Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Name Parental Reports Controls UserMode' = 'C:\haxuimuqonvdno\uqvqjfblnmad.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Firewall PnP-X Registry Certificate UPnP] 'ImagePath' = 'C:\haxuimuqonvdno\uqvqjfblnmad.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Firewall PnP-X Registry Certificate UPnP] 'Start' = '00000002'
- 'C:\haxuimuqonvdno\fxakgxayc.exe' "c:\haxuimuqonvdno\uqvqjfblnmad.exe"
- 'C:\haxuimuqonvdno\uqvqjfblnmad.exe'
- 'C:\haxuimuqonvdno\sbr2p9akmptlnko1.exe'
- C:\haxuimuqonvdno\uqvqjfblnmad.exe
- C:\haxuimuqonvdno\fxakgxayc.exe
- C:\haxuimuqonvdno\aomqnq2f
- %WINDIR%\haxuimuqonvdno\vyc5hlv
- C:\haxuimuqonvdno\vyc5hlv
- C:\haxuimuqonvdno\sbr2p9akmptlnko1.exe
- C:\haxuimuqonvdno\fxakgxayc.exe
- C:\haxuimuqonvdno\uqvqjfblnmad.exe
- C:\haxuimuqonvdno\sbr2p9akmptlnko1.exe
- %WINDIR%\haxuimuqonvdno\vyc5hlv
- '62.##.253.114':51156
- '18#.#49.85.10':32097
- '15#.#82.245.137':33982
- '81.##7.50.99':52074
- '72.##1.47.203':22399
- '91.##.35.122':26126
- '20#.#36.131.186':52293
- '73.##.228.84':36884
- ClassName: 'Shell_TrayWnd' WindowName: ''