Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Defender Panel Peer KtmRm Notification WMI' = 'C:\wfdmsrmcelmkfe\kgurtetfhuhj.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Controls UserMode Netlogon VC Tools Policy] 'Start' = '00000002'
- 'C:\wfdmsrmcelmkfe\bwymfxl.exe' "c:\wfdmsrmcelmkfe\kgurtetfhuhj.exe"
- 'C:\wfdmsrmcelmkfe\kgurtetfhuhj.exe'
- 'C:\wfdmsrmcelmkfe\vgz8c2n7ivtvphl9rox.exe'
- C:\wfdmsrmcelmkfe\kgurtetfhuhj.exe
- C:\wfdmsrmcelmkfe\bwymfxl.exe
- C:\wfdmsrmcelmkfe\zliuhrln
- %WINDIR%\wfdmsrmcelmkfe\bxjrsp4fwgd
- C:\wfdmsrmcelmkfe\bxjrsp4fwgd
- C:\wfdmsrmcelmkfe\vgz8c2n7ivtvphl9rox.exe
- C:\wfdmsrmcelmkfe\bwymfxl.exe
- C:\wfdmsrmcelmkfe\kgurtetfhuhj.exe
- C:\wfdmsrmcelmkfe\vgz8c2n7ivtvphl9rox.exe
- %WINDIR%\wfdmsrmcelmkfe\bxjrsp4fwgd
- 'jo####ystraight.net':80
- 'hu####dstraight.net':80
- 'jo####yairplane.net':80
- 'hu####dairplane.net':80
- 'jo####yguard.net':80
- 'hu####dfence.net':80
- 'de####yairplane.net':80
- 'hu####dguard.net':80
- 'jo####yfence.net':80
- 're####erbanker.net':80
- 'wo###found.net':80
- 're####erfound.net':80
- 'fo####banker.net':80
- 'in####sebanker.net':80
- 'wo###spring.net':80
- 're####ersuccess.net':80
- 'wo###banker.net':80
- 're####erspring.net':80
- 'wo####uccess.net':80
- 'be###gguard.net':80
- 'ri###nfence.net':80
- 'be####straight.net':80
- 'ri###nguard.net':80
- 'be###gfence.net':80
- 'ch####traight.net':80
- 'th####traight.net':80
- 'ch####irplane.net':80
- 'th####irplane.net':80
- 'ri####straight.net':80
- 'li####straight.net':80
- 'de####yguard.net':80
- 'li####airplane.net':80
- 'de####ystraight.net':80
- 'li###eguard.net':80
- 'ri####airplane.net':80
- 'be####airplane.net':80
- 'de####yfence.net':80
- 'li###efence.net':80
- 'in####sesuccess.net':80
- 'th###spring.net':80
- 'ch####uccess.net':80
- 'th###found.net':80
- 'ch###spring.net':80
- 'th####uccess.net':80
- 'wi###nfound.net':80
- 'su###rfound.net':80
- 'ch###banker.net':80
- 'th###banker.net':80
- 'ch###found.net':80
- 'be###gfound.net':80
- 'ri####spring.net':80
- 'li####banker.net':80
- 'ri###nfound.net':80
- 'be####spring.net':80
- 'ri####banker.net':80
- 'be####banker.net':80
- 'ri####success.net':80
- 'be####success.net':80
- 'ef####banker.net':80
- 'th####hbanker.net':80
- 'ef####success.net':80
- 'th####hsuccess.net':80
- 'fo###tfound.net':80
- 'in####sespring.net':80
- 'fo####success.net':80
- 'in####sefound.net':80
- 'fo####spring.net':80
- 'th####hspring.net':80
- 'wi####success.net':80
- 'su####success.net':80
- 'wi####spring.net':80
- 'su####spring.net':80
- 'wi####banker.net':80
- 'th####hfound.net':80
- 'ef####spring.net':80
- 'su####banker.net':80
- 'ef###tfound.net':80
- http://jo####ystraight.net/index.php?me########
- http://hu####dstraight.net/index.php?me########
- http://jo####yairplane.net/index.php?me########
- http://hu####dairplane.net/index.php?me########
- http://jo####yguard.net/index.php?me########
- http://hu####dfence.net/index.php?me########
- http://de####yairplane.net/index.php?me########
- http://hu####dguard.net/index.php?me########
- http://jo####yfence.net/index.php?me########
- http://re####erbanker.net/index.php?me########
- http://wo###found.net/index.php?me########
- http://re####erfound.net/index.php?me########
- http://fo####banker.net/index.php?me########
- http://in####sebanker.net/index.php?me########
- http://wo###spring.net/index.php?me########
- http://re####ersuccess.net/index.php?me########
- http://wo###banker.net/index.php?me########
- http://re####erspring.net/index.php?me########
- http://wo####uccess.net/index.php?me########
- http://be###gguard.net/index.php?me########
- http://ri###nfence.net/index.php?me########
- http://be####straight.net/index.php?me########
- http://ri###nguard.net/index.php?me########
- http://be###gfence.net/index.php?me########
- http://ch####traight.net/index.php?me########
- http://th####traight.net/index.php?me########
- http://ch####irplane.net/index.php?me########
- http://th####irplane.net/index.php?me########
- http://ri####straight.net/index.php?me########
- http://li####straight.net/index.php?me########
- http://de####yguard.net/index.php?me########
- http://li####airplane.net/index.php?me########
- http://de####ystraight.net/index.php?me########
