Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Internet Gateway Accounts' = 'C:\qyfqdomwr\scxbduibzcjl.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Helper Coordinator UPnP] 'Start' = '00000002'
- 'C:\qyfqdomwr\wyhppiwybv.exe' "c:\qyfqdomwr\scxbduibzcjl.exe"
- 'C:\qyfqdomwr\scxbduibzcjl.exe'
- 'C:\qyfqdomwr\yy2qr4nrcvriwsc8u.exe'
- C:\qyfqdomwr\scxbduibzcjl.exe
- C:\qyfqdomwr\wyhppiwybv.exe
- C:\qyfqdomwr\zympqcffszr
- %WINDIR%\qyfqdomwr\jgorxhr
- C:\qyfqdomwr\jgorxhr
- C:\qyfqdomwr\yy2qr4nrcvriwsc8u.exe
- C:\qyfqdomwr\wyhppiwybv.exe
- C:\qyfqdomwr\scxbduibzcjl.exe
- C:\qyfqdomwr\yy2qr4nrcvriwsc8u.exe
- %WINDIR%\qyfqdomwr\jgorxhr
- 'mi####device.net':80
- 'tw####device.net':80
- 'mi####language.net':80
- 'tw####language.net':80
- 'ra####settle.net':80
- 'mo####gsettle.net':80
- 'mi####before.net':80
- 'tw####before.net':80
- 'of###device.net':80
- 'al###device.net':80
- 'of####anguage.net':80
- 'al####anguage.net':80
- 'mi####settle.net':80
- 'tw####settle.net':80
- 'of###before.net':80
- 'al###before.net':80
- 'st####edevice.net':80
- 'hi####ydevice.net':80
- 'st####elanguage.net':80
- 'hi####ylanguage.net':80
- 'am####settle.net':80
- 'we####rsettle.net':80
- 'st####ebefore.net':80
- 'hi####ybefore.net':80
- 'ra####device.net':80
- 'mo####gdevice.net':80
- 'ra####language.net':80
- 'mo####glanguage.net':80
- 'st####esettle.net':80
- 'hi####ysettle.net':80
- 'ra####before.net':80
- 'mo####gbefore.net':80
- 'al###settle.net':80
- 'cl###became.net':80
- 'th####ontain.net':80
- 'cl####ndustry.net':80
- 'th###became.net':80
- 'cl###basket.net':80
- 'th###settle.net':80
- 'cl####ontain.net':80
- 'th###basket.net':80
- 'we####rbecame.net':80
- 'am####contain.net':80
- 'we####rindustry.net':80
- 'am####became.net':80
- 'we####rbasket.net':80
- 'th####ndustry.net':80
- 'we####rcontain.net':80
- 'am####basket.net':80
- 'co####elanguage.net':80
- 'ch###device.net':80
- 'co####esettle.net':80
- 'ch####anguage.net':80
- 'co####ebefore.net':80
- 'of###settle.net':80
- 'co####edevice.net':80
- 'ch###before.net':80
- 'pr####tlanguage.net':80
- 'th###device.net':80
- 'pr####tsettle.net':80
- 'th####anguage.net':80
- 'pr####tbefore.net':80
- 'ch###settle.net':80
- 'pr####tdevice.net':80
- 'th###before.net':80
- http://mi####device.net/index.php?me########
- http://tw####device.net/index.php?me########
- http://mi####language.net/index.php?me########
- http://tw####language.net/index.php?me########
- http://ra####settle.net/index.php?me########
- http://mo####gsettle.net/index.php?me########
- http://mi####before.net/index.php?me########
- http://tw####before.net/index.php?me########
- http://of###device.net/index.php?me########
- http://al###device.net/index.php?me########
- http://of####anguage.net/index.php?me########
- http://al####anguage.net/index.php?me########
- http://mi####settle.net/index.php?me########
- http://tw####settle.net/index.php?me########
- http://of###before.net/index.php?me########
- http://al###before.net/index.php?me########
- http://st####edevice.net/index.php?me########
- http://hi####ydevice.net/index.php?me########
- http://st####elanguage.net/index.php?me########
- http://hi####ylanguage.net/index.php?me########
- http://am####settle.net/index.php?me########
- http://we####rsettle.net/index.php?me########
- http://st####ebefore.net/index.php?me########
- http://hi####ybefore.net/index.php?me########
- http://ra####device.net/index.php?me########
- http://mo####gdevice.net/index.php?me########
- http://ra####language.net/index.php?me########
- http://mo####glanguage.net/index.php?me########
