Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SPP Defragmenter Routing DNS Proxy' = 'C:\gizxlyycujvjy\opyqgerqxbt.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Device Services COM Assistant] 'Start' = '00000002'
- 'C:\gizxlyycujvjy\cmjxkzu.exe' "c:\gizxlyycujvjy\opyqgerqxbt.exe"
- 'C:\gizxlyycujvjy\opyqgerqxbt.exe'
- 'C:\gizxlyycujvjy\nlb12p06xugdjh7eyr.exe'
- C:\gizxlyycujvjy\opyqgerqxbt.exe
- C:\gizxlyycujvjy\cmjxkzu.exe
- C:\gizxlyycujvjy\jexnfbjtywl
- %WINDIR%\gizxlyycujvjy\nur09kpj2f
- C:\gizxlyycujvjy\nur09kpj2f
- C:\gizxlyycujvjy\nlb12p06xugdjh7eyr.exe
- C:\gizxlyycujvjy\cmjxkzu.exe
- C:\gizxlyycujvjy\opyqgerqxbt.exe
- C:\gizxlyycujvjy\nlb12p06xugdjh7eyr.exe
- %WINDIR%\gizxlyycujvjy\nur09kpj2f
- 'ca####nopinion.net':80
- 'la####romise.net':80
- 'ca####nshort.net':80
- 'la####pinion.net':80
- 'el####icshould.net':80
- 're###dshort.net':80
- 'ca####npromise.net':80
- 're####should.net':80
- 'de####opinion.net':80
- 'ni####romise.net':80
- 'de###eshort.net':80
- 'ni####pinion.net':80
- 'ca####nshould.net':80
- 'la###short.net':80
- 'de####promise.net':80
- 'la###should.net':80
- 'el####icshort.net':80
- 'st####promise.net':80
- 'tr####romise.net':80
- 'st####opinion.net':80
- 'tr####pinion.net':80
- 'be###rshort.net':80
- 'ga###rshort.net':80
- 'be####should.net':80
- 'ga####should.net':80
- 're####promise.net':80
- 'el####icpromise.net':80
- 're####opinion.net':80
- 'el####icopinion.net':80
- 'st###tshort.net':80
- 'tr###short.net':80
- 'st####should.net':80
- 'tr###should.net':80
- 'he####ifference.net':80
- 'ge#####ifference.net':80
- 'he###charge.net':80
- 'ge####charge.net':80
- 'va####ssingle.net':80
- 're####single.net':80
- 'he###every.net':80
- 'ge###eevery.net':80
- 'le#####ifference.net':80
- 'he#####ifference.net':80
- 'le####charge.net':80
- 'he####charge.net':80
- 'he###single.net':80
- 'ge####single.net':80
- 'le###revery.net':80
- 'he###nevery.net':80
- 'va####scharge.net':80
- 'do####pinion.net':80
- 'ag####tpromise.net':80
- 'do###short.net':80
- 'ag####topinion.net':80
- 'de####should.net':80
- 'ni###short.net':80
- 'do####romise.net':80
- 'ni###should.net':80
- 're#####ifference.net':80
- 'va####severy.net':80
- 're####charge.net':80
- 'va#####difference.net':80
- 'do###should.net':80
- 'ag####tshort.net':80
- 're###nevery.net':80
- 'ag####tshould.net':80
- http://ca####nopinion.net/index.php?me########
- http://la####romise.net/index.php?me########
- http://ca####nshort.net/index.php?me########
- http://la####pinion.net/index.php?me########
- http://el####icshould.net/index.php?me########
- http://re###dshort.net/index.php?me########
- http://ca####npromise.net/index.php?me########
- http://re####should.net/index.php?me########
- http://de####opinion.net/index.php?me########
- http://ni####romise.net/index.php?me########
- http://de###eshort.net/index.php?me########
- http://ni####pinion.net/index.php?me########
- http://ca####nshould.net/index.php?me########
- http://la###short.net/index.php?me########
- http://de####promise.net/index.php?me########
- http://la###should.net/index.php?me########
- http://el####icshort.net/index.php?me########
- http://st####promise.net/index.php?me########
- http://tr####romise.net/index.php?me########
- http://st####opinion.net/index.php?me########
- http://tr####pinion.net/index.php?me########
- http://be###rshort.net/index.php?me########
- http://ga###rshort.net/index.php?me########
- http://be####should.net/index.php?me########
- http://ga####should.net/index.php?me########
- http://re####promise.net/index.php?me########
- http://el####icpromise.net/index.php?me########
- http://re####opinion.net/index.php?me########
