Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'qcldpxswqybsq' = '%TEMP%\zoavkvtaxioijrva.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'rckbmtnqjqsi' = '%TEMP%\ngwvodfqrgqotfnwyvtr.exe .'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'agjvbds' = '%TEMP%\pgurivvedqyuxhnuup.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'pwanuxnm' = '%TEMP%\cwnnhxamoepouhqadbaze.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'gothptkka' = 'zoavkvtaxioijrva.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ziodmrjkbg' = 'pgurivvedqyuxhnuup.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'uelblrkmekl' = 'pgurivvedqyuxhnuup.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'rckbmtnqjqsi' = '%TEMP%\ashfxlmwwktqufmuvro.exe .'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'pwanuxnm' = '%TEMP%\pgurivvedqyuxhnuup.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'agjvbds' = 'pgurivvedqyuxhnuup.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'pwanuxnm' = 'pgurivvedqyuxhnuup.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'nsufkl' = '%TEMP%\ngwvodfqrgqotfnwyvtr.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ziodmrjkbg' = 'zoavkvtaxioijrva.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'agjvbds' = 'cwnnhxamoepouhqadbaze.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'pwanuxnm' = '%TEMP%\gwjfvhgomyfaclqwv.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'pwanuxnm' = 'cwnnhxamoepouhqadbaze.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'nsufkl' = '%TEMP%\cwnnhxamoepouhqadbaze.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'gothptkka' = 'ashfxlmwwktqufmuvro.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'qcldpxswqybsq' = '%TEMP%\ashfxlmwwktqufmuvro.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'agjvbds' = '%TEMP%\zoavkvtaxioijrva.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'pwanuxnm' = 'gwjfvhgomyfaclqwv.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'rckbmtnqjqsi' = '%TEMP%\cwnnhxamoepouhqadbaze.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'nsufkl' = '%TEMP%\pgurivvedqyuxhnuup.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'agjvbds' = '%TEMP%\ngwvodfqrgqotfnwyvtr.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'uelblrkmekl' = 'ashfxlmwwktqufmuvro.exe .'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'uelblrkmekl' = 'zoavkvtaxioijrva.exe .'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ziodmrjkbg' = 'ashfxlmwwktqufmuvro.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'gothptkka' = 'ngwvodfqrgqotfnwyvtr.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'agjvbds' = 'gwjfvhgomyfaclqwv.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'pwanuxnm' = 'ngwvodfqrgqotfnwyvtr.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'gothptkka' = 'cwnnhxamoepouhqadbaze.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ziodmrjkbg' = 'ngwvodfqrgqotfnwyvtr.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'uelblrkmekl' = 'cwnnhxamoepouhqadbaze.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'qcldpxswqybsq' = '%TEMP%\gwjfvhgomyfaclqwv.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'rckbmtnqjqsi' = '%TEMP%\gwjfvhgomyfaclqwv.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'nsufkl' = '%TEMP%\zoavkvtaxioijrva.