Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Hardware iSCSI Connection' = 'C:\xgykwgl\uosavpun.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Visual Services BitLocker Sharing Reports] 'Start' = '00000002'
- 'C:\xgykwgl\qibilqskrwb.exe' "c:\xgykwgl\uosavpun.exe"
- 'C:\xgykwgl\uosavpun.exe'
- 'C:\xgykwgl\ns2jtkdf1jcvfxkub3.exe'
- C:\xgykwgl\uosavpun.exe
- C:\xgykwgl\qibilqskrwb.exe
- C:\xgykwgl\jqeyjpqqznck
- %WINDIR%\xgykwgl\rcmxo5emh
- C:\xgykwgl\rcmxo5emh
- C:\xgykwgl\ns2jtkdf1jcvfxkub3.exe
- C:\xgykwgl\qibilqskrwb.exe
- C:\xgykwgl\uosavpun.exe
- C:\xgykwgl\ns2jtkdf1jcvfxkub3.exe
- %WINDIR%\xgykwgl\rcmxo5emh
- 'ge####choose.net':80
- 'he####however.net':80
- 'le####however.net':80
- 'ge####although.net':80
- 'va####schoose.net':80
- 'ge####however.net':80
- 'ge####period.net':80
- 'he####period.net':80
- 'le####choose.net':80
- 're####ehowever.net':80
- 'or####owever.net':80
- 'he####choose.net':80
- 'le####period.net':80
- 'he####although.net':80
- 'le####although.net':80
- 'fo####dcharge.net':80
- 'de####charge.net':80
- 'fo####dsingle.net':80
- 'de#####ifference.net':80
- 'fo####devery.net':80
- 'de###eevery.net':80
- 'fo#####difference.net':80
- 'de####single.net':80
- 're####although.net':80
- 'va####salthough.net':80
- 're####choose.net':80
- 'va####speriod.net':80
- 're####however.net':80
- 'va####showever.net':80
- 're####period.net':80
- 're####eperiod.net':80
- 'he###choose.net':80
- 'di####ultchoose.net':80
- 'gl####owever.net':80
- 'di#####ltalthough.net':80
- 'he###period.net':80
- 'di####ultperiod.net':80
- 'he####lthough.net':80
- 'an####however.net':80
- 'gl###choose.net':80
- 'an####choose.net':80
- 'fo####dhowever.net':80
- 'an####although.net':80
- 'gl###period.net':80
- 'an####period.net':80
- 'gl####lthough.net':80
- 'or###choose.net':80
- 'ne#####ryhowever.net':80
- 'pl####nthowever.net':80
- 're####echoose.net':80
- 'or###period.net':80
- 're####ealthough.net':80
- 'or####lthough.net':80
- 'ne####aryperiod.net':80
- 'pl####ntchoose.net':80
- 'he####owever.net':80
- 'di#####lthowever.net':80
- 'ne####arychoose.net':80
- 'pl####ntperiod.net':80
- 'ne#####ryalthough.net':80
- 'pl#####talthough.net':80
- http://ge####choose.net/index.php?me########
- http://he####however.net/index.php?me########
- http://le####however.net/index.php?me########
- http://ge####although.net/index.php?me########
- http://va####schoose.net/index.php?me########
- http://ge####however.net/index.php?me########
- http://ge####period.net/index.php?me########
- http://he####period.net/index.php?me########
- http://le####choose.net/index.php?me########
- http://re####ehowever.net/index.php?me########
- http://or####owever.net/index.php?me########
- http://he####choose.net/index.php?me########
- http://le####period.net/index.php?me########
- http://he####although.net/index.php?me########
- http://le####although.net/index.php?me########
- http://fo####dcharge.net/index.php?me########
- http://de####charge.net/index.php?me########
- http://fo####dsingle.net/index.php?me########
- http://de#####ifference.net/index.php?me########
- http://fo####devery.net/index.php?me########
- http://de###eevery.net/index.php?me########
- http://fo#####difference.net/index.php?me########
- http://de####single.net/index.php?me########
- http://re####although.net/index.php?me########
- http://va####salthough.net/index.php?me########
- http://re####choose.net/index.php?me########
- http://va####speriod.net/index.php?me########
