Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Instrumentation Level Computer Media Health' = 'C:\lgewoqpo\vcqikuldty.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\WinHTTP Helper Experience Propagation Time] 'Start' = '00000002'
- 'C:\lgewoqpo\zyzmfitu.exe' "c:\lgewoqpo\vcqikuldty.exe"
- 'C:\lgewoqpo\vcqikuldty.exe'
- 'C:\lgewoqpo\lbd2n8tyommicku.exe'
- C:\lgewoqpo\vcqikuldty.exe
- C:\lgewoqpo\zyzmfitu.exe
- C:\lgewoqpo\ysmydccj
- %WINDIR%\lgewoqpo\szyqptgi0ovt
- C:\lgewoqpo\szyqptgi0ovt
- C:\lgewoqpo\lbd2n8tyommicku.exe
- C:\lgewoqpo\zyzmfitu.exe
- C:\lgewoqpo\vcqikuldty.exe
- C:\lgewoqpo\lbd2n8tyommicku.exe
- %WINDIR%\lgewoqpo\szyqptgi0ovt
- 'pl#####ttraining.net':80
- 'ne#####rytraining.net':80
- 'pl####nthunger.net':80
- 'ne####aryhunger.net':80
- 'pl####ntthrown.net':80
- 'ne####arythrown.net':80
- 'pl####ntstorm.net':80
- 'ne####arystorm.net':80
- 'di#####lttraining.net':80
- 'he####raining.net':80
- 'di####ulthunger.net':80
- 'he###hunger.net':80
- 'di####ultthrown.net':80
- 'he###thrown.net':80
- 'di####ultstorm.net':80
- 'he###storm.net':80
- 'le####training.net':80
- 'he####training.net':80
- 'le####hunger.net':80
- 'he####hunger.net':80
- 'le####thrown.net':80
- 'he####thrown.net':80
- 'le###rstorm.net':80
- 'he###nstorm.net':80
- 'or####raining.net':80
- 're####etraining.net':80
- 'or###hunger.net':80
- 're####ehunger.net':80
- 'or###thrown.net':80
- 're####ethrown.net':80
- 'or###storm.net':80
- 're####estorm.net':80
- 'va####swhile.net':80
- 're###nwhile.net':80
- 'va####sschool.net':80
- 're####school.net':80
- 'va#####therefore.net':80
- 're####therefore.net':80
- 'va####squestion.net':80
- 're####question.net':80
- 'he###while.net':80
- 'ge###ewhile.net':80
- 'he###school.net':80
- 'ge####school.net':80
- 'he####herefore.net':80
- 'ge####therefore.net':80
- 'he####uestion.net':80
- 'ge####question.net':80
- 'an####training.net':80
- 'gl####raining.net':80
- 'an####hunger.net':80
- 'gl###hunger.net':80
- 'an####thrown.net':80
- 'gl###thrown.net':80
- 'an###rstorm.net':80
- 'gl###storm.net':80
- 'de####training.net':80
- 'fo####dtraining.net':80
- 'de####hunger.net':80
- 'fo####dhunger.net':80
- 'de####thrown.net':80
- 'fo####dthrown.net':80
- 'de###estorm.net':80
- 'fo####dstorm.net':80
- http://pl#####ttraining.net/index.php?me########
- http://ne#####rytraining.net/index.php?me########
- http://pl####nthunger.net/index.php?me########
- http://ne####aryhunger.net/index.php?me########
- http://pl####ntthrown.net/index.php?me########
- http://ne####arythrown.net/index.php?me########
- http://pl####ntstorm.net/index.php?me########
- http://ne####arystorm.net/index.php?me########
- http://di#####lttraining.net/index.php?me########
- http://he####raining.net/index.php?me########
- http://di####ulthunger.net/index.php?me########
- http://he###hunger.net/index.php?me########
- http://di####ultthrown.net/index.php?me########
- http://he###thrown.net/index.php?me########
- http://di####ultstorm.net/index.php?me########
- http://he###storm.net/index.php?me########
- http://le####training.net/index.php?me########
- http://he####training.net/index.php?me########
- http://le####hunger.net/index.php?me########
- http://he####hunger.net/index.php?me########
- http://le####thrown.net/index.php?me########
- http://he####thrown.net/index.php?me########
- http://le###rstorm.net/index.php?me########
- http://he###nstorm.net/index.php?me########
- http://or####raining.net/index.php?me########
- http://re####etraining.net/index.php?me########
- http://or###hunger.net/index.php?me########
- http://re####ehunger.net/index.php?me########
