Technical Information
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'Adobe_Reader' = '%TEMP%\\wmpscfgs.exe'
- %WINDIR%\tasks\at1.job
- <SYSTEM32>\tasks\at14
- %WINDIR%\tasks\at15.job
- <SYSTEM32>\tasks\at15
- %WINDIR%\tasks\at16.job
- <SYSTEM32>\tasks\at16
- %WINDIR%\tasks\at17.job
- <SYSTEM32>\tasks\at17
- %WINDIR%\tasks\at18.job
- <SYSTEM32>\tasks\at13
- %WINDIR%\tasks\at14.job
- <SYSTEM32>\tasks\at18
- %WINDIR%\tasks\at20.job
- <SYSTEM32>\tasks\at20
- %WINDIR%\tasks\at21.job
- <SYSTEM32>\tasks\at21
- %WINDIR%\tasks\at22.job
- <SYSTEM32>\tasks\at22
- %WINDIR%\tasks\at23.job
- <SYSTEM32>\tasks\at23
- %WINDIR%\tasks\at19.job
- <SYSTEM32>\tasks\at19
- %WINDIR%\tasks\at13.job
- <SYSTEM32>\tasks\at12
- %WINDIR%\tasks\at12.job
- %WINDIR%\tasks\at2.job
- <SYSTEM32>\tasks\at2
- %WINDIR%\tasks\at3.job
- <SYSTEM32>\tasks\at3
- %WINDIR%\tasks\at4.job
- <SYSTEM32>\tasks\at4
- %WINDIR%\tasks\at5.job
- <SYSTEM32>\tasks\at5
- %WINDIR%\tasks\at6.job
- <SYSTEM32>\tasks\at1
- <SYSTEM32>\tasks\at6
- <SYSTEM32>\tasks\at7
- %WINDIR%\tasks\at8.job
- <SYSTEM32>\tasks\at8
- %WINDIR%\tasks\at9.job
- <SYSTEM32>\tasks\at9
- %WINDIR%\tasks\at10.job
- <SYSTEM32>\tasks\at10
- %WINDIR%\tasks\at11.job
- <SYSTEM32>\tasks\at11
- %WINDIR%\tasks\at7.job
- %WINDIR%\tasks\at24.job
- <SYSTEM32>\tasks\at24
- %ProgramFiles(x86)%\adobe\acrotray .exe
- %ProgramFiles(x86)%\adobe\acrotray.exe
- %ProgramFiles(x86)%\internet explorer\wmpscfgs.exe
- %ALLUSERSPROFILE%\microsoft\crypto\rsa\s-1-5-18\d42cc0c3858a58db2db37658219e6400_0cb67e2f-dc95-45ca-8fb8-69bde8e3f814
- %TEMP%\wmpscfgs.exe
- %ProgramFiles(x86)%\811657.dat
- %ProgramFiles(x86)%\811735.dat
- %ProgramFiles(x86)%\811657.dat
- %WINDIR%\tasks\at21.job
- <SYSTEM32>\tasks\at21
- %WINDIR%\tasks\at22.job
- <SYSTEM32>\tasks\at22
- %WINDIR%\tasks\at23.job
- <SYSTEM32>\tasks\at23
- %WINDIR%\tasks\at24.job
- <SYSTEM32>\tasks\at24
- %WINDIR%\tasks\at3.job
- %WINDIR%\tasks\at14.job
- <SYSTEM32>\tasks\at3
- <SYSTEM32>\tasks\at4
- %WINDIR%\tasks\at5.job
- <SYSTEM32>\tasks\at5
- %WINDIR%\tasks\at6.job
- <SYSTEM32>\tasks\at6
- %WINDIR%\tasks\at7.job
- <SYSTEM32>\tasks\at7
- %WINDIR%\tasks\at8.job
- <SYSTEM32>\tasks\at8
- %WINDIR%\tasks\at20.job
- <SYSTEM32>\tasks\at20
- <SYSTEM32>\tasks\at2
- %WINDIR%\tasks\at2.job
- <SYSTEM32>\tasks\at19
- %WINDIR%\tasks\at1.job
- <SYSTEM32>\tasks\at1
- %WINDIR%\tasks\at10.job
- <SYSTEM32>\tasks\at10
- %WINDIR%\tasks\at11.job
- <SYSTEM32>\tasks\at11
- %WINDIR%\tasks\at12.job
- <SYSTEM32>\tasks\at12
- %WINDIR%\tasks\at13.job
- %WINDIR%\tasks\at9.job
- %WINDIR%\tasks\at4.job
- <SYSTEM32>\tasks\at13
- %WINDIR%\tasks\at15.job
- <SYSTEM32>\tasks\at15
- %WINDIR%\tasks\at16.job
- <SYSTEM32>\tasks\at16
- %WINDIR%\tasks\at17.job
- <SYSTEM32>\tasks\at17
- %WINDIR%\tasks\at18.job
- <SYSTEM32>\tasks\at18
- %WINDIR%\tasks\at19.job
- %ProgramFiles(x86)%\811735.dat
- <SYSTEM32>\tasks\at14
- <SYSTEM32>\tasks\at9
- from %TEMP%\wmpscfgs.exe to %TEMP%\wmpscfgs .exe
- %TEMP%\wmpscfgs.exe
- 'su####etforme.com':80
- 'cl#####4.expdirclk.com':80
- 'ec#####rforrinho.info':443
- 'x.##2.us':80
- 'o.##2.us':80
- 'oc##.###tg2.amazontrust.com':80
- 'oc##.####ca1.amazontrust.com':80
- 'cr#.####ca1.amazontrust.com':80
- http://www.su####etforme.com/dupe.php?q=###########################################################################################
- http://cl#####4.expdirclk.com/click?i=#############
- http://www.su####etforme.com/search.php?q=###########################################################################################
- http://www.su####etforme.com/search.php?ch#######################################################################################################################################################...
- http://x.##2.us/x.cer
- http://o.##2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
- http://oc##.###tg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
- http://oc##.####ca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
- http://cr#.####ca1.amazontrust.com/rootca1.crl
- 'ec#####rforrinho.info':443
- DNS ASK su####etforme.com
- DNS ASK cl#####4.expdirclk.com
- DNS ASK ec#####rforrinho.info
- DNS ASK x.##2.us
- DNS ASK o.##2.us
- DNS ASK oc##.###tg2.amazontrust.com
- DNS ASK oc##.####ca1.amazontrust.com
- DNS ASK cr#.####ca1.amazontrust.com
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%TEMP%\wmpscfgs.exe'
- '%ProgramFiles(x86)%\internet explorer\wmpscfgs.exe' Explorer\wmpscfgs.exe
- '%TEMP%\wmpscfgs.exe' ' (with hidden window)
- '%ProgramFiles(x86)%\internet explorer\wmpscfgs.exe' Explorer\wmpscfgs.exe' (with hidden window)