Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'ifzmdumeynfenzpjjc' = '%TEMP%\zvoaqgxohvmksdslk.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'zvoaqgxohvmksdslk' = '%TEMP%\zvoaqgxohvmksdslk.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'kbpwhseqenzs' = 'ifzmdumeynfenzpjjc.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'jbqykwjwlvicg' = '%TEMP%\vvsicwrmjbwykzspsoolb.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'jbqykwjwlvicg' = 'snfqfukasfvszjxp.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'kdtcpcqeuftotb' = 'gfbqjcwqmdxyjxplnihd.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'snfqfukasfvszjxp' = 'zvoaqgxohvmksdslk.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'zvoaqgxohvmksdslk' = '%TEMP%\snfqfukasfvszjxp.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'ndqwgqbmzhs' = '%TEMP%\gfbqjcwqmdxyjxplnihd.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'kbpwhseqenzs' = 'snfqfukasfvszjxp.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'nhyiwkzofrgcire' = 'vvsicwrmjbwykzspsoolb.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'jbqykwjwlvicg' = 'ifzmdumeynfenzpjjc.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'kbpwhseqenzs' = 'gfbqjcwqmdxyjxplnihd.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'kbpwhseqenzs' = '%TEMP%\gfbqjcwqmdxyjxplnihd.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'jbqykwjwlvicg' = '%TEMP%\zvoaqgxohvmksdslk.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'ifzmdumeynfenzpjjc' = '%TEMP%\vvsicwrmjbwykzspsoolb.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'ndqwgqbmzhs' = '%TEMP%\vvsicwrmjbwykzspsoolb.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'jbqykwjwlvicg' = '%TEMP%\trmaskdwrhaakxojkec.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'kdtcpcqeuftotb' = 'trmaskdwrhaakxojkec.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'nhyiwkzofrgcire' = 'zvoaqgxohvmksdslk.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'snfqfukasfvszjxp' = 'vvsicwrmjbwykzspsoolb.exe .'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'nhyiwkzofrgcire' = 'ifzmdumeynfenzpjjc.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'snfqfukasfvszjxp' = 'trmaskdwrhaakxojkec.exe .'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'jbqykwjwlvicg' = '%TEMP%\gfbqjcwqmdxyjxplnihd.exe .'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'kbpwhseqenzs' = '%TEMP%\ifzmdumeynfenzpjjc.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'zvoaqgxohvmksdslk' = '%TEMP%\vvsicwrmjbwykzspsoolb.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'jbqykwjwlvicg' = 'zvoaqgxohvmksdslk.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'kdtcpcqeuftotb' = 'snfqfukasfvszjxp.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'nhyiwkzofrgcire' = 'gfbqjcwqmdxyjxplnihd.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'snfqfukasfvszjxp' = 'ifzmdumeynfenzpjjc.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'ifzmdumeynfenzpjjc' = '%TEMP%\snfqfukasfvszjxp.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'zvoaqgxohvmksdslk' = '%TEMP%\trmaskdwrhaakxojkec.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'ndqwgqbmzhs' = '%TEMP%\ifzmdumeynfenzpjjc.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'kbpwhseqenzs' = '%TEMP%\trmaskdwrhaakxojkec.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'jbqykwjwlvicg' = '%TEMP%\snfqfukasfvszjxp.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'kbpwhseqenzs' = 'zvoaqgxohvmksdslk.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'kbpwhseqenzs' = 'vvsicwrmjbwykzspsoolb.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'jbqykwjwlvicg' = 'trmaskdwrhaakxojkec.exe .'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'nhyiwkzofrgcire' = 'trmaskdwrhaakxojkec.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'snfqfukasfvszjxp' = 'gfbqjcwqmdxyjxplnihd.