Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'PNRP Update Modules Application' = 'C:\jfsgjeigga\ovdxnnci.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Engine Modules IP Adapter DLL] 'ImagePath' = 'C:\jfsgjeigga\ovdxnnci.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Engine Modules IP Adapter DLL] 'Start' = '00000002'
- 'C:\jfsgjeigga\lpesysn.exe' "c:\jfsgjeigga\ovdxnnci.exe"
- 'C:\jfsgjeigga\ovdxnnci.exe'
- 'C:\jfsgjeigga\jypca3ai2jlxnryn6qb.exe'
- C:\jfsgjeigga\ovdxnnci.exe
- C:\jfsgjeigga\lpesysn.exe
- C:\jfsgjeigga\jypca3ai2jlxnryn6qb.exe
- %WINDIR%\jfsgjeigga\glsxqp
- C:\jfsgjeigga\glsxqp
- C:\jfsgjeigga\lpesysn.exe
- C:\jfsgjeigga\ovdxnnci.exe
- C:\jfsgjeigga\jypca3ai2jlxnryn6qb.exe
- %WINDIR%\jfsgjeigga\glsxqp
- 'st###indeed.net':80
- 'mi###indeed.net':80
- 'st###notice.net':80
- 'mi###notice.net':80
- 'st###during.net':80
- 'pr####length.net':80
- 'do####notice.net':80
- 'mi###during.net':80
- 'do####length.net':80
- 'ev####gnotice.net':80
- 'bu####ngindeed.net':80
- 'ev####glength.net':80
- 'bu####ngnotice.net':80
- 'ev####gindeed.net':80
- 'st###length.net':80
- 'mi###length.net':80
- 'bu####ngduring.net':80
- 'ev####gduring.net':80
- 'br####notice.net':80
- 're####notice.net':80
- 'br####length.net':80
- 're####length.net':80
- 'br####indeed.net':80
- 're####during.net':80
- 'pr####elength.net':80
- 're####indeed.net':80
- 'br####during.net':80
- 'pr####indeed.net':80
- 'do####during.net':80
- 'pr####notice.net':80
- 'do####indeed.net':80
- 'pr####during.net':80
- 'fe####indeed.net':80
- 'fe####during.net':80
- 'fe####length.net':80
- 'fe####notice.net':80
- 'sw###space.net':80
- 'pr####lyspace.net':80
- 'fi###hclose.net':80
- 'le###close.net':80
- 'sw###travel.net':80
- 'pr####lyyellow.net':80
- 'sw###close.net':80
- 'pr####lytravel.net':80
- 'sw###yellow.net':80
- 'su####tclose.net':80
- 'fi###hspace.net':80
- 'su####tyellow.net':80
- 'wi###rclose.net':80
- 'le###space.net':80
- 'fi####yellow.net':80
- 'le###yellow.net':80
- 'fi####travel.net':80
- 'le###travel.net':80
- 'mo####ntnotice.net':80
- 'ou####enotice.net':80
- 'mo####ntlength.net':80
- 'ou####elength.net':80
- 'mo####ntindeed.net':80
- 'ou####eduring.net':80
- 'bu####nglength.net':80
- 'ou####eindeed.net':80
- 'mo####ntduring.net':80
- 'ma####alspace.net':80
- 'se####ltravel.net':80
- 'pr####lyclose.net':80
- 'se####lspace.net':80
- 'ma####altravel.net':80
- 'se####lclose.net':80
- 'ma####alclose.net':80
- 'se####lyellow.net':80
- 'ma####alyellow.net':80
- http://st###indeed.net/index.php
- http://mi###indeed.net/index.php
- http://st###notice.net/index.php
- http://mi###notice.net/index.php
- http://st###during.net/index.php
- http://pr####length.net/index.php
- http://do####notice.net/index.php
- http://mi###during.net/index.php
- http://do####length.net/index.php
- http://ev####gnotice.net/index.php
- http://bu####ngindeed.net/index.php
- http://ev####glength.net/index.php
- http://bu####ngnotice.net/index.php
- http://ev####gindeed.net/index.php
- http://st###length.net/index.php
- http://mi###length.net/index.php
- http://bu####ngduring.net/index.php
- http://ev####gduring.net/index.php
- http://br####notice.net/index.php
- http://re####notice.net/index.php
- http://br####length.net/index.php
- http://re####length.net/index.php
- http://br####indeed.net/index.php
- http://re####during.net/index.php
- http://pr####elength.net/index.php
- http://re####indeed.net/index.php
- http://br####during.net/index.php
- http://pr####indeed.net/index.php
- http://do####during.net/index.php
- http://pr####notice.net/index.php