- http://or###thrown.net/index.php?me########
- http://re####ethrown.net/index.php?me########
- http://or###storm.net/index.php?me########
- http://re####estorm.net/index.php?me########
- http://va####swhile.net/index.php?me########
- http://re###nwhile.net/index.php?me########
- http://va####sschool.net/index.php?me########
- http://re####school.net/index.php?me########
- http://va#####therefore.net/index.php?me########
- http://re####therefore.net/index.php?me########
- http://va####squestion.net/index.php?me########
- http://re####question.net/index.php?me########
- http://he###while.net/index.php?me########
- http://ge###ewhile.net/index.php?me########
- http://he###school.net/index.php?me########
- http://ge####school.net/index.php?me########
- http://he####herefore.net/index.php?me########
- http://ge####therefore.net/index.php?me########
- http://he####uestion.net/index.php?me########
- http://ge####question.net/index.php?me########
- http://an####training.net/index.php?me########
- http://gl####raining.net/index.php?me########
- http://an####hunger.net/index.php?me########
- http://gl###hunger.net/index.php?me########
- http://an####thrown.net/index.php?me########
- http://gl###thrown.net/index.php?me########
- http://an###rstorm.net/index.php?me########
- http://gl###storm.net/index.php?me########
- http://de####training.net/index.php?me########
- http://fo####dtraining.net/index.php?me########
- http://de####hunger.net/index.php?me########
- http://fo####dhunger.net/index.php?me########
- http://de####thrown.net/index.php?me########
- http://fo####dthrown.net/index.php?me########
- http://de###estorm.net/index.php?me########
- http://fo####dstorm.net/index.php?me########
- DNS ASK ne#####rytraining.net
- DNS ASK pl####ntstorm.net
- DNS ASK ne####aryhunger.net
- DNS ASK pl#####ttraining.net
- DNS ASK ne####arythrown.net
- DNS ASK or###hunger.net
- DNS ASK ne####arystorm.net
- DNS ASK pl####ntthrown.net
- DNS ASK he####raining.net
- DNS ASK di####ultstorm.net
- DNS ASK he###hunger.net
- DNS ASK di#####lttraining.net
- DNS ASK he###thrown.net
- DNS ASK pl####nthunger.net
- DNS ASK he###storm.net
- DNS ASK di####ultthrown.net
- DNS ASK he####training.net
- DNS ASK le###rstorm.net
- DNS ASK he####hunger.net
- DNS ASK le####training.net
- DNS ASK he####thrown.net
- DNS ASK ge####hunger.net
- DNS ASK he###nstorm.net
- DNS ASK le####thrown.net
- DNS ASK re####etraining.net
- DNS ASK or###storm.net
- DNS ASK re####ehunger.net
- DNS ASK or####raining.net
- DNS ASK re####ethrown.net
- DNS ASK le####hunger.net
- DNS ASK re####estorm.net
- DNS ASK or###thrown.net
- DNS ASK di####ulthunger.net
- DNS ASK va####swhile.net
- DNS ASK re###nwhile.net
- DNS ASK va####sschool.net
- DNS ASK re####school.net
- DNS ASK va#####therefore.net
- DNS ASK re####therefore.net
- DNS ASK va####squestion.net
- DNS ASK re####question.net
- DNS ASK he###while.net
- DNS ASK ge###ewhile.net
- DNS ASK he###school.net
- DNS ASK ge####school.net
- DNS ASK he####herefore.net
- DNS ASK ge####therefore.net
- DNS ASK he####uestion.net
- DNS ASK ge####question.net
- DNS ASK an####training.net
- DNS ASK gl####raining.net
- DNS ASK an####hunger.net
- DNS ASK gl###hunger.net
- DNS ASK an####thrown.net
- DNS ASK gl###thrown.net
- DNS ASK an###rstorm.net
- DNS ASK gl###storm.net
- DNS ASK de####training.net
- DNS ASK fo####dtraining.net
- DNS ASK de####hunger.net
- DNS ASK fo####dhunger.net
- DNS ASK de####thrown.net
- DNS ASK fo####dthrown.net
- DNS ASK de###estorm.net
- DNS ASK fo####dstorm.net
- ClassName: 'Shell_TrayWnd' WindowName: ''