Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Extensible Reporting Interface Error Web' = 'C:\mujuwyc\ziamtrofmbdk.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Agent Detection Store Provider Tools Desktop] 'Start' = '00000002'
- 'C:\mujuwyc\xckxpne.exe' "c:\mujuwyc\ziamtrofmbdk.exe"
- 'C:\mujuwyc\ziamtrofmbdk.exe'
- 'C:\mujuwyc\dgi2in0pbjlhofhsfp.exe'
- C:\mujuwyc\ziamtrofmbdk.exe
- C:\mujuwyc\xckxpne.exe
- C:\mujuwyc\dgi2in0pbjlhofhsfp.exe
- %WINDIR%\mujuwyc\dk8zvkesplz
- C:\mujuwyc\dk8zvkesplz
- C:\mujuwyc\xckxpne.exe
- C:\mujuwyc\ziamtrofmbdk.exe
- C:\mujuwyc\dgi2in0pbjlhofhsfp.exe
- %WINDIR%\mujuwyc\dk8zvkesplz
- 'bu####nganimal.net':80
- 'ev####ganimal.net':80
- 'bu####ngescape.net':80
- 'ev####gescape.net':80
- 'bu####ngproblem.net':80
- 'ev####gmodern.net':80
- 'st###escape.net':80
- 'ev####gproblem.net':80
- 'bu####ngmodern.net':80
- 'ou####emodern.net':80
- 'mo####ntescape.net':80
- 'ou####eescape.net':80
- 'st####thgoodbye.net':80
- 'st#####hfortieth.net':80
- 'mo####ntanimal.net':80
- 'ou####eproblem.net':80
- 'mo####ntmodern.net':80
- 'ou####eanimal.net':80
- 'mo####ntproblem.net':80
- 'pr####problem.net':80
- 'do####modern.net':80
- 'pr####animal.net':80
- 'do####problem.net':80
- 'pr####modern.net':80
- 'fe####problem.net':80
- 'fe####modern.net':80
- 'fe####escape.net':80
- 'fe####animal.net':80
- 'do####animal.net':80
- 'mi###animal.net':80
- 'st####roblem.net':80
- 'mi###escape.net':80
- 'st###animal.net':80
- 'mi####roblem.net':80
- 'do####escape.net':80
- 'pr####escape.net':80
- 'st###modern.net':80
- 'mi###modern.net':80
- 'st#####hstranger.net':80
- 'pr####stranger.net':80
- 'do####goodbye.net':80
- 'pr####advance.net':80
- 'do####stranger.net':80
- 'pr####goodbye.net':80
- 'fe####advance.net':80
- 'fe####stranger.net':80
- 'do####fortieth.net':80
- 'pr####fortieth.net':80
- 'do####advance.net':80
- 'mi####dvance.net':80
- 'st####tranger.net':80
- 'ev####gfortieth.net':80
- 'st####dvance.net':80
- 'mi####tranger.net':80
- 'st####ortieth.net':80
- 'mi####ortieth.net':80
- 'st####oodbye.net':80
- 'mi####oodbye.net':80
- 'pr####estranger.net':80
- 'de####stranger.net':80
- 'pr####eadvance.net':80
- 'de####advance.net':80
- 'pr####egoodbye.net':80
- 'de####fortieth.net':80
- 'st####thadvance.net':80
- 'de####goodbye.net':80
- 'pr####efortieth.net':80
- 're####fortieth.net':80
- 'br####advance.net':80
- 're####advance.net':80
- 'fe####goodbye.net':80
- 'fe####fortieth.net':80
- 'br####stranger.net':80
- 're####goodbye.net':80
- 'br####fortieth.net':80
- 're####stranger.net':80
- 'br####goodbye.net':80
- http://bu####nganimal.net/index.php
- http://ev####ganimal.net/index.php
- http://bu####ngescape.net/index.php
- http://ev####gescape.net/index.php
- http://bu####ngproblem.net/index.php
- http://ev####gmodern.net/index.php
- http://st###escape.net/index.php
- http://ev####gproblem.net/index.php
- http://bu####ngmodern.net/index.php
- http://ou####emodern.net/index.php
- http://mo####ntescape.net/index.php
- http://ou####eescape.net/index.php
- http://st####thgoodbye.net/index.php
- http://st#####hfortieth.net/index.php
- http://mo####ntanimal.net/index.php
- http://ou####eproblem.net/index.php
- http://mo####ntmodern.net/index.php
- http://ou####eanimal.net/index.php
- http://mo####ntproblem.net/index.php
- http://pr####problem.net/index.php
- http://do####modern.net/index.php
- http://pr####animal.net/index.php
- http://do####problem.net/index.php
- http://pr####modern.net/index.php
- http://fe####problem.net/index.php
- http://fe####modern.net/index.php
- http://fe####escape.net/index.php
- http://fe####animal.net/index.php
- http://do####animal.net/index.php
- http://mi###animal.net/index.php
- http://st####roblem.net/index.php
- http://mi###escape.net/index.php
- http://st###animal.net/index.php
- http://mi####roblem.net/index.php
