Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Plug Search Encryption Extensible' = 'C:\abvjzwodu\spqiocgggmnw.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Topology Endpoint AutoConfig] 'ImagePath' = 'C:\abvjzwodu\spqiocgggmnw.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Topology Endpoint AutoConfig] 'Start' = '00000002'
- 'C:\abvjzwodu\wwbtytxp.exe' "c:\abvjzwodu\spqiocgggmnw.exe"
- 'C:\abvjzwodu\spqiocgggmnw.exe'
- 'C:\abvjzwodu\qc02tfwislssekt.exe'
- C:\abvjzwodu\spqiocgggmnw.exe
- C:\abvjzwodu\wwbtytxp.exe
- C:\abvjzwodu\txjtdp
- %WINDIR%\abvjzwodu\jpnhv6
- C:\abvjzwodu\jpnhv6
- C:\abvjzwodu\qc02tfwislssekt.exe
- C:\abvjzwodu\wwbtytxp.exe
- C:\abvjzwodu\spqiocgggmnw.exe
- C:\abvjzwodu\qc02tfwislssekt.exe
- %WINDIR%\abvjzwodu\jpnhv6
- 'se####contain.net':80
- 'la####ontain.net':80
- 'la###became.net':80
- 'la####ndustry.net':80
- 'se####became.net':80
- 'mo####industry.net':80
- 'si####became.net':80
- 'si####industry.net':80
- 'se####basket.net':80
- 'la###basket.net':80
- 'se####lmaster.net':80
- 'ma####almaster.net':80
- 'ma#####lcontinue.net':80
- 'pr#####ydiscover.net':80
- 'se####lcontinue.net':80
- 'ma#####ldiscover.net':80
- 'se####industry.net':80
- 'se####ldiscover.net':80
- 'se####lwonder.net':80
- 'ma####alwonder.net':80
- 'pe####sindustry.net':80
- 'wi####industry.net':80
- 'po####lebasket.net':80
- 'po####lecontain.net':80
- 'mo####inbasket.net':80
- 'wi####contain.net':80
- 'pe####sbasket.net':80
- 'pe####scontain.net':80
- 'pe####sbecame.net':80
- 'wi####became.net':80
- 'si####basket.net':80
- 'mo####basket.net':80
- 'mo####contain.net':80
- 'mo####became.net':80
- 'si####contain.net':80
- 'po####lebecame.net':80
- 'mo####incontain.net':80
- 'mo####inbecame.net':80
- 'mo#####nindustry.net':80
- 'po#####eindustry.net':80
- 'sw####iscover.net':80
- 'po#####ediscover.net':80
- 'pe####scontinue.net':80
- 'mo#####ndiscover.net':80
- 'mo####inwonder.net':80
- 'po####lewonder.net':80
- 'pe####swonder.net':80
- 'wi####wonder.net':80
- 'wi####master.net':80
- 'wi####continue.net':80
- 'pe####smaster.net':80
- 'mo####wonder.net':80
- 'si####discover.net':80
- 'si####wonder.net':80
- 'si####master.net':80
- 'mo####master.net':80
- 'mo####inmaster.net':80
- 'po####lemaster.net':80
- 'po#####econtinue.net':80
- 'mo####discover.net':80
- 'mo#####ncontinue.net':80
- 'le####iscover.net':80
- 'sw####ontinue.net':80
- 'fi####discover.net':80
- 'fi####wonder.net':80
- 'le###wonder.net':80
- 'sw###wonder.net':80
- 'pr####lywonder.net':80
- 'pr####lymaster.net':80
- 'pr#####ycontinue.net':80
- 'sw###master.net':80
- 'su####tmaster.net':80
- 'su####twonder.net':80
- 'su####tcontinue.net':80
- 'pe####sdiscover.net':80
- 'wi####discover.net':80
- 'fi####master.net':80
- 'le###master.net':80
- 'le####ontinue.net':80
- 'su####tdiscover.net':80
- 'fi####continue.net':80
- http://se####contain.net/index.php
- http://la####ontain.net/index.php
- http://la###became.net/index.php
- http://la####ndustry.net/index.php
- http://se####became.net/index.php
- http://mo####industry.net/index.php
- http://si####became.net/index.php
- http://si####industry.net/index.php
- http://se####basket.net/index.php
- http://la###basket.net/index.php
- http://se####lmaster.net/index.php
- http://ma####almaster.net/index.php
- http://ma#####lcontinue.net/index.php
- http://pr#####ydiscover.net/index.php
- http://se####lcontinue.net/index.php
- http://ma#####ldiscover.net/index.php
- http://se####industry.net/index.php
- http://se####ldiscover.net/index.php
- http://se####lwonder.net/index.php
- http://ma####alwonder.net/index.php
- http://pe####sindustry.net/index.php
- http://wi####industry.net/index.php
- http://po####lebasket.net/index.php
- http://po####lecontain.net/index.php
- http://mo####inbasket.net/index.php
- http://wi####contain.net/index.php
- http://pe####sbasket.net/index.php
- http://pe####scontain.net/index.php
- http://pe####sbecame.net/index.php
- http://wi####became.net/index.php
- http://si####basket.net/index.php
- http://mo####basket.net/index.php
- http://mo####contain.net/index.php
- http://mo####became.net/index.php
