Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'AuthIP Bluetooth Defragmenter' = 'C:\yqzwrdurshvzso\hltuypf.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Audio Connectivity Connections Superfetch Player] 'Start' = '00000002'
- 'C:\yqzwrdurshvzso\axfyhzcamsu.exe' "c:\yqzwrdurshvzso\hltuypf.exe"
- 'C:\yqzwrdurshvzso\hltuypf.exe'
- 'C:\yqzwrdurshvzso\gdxle2kugslqfhnvmfc2g.exe'
- C:\yqzwrdurshvzso\hltuypf.exe
- C:\yqzwrdurshvzso\axfyhzcamsu.exe
- C:\yqzwrdurshvzso\rsvyeanmib
- %WINDIR%\yqzwrdurshvzso\yzex2r9k
- C:\yqzwrdurshvzso\yzex2r9k
- C:\yqzwrdurshvzso\gdxle2kugslqfhnvmfc2g.exe
- C:\yqzwrdurshvzso\axfyhzcamsu.exe
- C:\yqzwrdurshvzso\hltuypf.exe
- C:\yqzwrdurshvzso\gdxle2kugslqfhnvmfc2g.exe
- %WINDIR%\yqzwrdurshvzso\yzex2r9k
- 'pr####tpeople.net':80
- 'th####aughter.net':80
- 'pr####tbrown.net':80
- 'th###people.net':80
- 'pr####tdaughter.net':80
- 'ch###brown.net':80
- 'co####ebrown.net':80
- 'ch###ready.net':80
- 'co####eready.net':80
- 'th###bright.net':80
- 'cl###bright.net':80
- 'th####xplain.net':80
- 'cl####xplain.net':80
- 'th###inside.net':80
- 'pr####tready.net':80
- 'th###brown.net':80
- 'cl###inside.net':80
- 'th###ready.net':80
- 'ch###people.net':80
- 'mi###eready.net':80
- 'tw###eready.net':80
- 'of####aughter.net':80
- 'al####aughter.net':80
- 'mi###ebrown.net':80
- 'tw####people.net':80
- 'mi####daughter.net':80
- 'tw###ebrown.net':80
- 'mi####people.net':80
- 'co####edaughter.net':80
- 'of###ready.net':80
- 'co####epeople.net':80
- 'ch####aughter.net':80
- 'al###ready.net':80
- 'of###people.net':80
- 'al###people.net':80
- 'of###brown.net':80
- 'al###brown.net':80
- 'cl####nstead.net':80
- 'tw####inside.net':80
- 'ra####instead.net':80
- 'tw####bright.net':80
- 'mi####inside.net':80
- 'mo####ginstead.net':80
- 'ra####bright.net':80
- 'mo####gbright.net':80
- 'ra####explain.net':80
- 'mo####gexplain.net':80
- 'of###inside.net':80
- 'al###inside.net':80
- 'of###bright.net':80
- 'al###bright.net':80
- 'mi####instead.net':80
- 'tw####explain.net':80
- 'mi####bright.net':80
- 'tw####instead.net':80
- 'mi####explain.net':80
- 'ra####inside.net':80
- 'am####explain.net':80
- 'we####rexplain.net':80
- 'am####instead.net':80
- 'we####rinstead.net':80
- 'am####bright.net':80
- 'we####rinside.net':80
- 'th####nstead.net':80
- 'we####rbright.net':80
- 'am####inside.net':80
- 'hi####yinstead.net':80
- 'st####eexplain.net':80
- 'mo####ginside.net':80
- 'st####einstead.net':80
- 'hi####yexplain.net':80
- 'st####einside.net':80
- 'hi####yinside.net':80
- 'st####ebright.net':80
- 'hi####ybright.net':80
- http://pr####tpeople.net/index.php?me########
- http://th####aughter.net/index.php?me########
- http://pr####tbrown.net/index.php?me########
- http://th###people.net/index.php?me########
- http://pr####tdaughter.net/index.php?me########
- http://ch###brown.net/index.php?me########
- http://co####ebrown.net/index.php?me########
- http://ch###ready.net/index.php?me########
- http://co####eready.net/index.php?me########
- http://th###bright.net/index.php?me########
- http://cl###bright.net/index.php?me########
- http://th####xplain.net/index.php?me########
- http://cl####xplain.net/index.php?me########
- http://th###inside.net/index.php?me########
- http://pr####tready.net/index.php?me########
- http://th###brown.net/index.php?me########
- http://cl###inside.net/index.php?me########
- http://th###ready.net/index.php?me########
- http://ch###people.net/index.php?me########
- http://mi###eready.net/index.php?me########
- http://tw###eready.net/index.php?me########
- http://of####aughter.net/index.php?me########
- http://al####aughter.net/index.php?me########
- http://mi###ebrown.net/index.php?me########
- http://tw####people.net/index.php?me########
- http://mi####daughter.net/index.php?me########
- http://tw###ebrown.net/index.php?me########
- http://mi####people.net/index.php?me########
- http://co####edaughter.net/index.php?me########
- http://of###ready.net/index.php?me########
- http://co####epeople.net/index.php?me########
- http://ch####aughter.net/index.php?me########
- http://al###ready.net/index.php?me########