- http://st####esettle.net/index.php?me########
- http://hi####ysettle.net/index.php?me########
- http://ra####before.net/index.php?me########
- http://mo####gbefore.net/index.php?me########
- http://al###settle.net/index.php?me########
- http://cl###became.net/index.php?me########
- http://th####ontain.net/index.php?me########
- http://cl####ndustry.net/index.php?me########
- http://th###became.net/index.php?me########
- http://cl###basket.net/index.php?me########
- http://th###settle.net/index.php?me########
- http://cl####ontain.net/index.php?me########
- http://th###basket.net/index.php?me########
- http://we####rbecame.net/index.php?me########
- http://am####contain.net/index.php?me########
- http://we####rindustry.net/index.php?me########
- http://am####became.net/index.php?me########
- http://we####rbasket.net/index.php?me########
- http://th####ndustry.net/index.php?me########
- http://we####rcontain.net/index.php?me########
- http://am####basket.net/index.php?me########
- http://co####elanguage.net/index.php?me########
- http://ch###device.net/index.php?me########
- http://co####esettle.net/index.php?me########
- http://ch####anguage.net/index.php?me########
- http://co####ebefore.net/index.php?me########
- http://of###settle.net/index.php?me########
- http://co####edevice.net/index.php?me########
- http://ch###before.net/index.php?me########
- http://pr####tlanguage.net/index.php?me########
- http://th###device.net/index.php?me########
- http://pr####tsettle.net/index.php?me########
- http://th####anguage.net/index.php?me########
- http://pr####tbefore.net/index.php?me########
- http://ch###settle.net/index.php?me########
- http://pr####tdevice.net/index.php?me########
- http://th###before.net/index.php?me########
- DNS ASK mi####device.net
- DNS ASK tw####device.net
- DNS ASK mi####language.net
- DNS ASK tw####language.net
- DNS ASK ra####settle.net
- DNS ASK mo####gsettle.net
- DNS ASK mi####before.net
- DNS ASK tw####before.net
- DNS ASK of###device.net
- DNS ASK al###device.net
- DNS ASK of####anguage.net
- DNS ASK al####anguage.net
- DNS ASK mi####settle.net
- DNS ASK tw####settle.net
- DNS ASK of###before.net
- DNS ASK al###before.net
- DNS ASK ra####language.net
- DNS ASK hi####ydevice.net
- DNS ASK st####ebefore.net
- DNS ASK hi####ylanguage.net
- DNS ASK st####edevice.net
- DNS ASK we####rsettle.net
- DNS ASK am####language.net
- DNS ASK hi####ybefore.net
- DNS ASK am####settle.net
- DNS ASK mo####gdevice.net
- DNS ASK ra####before.net
- DNS ASK mo####glanguage.net
- DNS ASK ra####device.net
- DNS ASK hi####ysettle.net
- DNS ASK st####elanguage.net
- DNS ASK mo####gbefore.net
- DNS ASK st####esettle.net
- DNS ASK cl###became.net
- DNS ASK th####ontain.net
- DNS ASK cl####ndustry.net
- DNS ASK th###became.net
- DNS ASK cl###basket.net
- DNS ASK th###settle.net
- DNS ASK cl####ontain.net
- DNS ASK th###basket.net
- DNS ASK we####rbecame.net
- DNS ASK am####contain.net
- DNS ASK we####rindustry.net
- DNS ASK am####became.net
- DNS ASK we####rbasket.net
- DNS ASK th####ndustry.net
- DNS ASK we####rcontain.net
- DNS ASK am####basket.net
- DNS ASK pr####tsettle.net
- DNS ASK ch###device.net
- DNS ASK co####edevice.net
- DNS ASK ch####anguage.net
- DNS ASK co####elanguage.net
- DNS ASK of###settle.net
- DNS ASK al###settle.net
- DNS ASK ch###before.net
- DNS ASK co####ebefore.net
- DNS ASK th###device.net
- DNS ASK pr####tdevice.net
- DNS ASK th####anguage.net
- DNS ASK pr####tlanguage.net
- DNS ASK ch###settle.net
- DNS ASK co####esettle.net
- DNS ASK th###before.net
- DNS ASK pr####tbefore.net
- ClassName: 'Shell_TrayWnd' WindowName: ''