- http://si####contain.net/index.php
- http://po####lebecame.net/index.php
- http://mo####incontain.net/index.php
- http://mo####inbecame.net/index.php
- http://mo#####nindustry.net/index.php
- http://po#####eindustry.net/index.php
- http://sw####iscover.net/index.php
- http://po#####ediscover.net/index.php
- http://pe####scontinue.net/index.php
- http://mo#####ndiscover.net/index.php
- http://mo####inwonder.net/index.php
- http://po####lewonder.net/index.php
- http://pe####swonder.net/index.php
- http://wi####wonder.net/index.php
- http://wi####master.net/index.php
- http://wi####continue.net/index.php
- http://pe####smaster.net/index.php
- http://mo####wonder.net/index.php
- http://si####discover.net/index.php
- http://si####wonder.net/index.php
- http://si####master.net/index.php
- http://mo####master.net/index.php
- http://mo####inmaster.net/index.php
- http://po####lemaster.net/index.php
- http://po#####econtinue.net/index.php
- http://mo####discover.net/index.php
- http://mo#####ncontinue.net/index.php
- http://le####iscover.net/index.php
- http://sw####ontinue.net/index.php
- http://fi####discover.net/index.php
- http://fi####wonder.net/index.php
- http://le###wonder.net/index.php
- http://sw###wonder.net/index.php
- http://pr####lywonder.net/index.php
- http://pr####lymaster.net/index.php
- http://pr#####ycontinue.net/index.php
- http://sw###master.net/index.php
- http://su####tmaster.net/index.php
- http://su####twonder.net/index.php
- http://su####tcontinue.net/index.php
- http://pe####sdiscover.net/index.php
- http://wi####discover.net/index.php
- http://fi####master.net/index.php
- http://le###master.net/index.php
- http://le####ontinue.net/index.php
- http://su####tdiscover.net/index.php
- http://fi####continue.net/index.php
- DNS ASK se####contain.net
- DNS ASK la####ontain.net
- DNS ASK la###became.net
- DNS ASK la####ndustry.net
- DNS ASK se####became.net
- DNS ASK mo####industry.net
- DNS ASK si####became.net
- DNS ASK si####industry.net
- DNS ASK se####basket.net
- DNS ASK la###basket.net
- DNS ASK se####lmaster.net
- DNS ASK ma####almaster.net
- DNS ASK ma#####lcontinue.net
- DNS ASK pr#####ydiscover.net
- DNS ASK se####lcontinue.net
- DNS ASK ma#####ldiscover.net
- DNS ASK se####industry.net
- DNS ASK se####ldiscover.net
- DNS ASK se####lwonder.net
- DNS ASK ma####alwonder.net
- DNS ASK pe####sindustry.net
- DNS ASK wi####industry.net
- DNS ASK po####lebasket.net
- DNS ASK po####lecontain.net
- DNS ASK mo####inbasket.net
- DNS ASK wi####contain.net
- DNS ASK pe####sbasket.net
- DNS ASK pe####scontain.net
- DNS ASK pe####sbecame.net
- DNS ASK wi####became.net
- DNS ASK si####basket.net
- DNS ASK mo####basket.net
- DNS ASK mo####contain.net
- DNS ASK mo####became.net
- DNS ASK si####contain.net
- DNS ASK po####lebecame.net
- DNS ASK mo####incontain.net
- DNS ASK mo####inbecame.net
- DNS ASK mo#####nindustry.net
- DNS ASK po#####eindustry.net
- DNS ASK sw####iscover.net
- DNS ASK po#####ediscover.net
- DNS ASK pe####scontinue.net
- DNS ASK mo#####ndiscover.net
- DNS ASK mo####inwonder.net
- DNS ASK po####lewonder.net
- DNS ASK pe####swonder.net
- DNS ASK wi####wonder.net
- DNS ASK wi####master.net
- DNS ASK wi####continue.net
- DNS ASK pe####smaster.net
- DNS ASK mo####wonder.net
- DNS ASK si####discover.net
- DNS ASK si####wonder.net
- DNS ASK si####master.net
- DNS ASK mo####master.net
- DNS ASK mo####inmaster.net
- DNS ASK po####lemaster.net
- DNS ASK po#####econtinue.net
- DNS ASK mo####discover.net
- DNS ASK mo#####ncontinue.net
- DNS ASK le####iscover.net
- DNS ASK sw####ontinue.net
- DNS ASK fi####discover.net
- DNS ASK fi####wonder.net
- DNS ASK le###wonder.net
- DNS ASK sw###wonder.net
- DNS ASK pr####lywonder.net
- DNS ASK pr####lymaster.net
- DNS ASK pr#####ycontinue.net
- DNS ASK sw###master.net
- DNS ASK su####tmaster.net
- DNS ASK su####twonder.net
- DNS ASK su####tcontinue.net
- DNS ASK pe####sdiscover.net
- DNS ASK wi####discover.net
- DNS ASK fi####master.net
- DNS ASK le###master.net
- DNS ASK le####ontinue.net
- DNS ASK su####tdiscover.net
- DNS ASK fi####continue.net
- ClassName: 'Shell_TrayWnd' WindowName: ''