- http://of###people.net/index.php?me########
- http://al###people.net/index.php?me########
- http://of###brown.net/index.php?me########
- http://al###brown.net/index.php?me########
- http://cl####nstead.net/index.php?me########
- http://tw####inside.net/index.php?me########
- http://ra####instead.net/index.php?me########
- http://tw####bright.net/index.php?me########
- http://mi####inside.net/index.php?me########
- http://mo####ginstead.net/index.php?me########
- http://ra####bright.net/index.php?me########
- http://mo####gbright.net/index.php?me########
- http://ra####explain.net/index.php?me########
- http://mo####gexplain.net/index.php?me########
- http://of###inside.net/index.php?me########
- http://al###inside.net/index.php?me########
- http://of###bright.net/index.php?me########
- http://al###bright.net/index.php?me########
- http://mi####instead.net/index.php?me########
- http://tw####explain.net/index.php?me########
- http://mi####bright.net/index.php?me########
- http://tw####instead.net/index.php?me########
- http://mi####explain.net/index.php?me########
- http://ra####inside.net/index.php?me########
- http://am####explain.net/index.php?me########
- http://we####rexplain.net/index.php?me########
- http://am####instead.net/index.php?me########
- http://we####rinstead.net/index.php?me########
- http://am####bright.net/index.php?me########
- http://we####rinside.net/index.php?me########
- http://th####nstead.net/index.php?me########
- http://we####rbright.net/index.php?me########
- http://am####inside.net/index.php?me########
- http://hi####yinstead.net/index.php?me########
- http://st####eexplain.net/index.php?me########
- http://mo####ginside.net/index.php?me########
- http://st####einstead.net/index.php?me########
- http://hi####yexplain.net/index.php?me########
- http://st####einside.net/index.php?me########
- http://hi####yinside.net/index.php?me########
- http://st####ebright.net/index.php?me########
- http://hi####ybright.net/index.php?me########
- DNS ASK th####aughter.net
- DNS ASK pr####tdaughter.net
- DNS ASK th###people.net
- DNS ASK pr####tpeople.net
- DNS ASK ch###ready.net
- DNS ASK co####ebrown.net
- DNS ASK ch###people.net
- DNS ASK co####eready.net
- DNS ASK ch###brown.net
- DNS ASK pr####tbrown.net
- DNS ASK th###bright.net
- DNS ASK cl###bright.net
- DNS ASK th####xplain.net
- DNS ASK cl####xplain.net
- DNS ASK th###inside.net
- DNS ASK pr####tready.net
- DNS ASK th###brown.net
- DNS ASK cl###inside.net
- DNS ASK th###ready.net
- DNS ASK tw###eready.net
- DNS ASK mi###ebrown.net
- DNS ASK al####aughter.net
- DNS ASK mi###eready.net
- DNS ASK tw###ebrown.net
- DNS ASK mi####daughter.net
- DNS ASK tw####daughter.net
- DNS ASK mi####people.net
- DNS ASK tw####people.net
- DNS ASK of####aughter.net
- DNS ASK co####edaughter.net
- DNS ASK of###ready.net
- DNS ASK co####epeople.net
- DNS ASK ch####aughter.net
- DNS ASK al###ready.net
- DNS ASK of###people.net
- DNS ASK al###people.net
- DNS ASK of###brown.net
- DNS ASK al###brown.net
- DNS ASK ra####instead.net
- DNS ASK mo####ginstead.net
- DNS ASK mi####inside.net
- DNS ASK tw####inside.net
- DNS ASK ra####explain.net
- DNS ASK mo####gbright.net
- DNS ASK ra####inside.net
- DNS ASK mo####gexplain.net
- DNS ASK ra####bright.net
- DNS ASK tw####bright.net
- DNS ASK of###inside.net
- DNS ASK al###inside.net
- DNS ASK of###bright.net
- DNS ASK al###bright.net
- DNS ASK mi####instead.net
- DNS ASK tw####explain.net
- DNS ASK mi####bright.net
- DNS ASK tw####instead.net
- DNS ASK mi####explain.net
- DNS ASK we####rexplain.net
- DNS ASK am####bright.net
- DNS ASK we####rinstead.net
- DNS ASK am####explain.net
- DNS ASK we####rbright.net
- DNS ASK th####nstead.net
- DNS ASK cl####nstead.net
- DNS ASK am####inside.net
- DNS ASK we####rinside.net
- DNS ASK am####instead.net
- DNS ASK hi####yinstead.net
- DNS ASK st####eexplain.net
- DNS ASK mo####ginside.net
- DNS ASK st####einstead.net
- DNS ASK hi####yexplain.net
- DNS ASK st####einside.net
- DNS ASK hi####yinside.net
- DNS ASK st####ebright.net
- DNS ASK hi####ybright.net
- ClassName: 'Shell_TrayWnd' WindowName: ''