- http://el####icopinion.net/index.php?me########
- http://st###tshort.net/index.php?me########
- http://tr###short.net/index.php?me########
- http://st####should.net/index.php?me########
- http://tr###should.net/index.php?me########
- http://he####ifference.net/index.php?me########
- http://ge#####ifference.net/index.php?me########
- http://he###charge.net/index.php?me########
- http://ge####charge.net/index.php?me########
- http://va####ssingle.net/index.php?me########
- http://re####single.net/index.php?me########
- http://he###every.net/index.php?me########
- http://ge###eevery.net/index.php?me########
- http://le#####ifference.net/index.php?me########
- http://he#####ifference.net/index.php?me########
- http://le####charge.net/index.php?me########
- http://he####charge.net/index.php?me########
- http://he###single.net/index.php?me########
- http://ge####single.net/index.php?me########
- http://le###revery.net/index.php?me########
- http://he###nevery.net/index.php?me########
- http://va####scharge.net/index.php?me########
- http://do####pinion.net/index.php?me########
- http://ag####tpromise.net/index.php?me########
- http://do###short.net/index.php?me########
- http://ag####topinion.net/index.php?me########
- http://de####should.net/index.php?me########
- http://ni###short.net/index.php?me########
- http://do####romise.net/index.php?me########
- http://ni###should.net/index.php?me########
- http://re#####ifference.net/index.php?me########
- http://va####severy.net/index.php?me########
- http://re####charge.net/index.php?me########
- http://va#####difference.net/index.php?me########
- http://do###should.net/index.php?me########
- http://ag####tshort.net/index.php?me########
- http://re###nevery.net/index.php?me########
- http://ag####tshould.net/index.php?me########
- DNS ASK ca####nopinion.net
- DNS ASK la####romise.net
- DNS ASK ca####nshort.net
- DNS ASK la####pinion.net
- DNS ASK el####icshould.net
- DNS ASK re###dshort.net
- DNS ASK ca####npromise.net
- DNS ASK re####should.net
- DNS ASK de####opinion.net
- DNS ASK ni####romise.net
- DNS ASK de###eshort.net
- DNS ASK ni####pinion.net
- DNS ASK ca####nshould.net
- DNS ASK la###short.net
- DNS ASK de####promise.net
- DNS ASK la###should.net
- DNS ASK el####icshort.net
- DNS ASK st####promise.net
- DNS ASK tr####romise.net
- DNS ASK st####opinion.net
- DNS ASK tr####pinion.net
- DNS ASK be###rshort.net
- DNS ASK ga###rshort.net
- DNS ASK be####should.net
- DNS ASK ga####should.net
- DNS ASK re####promise.net
- DNS ASK el####icpromise.net
- DNS ASK re####opinion.net
- DNS ASK el####icopinion.net
- DNS ASK st###tshort.net
- DNS ASK tr###short.net
- DNS ASK st####should.net
- DNS ASK tr###should.net
- DNS ASK he####ifference.net
- DNS ASK ge#####ifference.net
- DNS ASK he###charge.net
- DNS ASK ge####charge.net
- DNS ASK va####ssingle.net
- DNS ASK re####single.net
- DNS ASK he###every.net
- DNS ASK ge###eevery.net
- DNS ASK le#####ifference.net
- DNS ASK he#####ifference.net
- DNS ASK le####charge.net
- DNS ASK he####charge.net
- DNS ASK he###single.net
- DNS ASK ge####single.net
- DNS ASK le###revery.net
- DNS ASK he###nevery.net
- DNS ASK va####scharge.net
- DNS ASK do####pinion.net
- DNS ASK ag####tpromise.net
- DNS ASK do###short.net
- DNS ASK ag####topinion.net
- DNS ASK de####should.net
- DNS ASK ni###short.net
- DNS ASK do####romise.net
- DNS ASK ni###should.net
- DNS ASK re#####ifference.net
- DNS ASK va####severy.net
- DNS ASK re####charge.net
- DNS ASK va#####difference.net
- DNS ASK do###should.net
- DNS ASK ag####tshort.net
- DNS ASK re###nevery.net
- DNS ASK ag####tshould.net
- ClassName: 'Shell_TrayWnd' WindowName: ''