Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Level Multimedia Human User' = 'C:\xmchjzliaoive\rgbmifec.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Media NetBIOS Host Services Name Key] 'Start' = '00000002'
- 'C:\xmchjzliaoive\eqrzxju.exe' "c:\xmchjzliaoive\rgbmifec.exe"
- 'C:\xmchjzliaoive\rgbmifec.exe'
- 'C:\xmchjzliaoive\hd2xdediur0hyk9qw.exe'
- C:\xmchjzliaoive\rgbmifec.exe
- C:\xmchjzliaoive\eqrzxju.exe
- C:\xmchjzliaoive\squkpj
- %WINDIR%\xmchjzliaoive\ncubkggspr
- C:\xmchjzliaoive\ncubkggspr
- C:\xmchjzliaoive\hd2xdediur0hyk9qw.exe
- C:\xmchjzliaoive\eqrzxju.exe
- C:\xmchjzliaoive\rgbmifec.exe
- C:\xmchjzliaoive\hd2xdediur0hyk9qw.exe
- %WINDIR%\xmchjzliaoive\ncubkggspr
- 'tr####iscover.net':80
- 'be####continue.net':80
- 'tr###wonder.net':80
- 'st####discover.net':80
- 'ga####master.net':80
- 'be####wonder.net':80
- 'ga####continue.net':80
- 'be####master.net':80
- 'el#####cdiscover.net':80
- 'st####continue.net':80
- 'el####icwonder.net':80
- 're####discover.net':80
- 'tr###master.net':80
- 'st####wonder.net':80
- 'tr####ontinue.net':80
- 'st####master.net':80
- 'br####iscover.net':80
- 'qu####ontinue.net':80
- 'br###wonder.net':80
- 'fl####iscover.net':80
- 'se####master.net':80
- 'qu###wonder.net':80
- 'se####continue.net':80
- 'qu###master.net':80
- 'ga####discover.net':80
- 'fl####ontinue.net':80
- 'ga####wonder.net':80
- 'be####discover.net':80
- 'br###master.net':80
- 'fl###wonder.net':80
- 'br####ontinue.net':80
- 'fl###master.net':80
- 'do####iscover.net':80
- 'ni####ontinue.net':80
- 'do###wonder.net':80
- 'ag####tdiscover.net':80
- 'de####master.net':80
- 'ni###wonder.net':80
- 'de####continue.net':80
- 'ni###master.net':80
- 'se####caught.net':80
- 'ag####tcontinue.net':80
- 'se####president.net':80
- 'qu###caught.net':80
- 'do###master.net':80
- 'ag####twonder.net':80
- 'do####ontinue.net':80
- 'ag####tmaster.net':80
- 'ca####ndiscover.net':80
- 're####continue.net':80
- 'ca####nwonder.net':80
- 'la####iscover.net':80
- 'el####icmaster.net':80
- 're####wonder.net':80
- 'el#####ccontinue.net':80
- 're####master.net':80
- 'de####discover.net':80
- 'la####ontinue.net':80
- 'de####wonder.net':80
- 'ni####iscover.net':80
- 'ca####nmaster.net':80
- 'la###wonder.net':80
- 'ca####ncontinue.net':80
- 'la###master.net':80
- http://tr####iscover.net/index.php?me########
- http://be####continue.net/index.php?me########
- http://tr###wonder.net/index.php?me########
- http://st####discover.net/index.php?me########
- http://ga####master.net/index.php?me########
- http://be####wonder.net/index.php?me########
- http://ga####continue.net/index.php?me########
- http://be####master.net/index.php?me########
- http://el#####cdiscover.net/index.php?me########
- http://st####continue.net/index.php?me########
- http://el####icwonder.net/index.php?me########
- http://re####discover.net/index.php?me########
- http://tr###master.net/index.php?me########
- http://st####wonder.net/index.php?me########
- http://tr####ontinue.net/index.php?me########
- http://st####master.net/index.php?me########
- http://br####iscover.net/index.php?me########
- http://qu####ontinue.net/index.php?me########
- http://br###wonder.net/index.php?me########
- http://fl####iscover.net/index.php?me########
- http://se####master.net/index.php?me########
- http://qu###wonder.net/index.php?me########
- http://se####continue.net/index.php?me########
- http://qu###master.net/index.php?me########
- http://ga####discover.net/index.php?me########
- http://fl####ontinue.net/index.php?me########
- http://ga####wonder.net/index.php?me########
