Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Control\Print\Providers\tdl] 'Name' = '%TEMP%\6.tmp'
- %TEMP%\mtaougq.exe
- %TEMP%\tgxp.exe
- %TEMP%\hrtcox.exe
- %TEMP%\fbaamp.exe
- %TEMP%\kcxow.exe
- %TEMP%\-1998166001
- %TEMP%\getnwq.exe
- %TEMP%\lfpowf.exe
- %TEMP%\bubejc.exe
- %TEMP%\nsz3.tmp\e4u.exe
- %TEMP%\nsz3.tmp\dnu.exe
- %TEMP%\bbrx.exe
- %TEMP%\jnowlrxs.exe
- %TEMP%\kjaabhjt.exe
- %TEMP%\nsz3.tmp\CB-WP.exe
- %TEMP%\nsz3.tmp\taskmgr.exe
- %TEMP%\getnwq.exe (downloaded from the Internet)
- %TEMP%\-1998166001 (downloaded from the Internet)
- %TEMP%\bubejc.exe (downloaded from the Internet)
- %TEMP%\lfpowf.exe (downloaded from the Internet)
- %TEMP%\bbrx.exe (downloaded from the Internet)
- %TEMP%\jnowlrxs.exe (downloaded from the Internet)
- %TEMP%\kjaabhjt.exe (downloaded from the Internet)
- %TEMP%\hrtcox.exe (downloaded from the Internet)
- %TEMP%\tgxp.exe (downloaded from the Internet)
- %TEMP%\kcxow.exe (downloaded from the Internet)
- %TEMP%\fbaamp.exe (downloaded from the Internet)
- %TEMP%\mtaougq.exe (downloaded from the Internet)
- <SYSTEM32>\spoolsv.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\vzgomuf[1].php
- %TEMP%\tgxp.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\zqksqlje[1].php
- %TEMP%\kcxow.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\ysautnmg[1].php
- %TEMP%\fbaamp.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\bfzhfdywe[1].php
- %TEMP%\mtaougq.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\mqlselg[1].php
- %TEMP%\-1998166001
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\vqkszys[1].php
- %TEMP%\getnwq.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\arzuoz[1].php
- %TEMP%\lfpowf.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\dubwucnvg[1].php
- %TEMP%\bubejc.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\hyxrmxs[1].php
- %TEMP%\~4.bat
- %TEMP%\nsz3.tmp\CB-WP.exe
- %WINDIR%\Temp\7.tmp
- %TEMP%\5.tmp
- %TEMP%\nsz3.tmp\taskmgr.exe
- %TEMP%\nso2.tmp
- %TEMP%\nsz3.tmp\e4u.exe
- %TEMP%\nsz3.tmp\dnu.exe
- %TEMP%\kjaabhjt.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\lcjepkiq[1].php
- %TEMP%\hrtcox.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\ycpxe[1].php
- %TEMP%\jnowlrxs.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\txfdyselte[1].php
- %TEMP%\bbrx.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\mdyfelge[1].php
- %TEMP%\~4.bat
- %TEMP%\6.tmp
- %WINDIR%\Temp\7.tmp
- %TEMP%\~4.bat
- %TEMP%\nsz3.tmp\taskmgr.exe
- %TEMP%\nsz3.tmp\CB-WP.exe
- %TEMP%\nsz3.tmp\dnu.exe
- %TEMP%\nsz3.tmp\e4u.exe
- from %TEMP%\5.tmp to %TEMP%\6.tmp
- 'st####artstudio.com':80
- 'ab####gnostic.com':80
- ab####gnostic.com/utaigom/arzuoz.php?ad########
- ab####gnostic.com/utaigom/zqksqlje.php?ad########
- ab####gnostic.com/utaigom/vzgomuf.php?ad########
- ab####gnostic.com/utaigom/vqkszys.php?ad#################################################
- ab####gnostic.com/utaigom/mqlselg.php?ad########
- ab####gnostic.com/utaigom/dubwucnvg.php?ad########
- ab####gnostic.com/utaigom/bfzhfdywe.php?ad########
- ab####gnostic.com/utaigom/lcjepkiq.php?ad########
- ab####gnostic.com/utaigom/mdyfelge.php?ad########
- ab####gnostic.com/utaigom/txfdyselte.php?ad########
- ab####gnostic.com/utaigom/ysautnmg.php?ad########
- ab####gnostic.com/utaigom/hyxrmxs.php?ad########
- ab####gnostic.com/utaigom/ycpxe.php?ad########
- DNS ASK st####artstudio.com
- DNS ASK ab####gnostic.com
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''