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'agjvbds' = '%TEMP%\cwnnhxamoepouhqadbaze.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'pwanuxnm' = '%TEMP%\ngwvodfqrgqotfnwyvtr.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'agjvbds' = 'ashfxlmwwktqufmuvro.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ziodmrjkbg' = 'gwjfvhgomyfaclqwv.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'agjvbds' = 'zoavkvtaxioijrva.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'uelblrkmekl' = 'ngwvodfqrgqotfnwyvtr.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'rckbmtnqjqsi' = '%TEMP%\zoavkvtaxioijrva.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'nsufkl' = '%TEMP%\gwjfvhgomyfaclqwv.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'agjvbds' = '%TEMP%\ashfxlmwwktqufmuvro.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'agjvbds' = 'ngwvodfqrgqotfnwyvtr.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'pwanuxnm' = 'zoavkvtaxioijrva.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'gothptkka' = 'pgurivvedqyuxhnuup.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'uelblrkmekl' = 'gwjfvhgomyfaclqwv.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'qcldpxswqybsq' = '%TEMP%\ngwvodfqrgqotfnwyvtr.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'agjvbds' = '%TEMP%\gwjfvhgomyfaclqwv.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'pwanuxnm' = '%TEMP%\ashfxlmwwktqufmuvro.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'pwanuxnm' = 'ashfxlmwwktqufmuvro.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'qcldpxswqybsq' = '%TEMP%\pgurivvedqyuxhnuup.exe'
- <Drive name for removable media>:\agjvbds.exe
- <Drive name for removable media>:\ziodmrjkbg.bat
- <Drive name for removable media>:\rckbmtnqjqsi.bat
- <Drive name for removable media>:\reohudzezimedj.bat
- <Drive name for removable media>:\autorun.inf
- hidden files
- Windows Task Manager (Taskmgr)
- Registry Editor (RegEdit)
- User Account Control (UAC)
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '00000001'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '00000001'
- %TEMP%\fuqtsslzody.exe
- %WINDIR%\syswow64\twwfihtozysapldwipxftzcclo.zuf
- %ProgramFiles(x86)%\twwfihtozysapldwipxftzcclo.zuf
- %LOCALAPPDATA%\twwfihtozysapldwipxftzcclo.zuf
- %WINDIR%\twwfihtozysapldwipxftzcclo.zuf
- %TEMP%\twwfihtozysapldwipxftzcclo.zuf
- %WINDIR%\syswow64\uitnbliokuzsszcgdvohgxlwqeolrnxcvvcfj.yrk
- %ProgramFiles(x86)%\uitnbliokuzsszcgdvohgxlwqeolrnxcvvcfj.yrk
- %LOCALAPPDATA%\uitnbliokuzsszcgdvohgxlwqeolrnxcvvcfj.yrk
- %TEMP%\uitnbliokuzsszcgdvohgxlwqeolrnxcvvcfj.yrk
- D:\reohudzezimedj.bat
- %TEMP%\uelblrkmekl\ziodmrjkbg.exe
- %TEMP%\uelblrkmekl\rcx6834.tmp
- C:\ziodmrjkbg.bat
- C:\rckbmtnqjqsi.bat
- C:\reohudzezimedj.bat
- C:\autorun.inf
- D:\ziodmrjkbg.bat
- D:\rckbmtnqjqsi.bat
- %TEMP%\rckbmtnqjqsi.exe
- %WINDIR%\uitnbliokuzsszcgdvohgxlwqeolrnxcvvcfj.yrk
- %TEMP%\toghctxkneqqxlvgkjjjpn.exe
- %WINDIR%\gwjfvhgomyfaclqwv.exe
- %WINDIR%\syswow64\zoavkvtaxioijrva.exe
- %WINDIR%\syswow64\gwjfvhgomyfaclqwv.exe
- %WINDIR%\syswow64\pgurivvedqyuxhnuup.exe
- %WINDIR%\syswow64\ashfxlmwwktqufmuvro.exe
- %WINDIR%\syswow64\ngwvodfqrgqotfnwyvtr.exe
- %WINDIR%\syswow64\cwnnhxamoepouhqadbaze.exe
- %WINDIR%\syswow64\toghctxkneqqxlvgkjjjpn.exe