- http://do####indeed.net/index.php
- http://pr####during.net/index.php
- http://fe####indeed.net/index.php
- http://fe####during.net/index.php
- http://fe####length.net/index.php
- http://fe####notice.net/index.php
- http://sw###space.net/index.php
- http://pr####lyspace.net/index.php
- http://fi###hclose.net/index.php
- http://le###close.net/index.php
- http://sw###travel.net/index.php
- http://pr####lyyellow.net/index.php
- http://sw###close.net/index.php
- http://pr####lytravel.net/index.php
- http://sw###yellow.net/index.php
- http://su####tclose.net/index.php
- http://fi###hspace.net/index.php
- http://su####tyellow.net/index.php
- http://wi###rclose.net/index.php
- http://le###space.net/index.php
- http://fi####yellow.net/index.php
- http://le###yellow.net/index.php
- http://fi####travel.net/index.php
- http://le###travel.net/index.php
- http://mo####ntnotice.net/index.php
- http://ou####enotice.net/index.php
- http://mo####ntlength.net/index.php
- http://ou####elength.net/index.php
- http://mo####ntindeed.net/index.php
- http://ou####eduring.net/index.php
- http://bu####nglength.net/index.php
- http://ou####eindeed.net/index.php
- http://mo####ntduring.net/index.php
- http://ma####alspace.net/index.php
- http://se####ltravel.net/index.php
- http://pr####lyclose.net/index.php
- http://se####lspace.net/index.php
- http://ma####altravel.net/index.php
- http://se####lclose.net/index.php
- http://ma####alclose.net/index.php
- http://se####lyellow.net/index.php
- http://ma####alyellow.net/index.php
- DNS ASK mi###indeed.net
- DNS ASK st###during.net
- DNS ASK mi###notice.net
- DNS ASK st###indeed.net
- DNS ASK mi###during.net
- DNS ASK do####notice.net
- DNS ASK pr####notice.net
- DNS ASK do####length.net
- DNS ASK pr####length.net
- DNS ASK bu####ngindeed.net
- DNS ASK ev####gindeed.net
- DNS ASK bu####ngnotice.net
- DNS ASK ev####gnotice.net
- DNS ASK bu####ngduring.net
- DNS ASK mi###length.net
- DNS ASK st###notice.net
- DNS ASK ev####gduring.net
- DNS ASK st###length.net
- DNS ASK re####notice.net
- DNS ASK br####indeed.net
- DNS ASK re####length.net
- DNS ASK br####notice.net
- DNS ASK re####indeed.net
- DNS ASK pr####elength.net
- DNS ASK de####length.net
- DNS ASK br####during.net
- DNS ASK re####during.net
- DNS ASK do####during.net
- DNS ASK pr####during.net
- DNS ASK do####indeed.net
- DNS ASK pr####indeed.net
- DNS ASK fe####length.net
- DNS ASK fe####during.net
- DNS ASK br####length.net
- DNS ASK fe####notice.net
- DNS ASK fe####indeed.net
- DNS ASK ev####glength.net
- DNS ASK sw###space.net
- DNS ASK pr####lyspace.net
- DNS ASK fi###hclose.net
- DNS ASK le###close.net
- DNS ASK sw###travel.net
- DNS ASK pr####lyyellow.net
- DNS ASK sw###close.net
- DNS ASK pr####lytravel.net
- DNS ASK sw###yellow.net
- DNS ASK su####tclose.net
- DNS ASK fi###hspace.net
- DNS ASK su####tyellow.net
- DNS ASK wi###rclose.net
- DNS ASK le###space.net
- DNS ASK fi####yellow.net
- DNS ASK le###yellow.net
- DNS ASK fi####travel.net
- DNS ASK le###travel.net
- DNS ASK mo####ntnotice.net
- DNS ASK ou####enotice.net
- DNS ASK mo####ntlength.net
- DNS ASK ou####elength.net
- DNS ASK mo####ntindeed.net
- DNS ASK ou####eduring.net
- DNS ASK bu####nglength.net
- DNS ASK ou####eindeed.net
- DNS ASK mo####ntduring.net
- DNS ASK ma####alspace.net
- DNS ASK se####ltravel.net
- DNS ASK pr####lyclose.net
- DNS ASK se####lspace.net
- DNS ASK ma####altravel.net
- DNS ASK se####lclose.net
- DNS ASK ma####alclose.net
- DNS ASK se####lyellow.net
- DNS ASK ma####alyellow.net
- ClassName: 'Shell_TrayWnd' WindowName: ''