- http://li###eguard.net/index.php?me########
- http://ri####airplane.net/index.php?me########
- http://be####airplane.net/index.php?me########
- http://de####yfence.net/index.php?me########
- http://li###efence.net/index.php?me########
- http://in####sesuccess.net/index.php?me########
- http://th###spring.net/index.php?me########
- http://ch####uccess.net/index.php?me########
- http://th###found.net/index.php?me########
- http://ch###spring.net/index.php?me########
- http://th####uccess.net/index.php?me########
- http://wi###nfound.net/index.php?me########
- http://su###rfound.net/index.php?me########
- http://ch###banker.net/index.php?me########
- http://th###banker.net/index.php?me########
- http://ch###found.net/index.php?me########
- http://be###gfound.net/index.php?me########
- http://ri####spring.net/index.php?me########
- http://li####banker.net/index.php?me########
- http://ri###nfound.net/index.php?me########
- http://be####spring.net/index.php?me########
- http://ri####banker.net/index.php?me########
- http://be####banker.net/index.php?me########
- http://ri####success.net/index.php?me########
- http://be####success.net/index.php?me########
- http://ef####banker.net/index.php?me########
- http://th####hbanker.net/index.php?me########
- http://ef####success.net/index.php?me########
- http://th####hsuccess.net/index.php?me########
- http://fo###tfound.net/index.php?me########
- http://in####sespring.net/index.php?me########
- http://fo####success.net/index.php?me########
- http://in####sefound.net/index.php?me########
- http://fo####spring.net/index.php?me########
- http://th####hspring.net/index.php?me########
- http://wi####success.net/index.php?me########
- http://su####success.net/index.php?me########
- http://wi####spring.net/index.php?me########
- http://su####spring.net/index.php?me########
- http://wi####banker.net/index.php?me########
- http://th####hfound.net/index.php?me########
- http://ef####spring.net/index.php?me########
- http://su####banker.net/index.php?me########
- http://ef###tfound.net/index.php?me########
- DNS ASK jo####ystraight.net
- DNS ASK hu####dstraight.net
- DNS ASK jo####yairplane.net
- DNS ASK hu####dairplane.net
- DNS ASK jo####yguard.net
- DNS ASK hu####dfence.net
- DNS ASK de####yairplane.net
- DNS ASK hu####dguard.net
- DNS ASK jo####yfence.net
- DNS ASK re####erbanker.net
- DNS ASK wo###found.net
- DNS ASK re####erfound.net
- DNS ASK fo####banker.net
- DNS ASK in####sebanker.net
- DNS ASK wo###spring.net
- DNS ASK re####ersuccess.net
- DNS ASK wo###banker.net
- DNS ASK re####erspring.net
- DNS ASK wo####uccess.net
- DNS ASK li####airplane.net
- DNS ASK ri###nfence.net
- DNS ASK be###gfence.net
- DNS ASK ri###nguard.net
- DNS ASK be###gguard.net
- DNS ASK ch####irplane.net
- DNS ASK th####traight.net
- DNS ASK ch###guard.net
- DNS ASK th####irplane.net
- DNS ASK ch####traight.net
- DNS ASK be####straight.net
- DNS ASK de####yguard.net
- DNS ASK li###eguard.net
- DNS ASK de####ystraight.net
- DNS ASK li####straight.net
- DNS ASK de####yfence.net
- DNS ASK be####airplane.net
- DNS ASK ri####straight.net
- DNS ASK li###efence.net
- DNS ASK ri####airplane.net
- DNS ASK th###spring.net
- DNS ASK ch####uccess.net
- DNS ASK th###found.net
- DNS ASK ch###spring.net
- DNS ASK th####uccess.net
- DNS ASK wi###nfound.net
- DNS ASK su###rfound.net
- DNS ASK ch###banker.net
- DNS ASK th###banker.net
- DNS ASK ch###found.net
- DNS ASK be###gfound.net
- DNS ASK ri####spring.net
- DNS ASK li####banker.net
- DNS ASK ri###nfound.net
- DNS ASK be####spring.net
- DNS ASK ri####banker.net
- DNS ASK be####banker.net
- DNS ASK ri####success.net
- DNS ASK be####success.net
- DNS ASK wi####spring.net
- DNS ASK th####hbanker.net
- DNS ASK fo###tfound.net
- DNS ASK th####hsuccess.net
- DNS ASK ef####banker.net
- DNS ASK in####sefound.net
- DNS ASK fo####success.net
- DNS ASK in####sesuccess.net
- DNS ASK fo####spring.net
- DNS ASK in####sespring.net
- DNS ASK ef####success.net
- DNS ASK su####success.net
- DNS ASK wi####banker.net
- DNS ASK su####spring.net
- DNS ASK wi####success.net
- DNS ASK su####banker.net
- DNS ASK ef####spring.net
- DNS ASK th####hspring.net
- DNS ASK ef###tfound.net
- DNS ASK th####hfound.net
- ClassName: 'Shell_TrayWnd' WindowName: ''