- http://re####however.net/index.php?me########
- http://va####showever.net/index.php?me########
- http://re####period.net/index.php?me########
- http://re####eperiod.net/index.php?me########
- http://he###choose.net/index.php?me########
- http://di####ultchoose.net/index.php?me########
- http://gl####owever.net/index.php?me########
- http://di#####ltalthough.net/index.php?me########
- http://he###period.net/index.php?me########
- http://di####ultperiod.net/index.php?me########
- http://he####lthough.net/index.php?me########
- http://an####however.net/index.php?me########
- http://gl###choose.net/index.php?me########
- http://an####choose.net/index.php?me########
- http://fo####dhowever.net/index.php?me########
- http://an####although.net/index.php?me########
- http://gl###period.net/index.php?me########
- http://an####period.net/index.php?me########
- http://gl####lthough.net/index.php?me########
- http://or###choose.net/index.php?me########
- http://ne#####ryhowever.net/index.php?me########
- http://pl####nthowever.net/index.php?me########
- http://re####echoose.net/index.php?me########
- http://or###period.net/index.php?me########
- http://re####ealthough.net/index.php?me########
- http://or####lthough.net/index.php?me########
- http://ne####aryperiod.net/index.php?me########
- http://pl####ntchoose.net/index.php?me########
- http://he####owever.net/index.php?me########
- http://di#####lthowever.net/index.php?me########
- http://ne####arychoose.net/index.php?me########
- http://pl####ntperiod.net/index.php?me########
- http://ne#####ryalthough.net/index.php?me########
- http://pl#####talthough.net/index.php?me########
- DNS ASK ge####choose.net
- DNS ASK he####however.net
- DNS ASK le####however.net
- DNS ASK ge####although.net
- DNS ASK va####schoose.net
- DNS ASK ge####however.net
- DNS ASK ge####period.net
- DNS ASK he####period.net
- DNS ASK le####choose.net
- DNS ASK re####ehowever.net
- DNS ASK or####owever.net
- DNS ASK he####choose.net
- DNS ASK le####period.net
- DNS ASK he####although.net
- DNS ASK le####although.net
- DNS ASK re####choose.net
- DNS ASK de#####ifference.net
- DNS ASK fo####dcharge.net
- DNS ASK de####charge.net
- DNS ASK fo#####difference.net
- DNS ASK an####single.net
- DNS ASK fo####devery.net
- DNS ASK de###eevery.net
- DNS ASK fo####dsingle.net
- DNS ASK va####speriod.net
- DNS ASK re####although.net
- DNS ASK va####salthough.net
- DNS ASK re####period.net
- DNS ASK de####single.net
- DNS ASK re####however.net
- DNS ASK va####showever.net
- DNS ASK he###choose.net
- DNS ASK di####ultchoose.net
- DNS ASK gl####owever.net
- DNS ASK di#####ltalthough.net
- DNS ASK he###period.net
- DNS ASK di####ultperiod.net
- DNS ASK he####lthough.net
- DNS ASK an####however.net
- DNS ASK gl###choose.net
- DNS ASK an####choose.net
- DNS ASK fo####dhowever.net
- DNS ASK an####although.net
- DNS ASK gl###period.net
- DNS ASK an####period.net
- DNS ASK gl####lthough.net
- DNS ASK di#####lthowever.net
- DNS ASK re####echoose.net
- DNS ASK or###choose.net
- DNS ASK ne#####ryhowever.net
- DNS ASK or####lthough.net
- DNS ASK re####eperiod.net
- DNS ASK or###period.net
- DNS ASK re####ealthough.net
- DNS ASK pl####nthowever.net
- DNS ASK ne####arychoose.net
- DNS ASK pl####ntchoose.net
- DNS ASK he####owever.net
- DNS ASK pl#####talthough.net
- DNS ASK ne####aryperiod.net
- DNS ASK pl####ntperiod.net
- DNS ASK ne#####ryalthough.net
- ClassName: 'Shell_TrayWnd' WindowName: ''