- http://do####escape.net/index.php
- http://pr####escape.net/index.php
- http://st###modern.net/index.php
- http://mi###modern.net/index.php
- http://st#####hstranger.net/index.php
- http://pr####stranger.net/index.php
- http://do####goodbye.net/index.php
- http://pr####advance.net/index.php
- http://do####stranger.net/index.php
- http://pr####goodbye.net/index.php
- http://fe####advance.net/index.php
- http://fe####stranger.net/index.php
- http://do####fortieth.net/index.php
- http://pr####fortieth.net/index.php
- http://do####advance.net/index.php
- http://mi####dvance.net/index.php
- http://st####tranger.net/index.php
- http://ev####gfortieth.net/index.php
- http://st####dvance.net/index.php
- http://mi####tranger.net/index.php
- http://st####ortieth.net/index.php
- http://mi####ortieth.net/index.php
- http://st####oodbye.net/index.php
- http://mi####oodbye.net/index.php
- http://pr####estranger.net/index.php
- http://de####stranger.net/index.php
- http://pr####eadvance.net/index.php
- http://de####advance.net/index.php
- http://pr####egoodbye.net/index.php
- http://de####fortieth.net/index.php
- http://st####thadvance.net/index.php
- http://de####goodbye.net/index.php
- http://pr####efortieth.net/index.php
- http://re####fortieth.net/index.php
- http://br####advance.net/index.php
- http://re####advance.net/index.php
- http://fe####goodbye.net/index.php
- http://fe####fortieth.net/index.php
- http://br####stranger.net/index.php
- http://re####goodbye.net/index.php
- http://br####fortieth.net/index.php
- http://re####stranger.net/index.php
- http://br####goodbye.net/index.php
- DNS ASK bu####nganimal.net
- DNS ASK ev####ganimal.net
- DNS ASK bu####ngescape.net
- DNS ASK ev####gescape.net
- DNS ASK bu####ngproblem.net
- DNS ASK ev####gmodern.net
- DNS ASK st###escape.net
- DNS ASK ev####gproblem.net
- DNS ASK bu####ngmodern.net
- DNS ASK ou####emodern.net
- DNS ASK mo####ntescape.net
- DNS ASK ou####eescape.net
- DNS ASK st####thgoodbye.net
- DNS ASK st#####hfortieth.net
- DNS ASK mo####ntanimal.net
- DNS ASK ou####eproblem.net
- DNS ASK mo####ntmodern.net
- DNS ASK ou####eanimal.net
- DNS ASK mo####ntproblem.net
- DNS ASK pr####problem.net
- DNS ASK do####modern.net
- DNS ASK pr####animal.net
- DNS ASK do####problem.net
- DNS ASK pr####modern.net
- DNS ASK fe####problem.net
- DNS ASK fe####modern.net
- DNS ASK fe####escape.net
- DNS ASK fe####animal.net
- DNS ASK do####animal.net
- DNS ASK mi###animal.net
- DNS ASK st####roblem.net
- DNS ASK mi###escape.net
- DNS ASK st###animal.net
- DNS ASK mi####roblem.net
- DNS ASK do####escape.net
- DNS ASK pr####escape.net
- DNS ASK st###modern.net
- DNS ASK mi###modern.net
- DNS ASK st#####hstranger.net
- DNS ASK pr####stranger.net
- DNS ASK do####goodbye.net
- DNS ASK pr####advance.net
- DNS ASK do####stranger.net
- DNS ASK pr####goodbye.net
- DNS ASK fe####advance.net
- DNS ASK fe####stranger.net
- DNS ASK do####fortieth.net
- DNS ASK pr####fortieth.net
- DNS ASK do####advance.net
- DNS ASK mi####dvance.net
- DNS ASK st####tranger.net
- DNS ASK ev####gfortieth.net
- DNS ASK st####dvance.net
- DNS ASK mi####tranger.net
- DNS ASK st####ortieth.net
- DNS ASK mi####ortieth.net
- DNS ASK st####oodbye.net
- DNS ASK mi####oodbye.net
- DNS ASK pr####estranger.net
- DNS ASK de####stranger.net
- DNS ASK pr####eadvance.net
- DNS ASK de####advance.net
- DNS ASK pr####egoodbye.net
- DNS ASK de####fortieth.net
- DNS ASK st####thadvance.net
- DNS ASK de####goodbye.net
- DNS ASK pr####efortieth.net
- DNS ASK re####fortieth.net
- DNS ASK br####advance.net
- DNS ASK re####advance.net
- DNS ASK fe####goodbye.net
- DNS ASK fe####fortieth.net
- DNS ASK br####stranger.net
- DNS ASK re####goodbye.net
- DNS ASK br####fortieth.net
- DNS ASK re####stranger.net
- DNS ASK br####goodbye.net
- ClassName: 'Shell_TrayWnd' WindowName: ''