####hildhood.net
- DNS ASK li###eclose.net
- DNS ASK ri###nspace.net
- DNS ASK de####yclose.net
- DNS ASK be###gspace.net
- DNS ASK wi####yellow.net
- DNS ASK ri####travel.net
- DNS ASK su####travel.net
- DNS ASK wi####travel.net
- DNS ASK su###rspace.net
- DNS ASK wi###nspace.net
- DNS ASK th###close.net
- DNS ASK ch###close.net
- DNS ASK th###yellow.net
- DNS ASK de####bottom.net
- DNS ASK gl###bottom.net
- DNS ASK ch###travel.net
- DNS ASK th###space.net
- DNS ASK ch###space.net
- DNS ASK be###gclose.net
- DNS ASK ri###nclose.net
- DNS ASK be####yellow.net
- DNS ASK ri####yellow.net
- DNS ASK be####travel.net
- DNS ASK ch###yellow.net
- DNS ASK di####ultbeyond.net
- 'C:\phyfsns\sk30yqthsztddvisuj.exe'
- 'C:\phyfsns\clmawzkqjp.exe'
- 'C:\phyfsns\msxnbtcpfs.exe' "c:\phyfsns\clmawzkqjp.exe"