Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Telephony Location Grouping Information' = 'C:\xdudibfkbmdmw\ehqecenn.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Defragmenter DHCP Backup SNMP Program] 'Start' = '00000002'
- 'C:\xdudibfkbmdmw\jolxzhwc.exe' "c:\xdudibfkbmdmw\ehqecenn.exe"
- 'C:\xdudibfkbmdmw\ehqecenn.exe'
- 'C:\xdudibfkbmdmw\kdqcc2juuqfbkhyvacfwk4.exe'
- C:\xdudibfkbmdmw\ehqecenn.exe
- C:\xdudibfkbmdmw\jolxzhwc.exe
- C:\xdudibfkbmdmw\kdqcc2juuqfbkhyvacfwk4.exe
- %WINDIR%\xdudibfkbmdmw\sjrqqjy
- C:\xdudibfkbmdmw\sjrqqjy
- C:\xdudibfkbmdmw\jolxzhwc.exe
- C:\xdudibfkbmdmw\ehqecenn.exe
- C:\xdudibfkbmdmw\kdqcc2juuqfbkhyvacfwk4.exe
- %WINDIR%\xdudibfkbmdmw\sjrqqjy
- 'fo####nbeyond.net':80
- 'su###nbeing.net':80
- 'ma####ebottom.net':80
- 'su####beyond.net':80
- 'fo####nbeing.net':80
- 'su####bottom.net':80
- 'fo####nbottom.net':80
- 'su####forever.net':80
- 'fo####nforever.net':80
- 'pe####beyond.net':80
- 'ma####ebeyond.net':80
- 'ex####bottom.net':80
- 'be####ebottom.net':80
- 'pe###nbeing.net':80
- 'ma####eforever.net':80
- 'pe####bottom.net':80
- 'ma####ebeing.net':80
- 'pe####forever.net':80
- 'wh####rbeyond.net':80
- 'fi####forever.net':80
- 'th####forever.net':80
- 'fi###ebeing.net':80
- 'th###hbeing.net':80
- 'fi####bottom.net':80
- 'ci####ttebeyond.net':80
- 'pi####ebeing.net':80
- 'th####bottom.net':80
- 'pi####ebeyond.net':80
- 'ri###being.net':80
- 'wh####rforever.net':80
- 'ri###beyond.net':80
- 'wh####rbeing.net':80
- 'ri####orever.net':80
- 'fi####beyond.net':80
- 'th####beyond.net':80
- 'wh####rbottom.net':80
- 'ri###bottom.net':80
- 'br####yellow.net':80
- 're####yellow.net':80
- 'br####travel.net':80
- 're####travel.net':80
- 'br###nclose.net':80
- 'de###espace.net':80
- 'pr####etravel.net':80
- 're###tclose.net':80
- 'pr####espace.net':80
- 'do####travel.net':80
- 'fe####yellow.net':80
- 'do###espace.net':80
- 'fe####travel.net':80
- 'do####yellow.net':80
- 'br###nspace.net':80
- 're###tspace.net':80
- 'fe###wclose.net':80
- 'do###eclose.net':80
- 'de####travel.net':80
- 'st###close.net':80
- 'ex####beyond.net':80
- 'st###yellow.net':80
- 'st####thclose.net':80
- 'be####ebeyond.net':80
- 'ex####forever.net':80
- 'be####eforever.net':80
- 'ex###tbeing.net':80
- 'be####ebeing.net':80
- 'pr####eclose.net':80
- 'de###eclose.net':80
- 'pr####eyellow.net':80
- 'de####yellow.net':80
- 'st####thspace.net':80
- 'st###travel.net':80
- 'st####thyellow.net':80
- 'st###space.net':80
- 'st####thtravel.net':80
- http://fo####nbeyond.net/index.php
- http://su###nbeing.net/index.php
- http://ma####ebottom.net/index.php
- http://su####beyond.net/index.php
- http://fo####nbeing.net/index.php
- http://su####bottom.net/index.php
- http://fo####nbottom.net/index.php
- http://su####forever.net/index.php
- http://fo####nforever.net/index.php
- http://pe####beyond.net/index.php
- http://ma####ebeyond.net/index.php
- http://ex####bottom.net/index.php
- http://be####ebottom.net/index.php
- http://pe###nbeing.net/index.php
- http://ma####eforever.net/index.php
- http://pe####bottom.net/index.php
- http://ma####ebeing.net/index.php
- http://pe####forever.net/index.php
- http://wh####rbeyond.net/index.php
- http://fi####forever.net/index.php
- http://th####forever.net/index.php
- http://fi###ebeing.net/index.php
- http://th###hbeing.net/index.php
- http://fi####bottom.net/index.php
- http://ci####ttebeyond.net/index.php
- http://pi####ebeing.net/index.php
- http://th####bottom.net/index.php
- http://pi####ebeyond.net/index.php
- http://ri###being.net/index.php
- http://wh####rforever.net/index.php
- http://ri###beyond.net/index.php