- http://be####discover.net/index.php?me########
- http://br###master.net/index.php?me########
- http://fl###wonder.net/index.php?me########
- http://br####ontinue.net/index.php?me########
- http://fl###master.net/index.php?me########
- http://do####iscover.net/index.php?me########
- http://ni####ontinue.net/index.php?me########
- http://do###wonder.net/index.php?me########
- http://ag####tdiscover.net/index.php?me########
- http://de####master.net/index.php?me########
- http://ni###wonder.net/index.php?me########
- http://de####continue.net/index.php?me########
- http://ni###master.net/index.php?me########
- http://se####caught.net/index.php?me########
- http://ag####tcontinue.net/index.php?me########
- http://se####president.net/index.php?me########
- http://qu###caught.net/index.php?me########
- http://do###master.net/index.php?me########
- http://ag####twonder.net/index.php?me########
- http://do####ontinue.net/index.php?me########
- http://ag####tmaster.net/index.php?me########
- http://ca####ndiscover.net/index.php?me########
- http://re####continue.net/index.php?me########
- http://ca####nwonder.net/index.php?me########
- http://la####iscover.net/index.php?me########
- http://el####icmaster.net/index.php?me########
- http://re####wonder.net/index.php?me########
- http://el#####ccontinue.net/index.php?me########
- http://re####master.net/index.php?me########
- http://de####discover.net/index.php?me########
- http://la####ontinue.net/index.php?me########
- http://de####wonder.net/index.php?me########
- http://ni####iscover.net/index.php?me########
- http://ca####nmaster.net/index.php?me########
- http://la###wonder.net/index.php?me########
- http://ca####ncontinue.net/index.php?me########
- http://la###master.net/index.php?me########
- DNS ASK be####continue.net
- DNS ASK ga####continue.net
- DNS ASK st####discover.net
- DNS ASK tr####iscover.net
- DNS ASK be####wonder.net
- DNS ASK ga####wonder.net
- DNS ASK be####master.net
- DNS ASK ga####master.net
- DNS ASK st####continue.net
- DNS ASK tr####ontinue.net
- DNS ASK re####discover.net
- DNS ASK el#####cdiscover.net
- DNS ASK st####wonder.net
- DNS ASK tr###wonder.net
- DNS ASK st####master.net
- DNS ASK tr###master.net
- DNS ASK qu####ontinue.net
- DNS ASK se####continue.net
- DNS ASK fl####iscover.net
- DNS ASK br####iscover.net
- DNS ASK qu###wonder.net
- DNS ASK se####wonder.net
- DNS ASK qu###master.net
- DNS ASK se####master.net
- DNS ASK fl####ontinue.net
- DNS ASK br####ontinue.net
- DNS ASK be####discover.net
- DNS ASK ga####discover.net
- DNS ASK fl###wonder.net
- DNS ASK br###wonder.net
- DNS ASK fl###master.net
- DNS ASK br###master.net
- DNS ASK el####icwonder.net
- DNS ASK do####iscover.net
- DNS ASK ni####ontinue.net
- DNS ASK do###wonder.net
- DNS ASK ag####tdiscover.net
- DNS ASK de####master.net
- DNS ASK ni###wonder.net
- DNS ASK de####continue.net
- DNS ASK ni###master.net
- DNS ASK se####caught.net
- DNS ASK ag####tcontinue.net
- DNS ASK se####president.net
- DNS ASK qu###caught.net
- DNS ASK do###master.net
- DNS ASK ag####twonder.net
- DNS ASK do####ontinue.net
- DNS ASK ag####tmaster.net
- DNS ASK ca####ndiscover.net
- DNS ASK re####continue.net
- DNS ASK ca####nwonder.net
- DNS ASK la####iscover.net
- DNS ASK el####icmaster.net
- DNS ASK re####wonder.net
- DNS ASK el#####ccontinue.net
- DNS ASK re####master.net
- DNS ASK de####discover.net
- DNS ASK la####ontinue.net
- DNS ASK de####wonder.net
- DNS ASK ni####iscover.net
- DNS ASK ca####nmaster.net
- DNS ASK la###wonder.net
- DNS ASK ca####ncontinue.net
- DNS ASK la###master.net
- ClassName: 'Shell_TrayWnd' WindowName: ''