Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Layer Management Center Secure' = 'C:\xcovtgwssbytoo\ymqwerjhsioe.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Config Defender Engine WinHTTP Card PC] 'ImagePath' = 'C:\xcovtgwssbytoo\ymqwerjhsioe.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Config Defender Engine WinHTTP Card PC] 'Start' = '00000002'
- 'C:\xcovtgwssbytoo\rlvwlojyvq.exe' "c:\xcovtgwssbytoo\ymqwerjhsioe.exe"
- 'C:\xcovtgwssbytoo\ymqwerjhsioe.exe'
- 'C:\xcovtgwssbytoo\ot3yq3m2qvodlxhcz8tfbz.exe'
- C:\xcovtgwssbytoo\ymqwerjhsioe.exe
- C:\xcovtgwssbytoo\rlvwlojyvq.exe
- C:\xcovtgwssbytoo\ot3yq3m2qvodlxhcz8tfbz.exe
- %WINDIR%\xcovtgwssbytoo\imhcfhbl
- C:\xcovtgwssbytoo\imhcfhbl
- C:\xcovtgwssbytoo\rlvwlojyvq.exe
- C:\xcovtgwssbytoo\ymqwerjhsioe.exe
- C:\xcovtgwssbytoo\ot3yq3m2qvodlxhcz8tfbz.exe
- %WINDIR%\xcovtgwssbytoo\imhcfhbl
- 'si####listen.net':80
- 'mo###rbring.net':80
- 'si####demand.net':80
- 'mo####listen.net':80
- 'se###ashout.net':80
- 'la###demand.net':80
- 'si###ebring.net':80
- 'la###shout.net':80
- 'mo####inlisten.net':80
- 'po####lebring.net':80
- 'mo####indemand.net':80
- 'po####lelisten.net':80
- 'si###eshout.net':80
- 'mo####demand.net':80
- 'mo####inbring.net':80
- 'mo###rshout.net':80
- 'se####demand.net':80
- 'ma####alsilver.net':80
- 'se####lsilver.net':80
- 'ma####alsister.net':80
- 'se####lsister.net':80
- 'pr####lyvalley.net':80
- 'sw###valley.net':80
- 'pr####lylabor.net':80
- 'sw###labor.net':80
- 'la###bring.net':80
- 'se###abring.net':80
- 'la###listen.net':80
- 'se####listen.net':80
- 'ma####alvalley.net':80
- 'se####lvalley.net':80
- 'ma####allabor.net':80
- 'se####llabor.net':80
- http://si####listen.net/index.php
- http://mo###rbring.net/index.php
- http://si####demand.net/index.php
- http://mo####listen.net/index.php
- http://se###ashout.net/index.php
- http://la###demand.net/index.php
- http://si###ebring.net/index.php
- http://la###shout.net/index.php
- http://mo####inlisten.net/index.php
- http://po####lebring.net/index.php
- http://mo####indemand.net/index.php
- http://po####lelisten.net/index.php
- http://si###eshout.net/index.php
- http://mo####demand.net/index.php
- http://mo####inbring.net/index.php
- http://mo###rshout.net/index.php
- http://se####demand.net/index.php
- http://ma####alsilver.net/index.php
- http://se####lsilver.net/index.php
- http://ma####alsister.net/index.php
- http://se####lsister.net/index.php
- http://pr####lyvalley.net/index.php
- http://sw###valley.net/index.php
- http://pr####lylabor.net/index.php
- http://sw###labor.net/index.php
- http://la###bring.net/index.php
- http://se###abring.net/index.php
- http://la###listen.net/index.php
- http://se####listen.net/index.php
- http://ma####alvalley.net/index.php
- http://se####lvalley.net/index.php
- http://ma####allabor.net/index.php
- http://se####llabor.net/index.php
- DNS ASK si####listen.net
- DNS ASK mo###rbring.net
- DNS ASK si####demand.net
- DNS ASK mo####listen.net
- DNS ASK se###ashout.net
- DNS ASK la###demand.net
- DNS ASK si###ebring.net
- DNS ASK la###shout.net
- DNS ASK mo####demand.net
- DNS ASK po####lelisten.net
- DNS ASK mo####inlisten.net
- DNS ASK po####ledemand.net
- DNS ASK mo####indemand.net
- DNS ASK mo###rshout.net
- DNS ASK si###eshout.net
- DNS ASK po####lebring.net
- DNS ASK mo####inbring.net
- DNS ASK ma####alsilver.net
- DNS ASK se####lsilver.net
- DNS ASK ma####alsister.net
- DNS ASK se####lsister.net
- DNS ASK pr####lyvalley.net
- DNS ASK sw###valley.net
- DNS ASK pr####lylabor.net
- DNS ASK sw###labor.net
- DNS ASK se####lvalley.net
- DNS ASK se####listen.net
- DNS ASK la###bring.net
- DNS ASK se####demand.net
- DNS ASK la###listen.net
- DNS ASK se####llabor.net
- DNS ASK ma####alvalley.net
- DNS ASK se###abring.net
- DNS ASK ma####allabor.net
- ClassName: 'Shell_TrayWnd' WindowName: ''