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'ifzmdumeynfenzpjjc' = '%TEMP%\gfbqjcwqmdxyjxplnihd.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'zvoaqgxohvmksdslk' = '%TEMP%\gfbqjcwqmdxyjxplnihd.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'ndqwgqbmzhs' = '%TEMP%\snfqfukasfvszjxp.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'kbpwhseqenzs' = 'trmaskdwrhaakxojkec.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'jbqykwjwlvicg' = '%TEMP%\ifzmdumeynfenzpjjc.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'jbqykwjwlvicg' = 'vvsicwrmjbwykzspsoolb.exe .'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'kdtcpcqeuftotb' = 'zvoaqgxohvmksdslk.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'ifzmdumeynfenzpjjc' = '%TEMP%\ifzmdumeynfenzpjjc.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'kdtcpcqeuftotb' = 'vvsicwrmjbwykzspsoolb.exe'
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'kbpwhseqenzs' = '%TEMP%\zvoaqgxohvmksdslk.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'ndqwgqbmzhs' = '%TEMP%\zvoaqgxohvmksdslk.exe'
- hidden files
- Registry Editor (RegEdit)
- User Account Control (UAC)
- %TEMP%\mxprwfslwhz.exe
- <LS_APPDATA>\ndqwgqbmzhskmrangsivblvgremxprwfs.xna
- %ProgramFiles(x86)%\ndqwgqbmzhskmrangsivblvgremxprwfs.xna
- %WINDIR%\syswow64\ndqwgqbmzhskmrangsivblvgremxprwfs.xna
- %TEMP%\wbdyxwwwyvvctnlnvwbdyx.wwy
- %WINDIR%\wbdyxwwwyvvctnlnvwbdyx.wwy
- <LS_APPDATA>\wbdyxwwwyvvctnlnvwbdyx.wwy
- %ProgramFiles(x86)%\wbdyxwwwyvvctnlnvwbdyx.wwy
- %WINDIR%\syswow64\wbdyxwwwyvvctnlnvwbdyx.wwy
- %TEMP%\tfoqwcj.exe
- %TEMP%\mnlcxsokibxandxvzwxvmh.exe
- %TEMP%\vvsicwrmjbwykzspsoolb.exe
- %TEMP%\gfbqjcwqmdxyjxplnihd.exe
- %TEMP%\trmaskdwrhaakxojkec.exe
- %TEMP%\ifzmdumeynfenzpjjc.exe
- %WINDIR%\ndqwgqbmzhskmrangsivblvgremxprwfs.xna
- %TEMP%\zvoaqgxohvmksdslk.exe
- %WINDIR%\mnlcxsokibxandxvzwxvmh.exe
- %WINDIR%\vvsicwrmjbwykzspsoolb.exe
- %WINDIR%\gfbqjcwqmdxyjxplnihd.exe
- %WINDIR%\trmaskdwrhaakxojkec.exe
- %WINDIR%\ifzmdumeynfenzpjjc.exe
- %WINDIR%\zvoaqgxohvmksdslk.exe
- %WINDIR%\snfqfukasfvszjxp.exe
- %WINDIR%\syswow64\mnlcxsokibxandxvzwxvmh.exe
- %WINDIR%\syswow64\vvsicwrmjbwykzspsoolb.exe
- %WINDIR%\syswow64\gfbqjcwqmdxyjxplnihd.exe
- %WINDIR%\syswow64\trmaskdwrhaakxojkec.exe
- %WINDIR%\syswow64\ifzmdumeynfenzpjjc.exe
- %WINDIR%\syswow64\zvoaqgxohvmksdslk.exe
- %WINDIR%\syswow64\snfqfukasfvszjxp.exe
- %TEMP%\snfqfukasfvszjxp.exe
- %TEMP%\ndqwgqbmzhskmrangsivblvgremxprwfs.xna
- %WINDIR%\syswow64\snfqfukasfvszjxp.exe
- <LS_APPDATA>\ndqwgqbmzhskmrangsivblvgremxprwfs.xna
- %ProgramFiles(x86)%\ndqwgqbmzhskmrangsivblvgremxprwfs.xna
- %WINDIR%\syswow64\ndqwgqbmzhskmrangsivblvgremxprwfs.xna
- %TEMP%\wbdyxwwwyvvctnlnvwbdyx.wwy
- %WINDIR%\wbdyxwwwyvvctnlnvwbdyx.wwy
- <LS_APPDATA>\wbdyxwwwyvvctnlnvwbdyx.wwy
- %ProgramFiles(x86)%\wbdyxwwwyvvctnlnvwbdyx.wwy
- %WINDIR%\syswow64\wbdyxwwwyvvctnlnvwbdyx.wwy
- %TEMP%\mnlcxsokibxandxvzwxvmh.exe
- %TEMP%\vvsicwrmjbwykzspsoolb.exe
- %TEMP%\gfbqjcwqmdxyjxplnihd.exe
- %TEMP%\trmaskdwrhaakxojkec.exe
- %TEMP%\ifzmdumeynfenzpjjc.exe
- %WINDIR%\ndqwgqbmzhskmrangsivblvgremxprwfs.xna
- %TEMP%\zvoaqgxohvmksdslk.exe
- %WINDIR%\mnlcxsokibxandxvzwxvmh.exe
- %WINDIR%\vvsicwrmjbwykzspsoolb.exe
- %WINDIR%\gfbqjcwqmdxyjxplnihd.exe
- %WINDIR%\trmaskdwrhaakxojkec.exe
- %WINDIR%\ifzmdumeynfenzpjjc.exe
- %WINDIR%\zvoaqgxohvmksdslk.exe
- %WINDIR%\snfqfukasfvszjxp.exe
- %WINDIR%\syswow64\mnlcxsokibxandxvzwxvmh.exe
- %WINDIR%\syswow64\vvsicwrmjbwykzspsoolb.exe
- %WINDIR%\syswow64\gfbqjcwqmdxyjxplnihd.exe
- %WINDIR%\syswow64\trmaskdwrhaakxojkec.exe
- %WINDIR%\syswow64\ifzmdumeynfenzpjjc.exe
- %WINDIR%\syswow64\zvoaqgxohvmksdslk.exe
- %TEMP%\snfqfukasfvszjxp.exe
- %TEMP%\ndqwgqbmzhskmrangsivblvgremxprwfs.xna
- DNS ASK wh#####yip.everdot.org
- DNS ASK sh####ipaddress.com
- DNS ASK wh###smyip.ca
- DNS ASK wh###smyip.com
- '%TEMP%\mxprwfslwhz.exe' "<Full path to file>*"
- '%TEMP%\tfoqwcj.exe' "-%TEMP%\snfqfukasfvszjxp.exe"