- %WINDIR%\zoavkvtaxioijrva.exe
- %WINDIR%\pgurivvedqyuxhnuup.exe
- %TEMP%\ngwvodfqrgqotfnwyvtr.exe
- %WINDIR%\ashfxlmwwktqufmuvro.exe
- %WINDIR%\ngwvodfqrgqotfnwyvtr.exe
- %WINDIR%\cwnnhxamoepouhqadbaze.exe
- %WINDIR%\toghctxkneqqxlvgkjjjpn.exe
- %TEMP%\zoavkvtaxioijrva.exe
- %TEMP%\gwjfvhgomyfaclqwv.exe
- %TEMP%\pgurivvedqyuxhnuup.exe
- %TEMP%\ashfxlmwwktqufmuvro.exe
- %TEMP%\cwnnhxamoepouhqadbaze.exe
- D:\autorun.inf
- %WINDIR%\syswow64\zoavkvtaxioijrva.exe
- %TEMP%\twwfihtozysapldwipxftzcclo.zuf
- %WINDIR%\syswow64\uitnbliokuzsszcgdvohgxlwqeolrnxcvvcfj.yrk
- %ProgramFiles(x86)%\uitnbliokuzsszcgdvohgxlwqeolrnxcvvcfj.yrk
- %LOCALAPPDATA%\uitnbliokuzsszcgdvohgxlwqeolrnxcvvcfj.yrk
- %WINDIR%\uitnbliokuzsszcgdvohgxlwqeolrnxcvvcfj.yrk
- %TEMP%\uitnbliokuzsszcgdvohgxlwqeolrnxcvvcfj.yrk
- C:\ziodmrjkbg.bat
- %LOCALAPPDATA%\twwfihtozysapldwipxftzcclo.zuf
- %WINDIR%\twwfihtozysapldwipxftzcclo.zuf
- C:\rckbmtnqjqsi.bat
- D:\ziodmrjkbg.bat
- D:\rckbmtnqjqsi.bat
- D:\reohudzezimedj.bat
- D:\autorun.inf
- <Drive name for removable media>:\agjvbds.exe
- <Drive name for removable media>:\ziodmrjkbg.bat
- <Drive name for removable media>:\rckbmtnqjqsi.bat
- C:\reohudzezimedj.bat
- C:\autorun.inf
- %ProgramFiles(x86)%\twwfihtozysapldwipxftzcclo.zuf
- %WINDIR%\syswow64\twwfihtozysapldwipxftzcclo.zuf
- %TEMP%\toghctxkneqqxlvgkjjjpn.exe
- %WINDIR%\syswow64\pgurivvedqyuxhnuup.exe
- %WINDIR%\syswow64\ashfxlmwwktqufmuvro.exe
- %WINDIR%\syswow64\ngwvodfqrgqotfnwyvtr.exe
- %WINDIR%\syswow64\cwnnhxamoepouhqadbaze.exe
- %WINDIR%\syswow64\toghctxkneqqxlvgkjjjpn.exe
- %WINDIR%\zoavkvtaxioijrva.exe
- %WINDIR%\gwjfvhgomyfaclqwv.exe
- %WINDIR%\pgurivvedqyuxhnuup.exe
- %WINDIR%\syswow64\gwjfvhgomyfaclqwv.exe
- %WINDIR%\ashfxlmwwktqufmuvro.exe
- %WINDIR%\cwnnhxamoepouhqadbaze.exe
- %WINDIR%\toghctxkneqqxlvgkjjjpn.exe
- %TEMP%\zoavkvtaxioijrva.exe
- %TEMP%\gwjfvhgomyfaclqwv.exe
- %TEMP%\pgurivvedqyuxhnuup.exe
- %TEMP%\ashfxlmwwktqufmuvro.exe
- %TEMP%\ngwvodfqrgqotfnwyvtr.exe
- %TEMP%\cwnnhxamoepouhqadbaze.exe
- %WINDIR%\ngwvodfqrgqotfnwyvtr.exe
- <Drive name for removable media>:\reohudzezimedj.bat
- <Drive name for removable media>:\autorun.inf
- from %TEMP%\uelblrkmekl\rcx6834.tmp to %TEMP%\uelblrkmekl\ziodmrjkbg.exe
- 'wh###smyip.com':80
- 'sh####ipaddress.com':80
- 'wh#####yipaddress.com':80
- 'yo##ube.com':80
- '87.##7.117.151':27569
- 'ym####uiwcymao.info':80
- http://www.wh###smyip.com/
- http://www.sh####ipaddress.com/
- http://wh#####yipaddress.com/
- http://www.yo##ube.com/
- http://ym####uiwcymao.info/
- DNS ASK wh###smyip.ca
- DNS ASK el####nansnan.org
- DNS ASK sk###miq.net
- DNS ASK sm####uiwcymao.biz
- DNS ASK mz####dsholapet.cc
- DNS ASK cj####dsholapet.cc
- DNS ASK ei###wiq.biz
- DNS ASK ay###aiq.biz
- DNS ASK fb###afox.com
- DNS ASK zc##dgn.com
- DNS ASK iq###qeoya.info
- DNS ASK iu###wiq.info
- DNS ASK cj####nansnan.com
- DNS ASK yp####nansnan.cc
- DNS ASK cs###eiq.biz
- DNS ASK ym####uiwcymao.info
- DNS ASK wk####dsholapet.org
- DNS ASK yo##ube.com
- DNS ASK wh#####yipaddress.com
- DNS ASK wh#####yip.everdot.org
- DNS ASK sh####ipaddress.com
- DNS ASK wh###smyip.com
- DNS ASK kv####dsholapet.cc
- DNS ASK km###geoya.info
- '%TEMP%\fuqtsslzody.exe' "<Full path to file>*"
- '%TEMP%\rckbmtnqjqsi.exe' "-<SYSTEM32>\\zoavkvtaxioijrva.exe"