- http://wh####rbeing.net/index.php
- http://ri####orever.net/index.php
- http://fi####beyond.net/index.php
- http://th####beyond.net/index.php
- http://wh####rbottom.net/index.php
- http://ri###bottom.net/index.php
- http://br####yellow.net/index.php
- http://re####yellow.net/index.php
- http://br####travel.net/index.php
- http://re####travel.net/index.php
- http://br###nclose.net/index.php
- http://de###espace.net/index.php
- http://pr####etravel.net/index.php
- http://re###tclose.net/index.php
- http://pr####espace.net/index.php
- http://do####travel.net/index.php
- http://fe####yellow.net/index.php
- http://do###espace.net/index.php
- http://fe####travel.net/index.php
- http://do####yellow.net/index.php
- http://br###nspace.net/index.php
- http://re###tspace.net/index.php
- http://fe###wclose.net/index.php
- http://do###eclose.net/index.php
- http://de####travel.net/index.php
- http://st###close.net/index.php
- http://ex####beyond.net/index.php
- http://st###yellow.net/index.php
- http://st####thclose.net/index.php
- http://be####ebeyond.net/index.php
- http://ex####forever.net/index.php
- http://be####eforever.net/index.php
- http://ex###tbeing.net/index.php
- http://be####ebeing.net/index.php
- http://pr####eclose.net/index.php
- http://de###eclose.net/index.php
- http://pr####eyellow.net/index.php
- http://de####yellow.net/index.php
- http://st####thspace.net/index.php
- http://st###travel.net/index.php
- http://st####thyellow.net/index.php
- http://st###space.net/index.php
- http://st####thtravel.net/index.php
- DNS ASK su###nbeing.net
- DNS ASK fo####nbeing.net
- DNS ASK su####beyond.net
- DNS ASK fo####nbeyond.net
- DNS ASK su####forever.net
- DNS ASK fo####nbottom.net
- DNS ASK wh####rbeyond.net
- DNS ASK fo####nforever.net
- DNS ASK su####bottom.net
- DNS ASK ma####ebeyond.net
- DNS ASK pe###nbeing.net
- DNS ASK be####ebottom.net
- DNS ASK pe####beyond.net
- DNS ASK ma####ebeing.net
- DNS ASK pe####bottom.net
- DNS ASK ma####ebottom.net
- DNS ASK pe####forever.net
- DNS ASK ma####eforever.net
- DNS ASK ri###beyond.net
- DNS ASK th####forever.net
- DNS ASK fi####bottom.net
- DNS ASK th###hbeing.net
- DNS ASK fi####forever.net
- DNS ASK th####bottom.net
- DNS ASK pi####ebeing.net
- DNS ASK ci####ttebeing.net
- DNS ASK pi####ebeyond.net
- DNS ASK ci####ttebeyond.net
- DNS ASK wh####rforever.net
- DNS ASK ri####orever.net
- DNS ASK wh####rbeing.net
- DNS ASK ri###being.net
- DNS ASK wh####rbottom.net
- DNS ASK th####beyond.net
- DNS ASK fi###ebeing.net
- DNS ASK ri###bottom.net
- DNS ASK fi####beyond.net
- DNS ASK ex####bottom.net
- DNS ASK br####yellow.net
- DNS ASK re####yellow.net
- DNS ASK br####travel.net
- DNS ASK re####travel.net
- DNS ASK br###nclose.net
- DNS ASK de###espace.net
- DNS ASK pr####etravel.net
- DNS ASK re###tclose.net
- DNS ASK pr####espace.net
- DNS ASK do####travel.net
- DNS ASK fe####yellow.net
- DNS ASK do###espace.net
- DNS ASK fe####travel.net
- DNS ASK do####yellow.net
- DNS ASK br###nspace.net
- DNS ASK re###tspace.net
- DNS ASK fe###wclose.net
- DNS ASK do###eclose.net
- DNS ASK de####travel.net
- DNS ASK st###close.net
- DNS ASK ex####beyond.net
- DNS ASK st###yellow.net
- DNS ASK st####thclose.net
- DNS ASK be####ebeyond.net
- DNS ASK ex####forever.net
- DNS ASK be####eforever.net
- DNS ASK ex###tbeing.net
- DNS ASK be####ebeing.net
- DNS ASK pr####eclose.net
- DNS ASK de###eclose.net
- DNS ASK pr####eyellow.net
- DNS ASK de####yellow.net
- DNS ASK st####thspace.net
- DNS ASK st###travel.net
- DNS ASK st####thyellow.net
- DNS ASK st###space.net
- DNS ASK st####thtravel.net
- ClassName: 'Shell_TrayWnd' WindowName: ''