Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'mivizipwuhuz' = '%HOMEPATH%\mivizipwuhuz.exe'
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\8260afbe-fae5-48b3-954e-c1381e8fb05e
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\2ff214cb-dac8-42eb-b87d-0a6b0105bf07
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\6c5b6a10-01f6-4162-ae16-38afd8580fe0
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ec702f375e1b12d218f67ab9ef19ca23_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\Preferred
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\cfcf1f6e-1cd4-4992-a68a-54d9efd6acda
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\c85c72db-c187-44cc-bcc8-91b462c4e424
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\428e9651-afad-41ca-8df2-7046eab76f9a
- %HOMEPATH%\mivizipwuhuz.exe
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\69a80a41-eb68-4643-994d-1324809a3522
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\6d7cc317-a4e9-4294-8432-aa33a788d23d
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\a16f1a63-1701-4a6d-91d2-5702acec1918
- 'sm##.live.com':25
- DNS ASK fr#####ckallergy.com
- DNS ASK ts#.org
- DNS ASK pr######nsolutionsky.com
- DNS ASK wk##.net
- DNS ASK ag#####des-druides.com
- DNS ASK is####arnataka.org
- DNS ASK te####g-video.com
- DNS ASK fr###spot.co.za
- DNS ASK st##om.nl
- DNS ASK di##d.com
- DNS ASK na###gurus.com
- DNS ASK th###rgery.com
- DNS ASK tv##ra.net
- DNS ASK co##th.com
- DNS ASK ro###eli.com
- DNS ASK sg###nting.ca
- DNS ASK db####onents.com
- DNS ASK we####dechurch.org
- DNS ASK xi###group.com
- DNS ASK eu##sia.it
- DNS ASK ar####esajandek.hu
- DNS ASK te###ra.co.jp
- DNS ASK ma#####siecologia.com
- DNS ASK ra######ckwarehouse.com.au
- DNS ASK st###edia.ca
- DNS ASK st##net.de
- DNS ASK bu####llmedia.com
- DNS ASK al###wared.com
- DNS ASK so####oncorp.com
- DNS ASK sl##go.org
- DNS ASK wo#####dhillwinery.com
- DNS ASK ge###r.gen.tr
- DNS ASK bi##imex.pl
- DNS ASK fi###ara.com
- DNS ASK hi##ken.com
- DNS ASK ar###2aa.org
- DNS ASK ma###egor.co.kr
- DNS ASK te###avis.com
- DNS ASK ca#####citytuxedo.com
- DNS ASK ae##ora.com
- DNS ASK su###france.com
- DNS ASK ku###ci.or.jp
- DNS ASK ws#####rontheweb.com
- DNS ASK ne#####xininstitute.com
- DNS ASK op###er.com.au
- DNS ASK xn########h8abch1g1b0ap6a9vxa.com
- DNS ASK co####permarkt.nl
- DNS ASK ap###farm.org
- DNS ASK gc##cpa.com
- DNS ASK st###tives.org
- DNS ASK pi##mia.com
- DNS ASK de####scueusa.com
- DNS ASK ac###nvestor.ca
- DNS ASK mo#####-vacaciones.com
- DNS ASK wl#.##uisiana.gov
- DNS ASK d-##b.net
- DNS ASK ad####ivechat.us
- DNS ASK up###on89.com
- DNS ASK ea##gen.com
- DNS ASK sm##.#irectcon.net
- DNS ASK ga######onlinemagazine.com
- DNS ASK sm##.###global.yahoo.com
- DNS ASK sm##.live.com
- DNS ASK sm##.#ail.yahoo.com
- DNS ASK d4###edia.com
- DNS ASK is##h.com
- DNS ASK ba######ramsevatrust.org
- DNS ASK le###riage.com
- DNS ASK ko###hi-hp.com
- DNS ASK ma###acorp.com
- DNS ASK le###ridica.com
- DNS ASK to#####rthcare.com.au
- DNS ASK re####efield.co.uk
- DNS ASK di##ro.se
- DNS ASK ac###ctory.net
- DNS ASK yo###omla.com
- DNS ASK fa###nonline.de
- DNS ASK sm##.#ompuserve.com
- DNS ASK sh###yspizza.ph
- DNS ASK bi#####ultimedia.com
- DNS ASK gu###man.com.br
- DNS ASK sa##s.net
- DNS ASK dj###taro.com
- DNS ASK ib##.com.br
- DNS ASK ka####okuren.com
- DNS ASK or####networks.net
- DNS ASK ma##.#irmail.net
- DNS ASK sa##y.com
- DNS ASK nu###ech.com
- DNS ASK pa###ball.be
- DNS ASK ta##on.com
- DNS ASK pc##ds.com
- DNS ASK ko###-sa.com
- DNS ASK to###nmeuse.com
- ClassName: 'Indicator' WindowName: '(null)'