Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Superfetch Color Office' = 'C:\jrwvrebqes\zqwkeqisztio.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Host Registrar Update Connections Panel Window] 'Start' = '00000002'
- 'C:\jrwvrebqes\smgegghne.exe' "c:\jrwvrebqes\zqwkeqisztio.exe"
- 'C:\jrwvrebqes\zqwkeqisztio.exe'
- 'C:\jrwvrebqes\hnqkl2uhok5gdkmp12cq.exe'
- C:\jrwvrebqes\zqwkeqisztio.exe
- C:\jrwvrebqes\smgegghne.exe
- C:\jrwvrebqes\wqchyafizp
- %WINDIR%\jrwvrebqes\qgr9vvx5lcq
- C:\jrwvrebqes\qgr9vvx5lcq
- C:\jrwvrebqes\hnqkl2uhok5gdkmp12cq.exe
- C:\jrwvrebqes\smgegghne.exe
- C:\jrwvrebqes\zqwkeqisztio.exe
- C:\jrwvrebqes\hnqkl2uhok5gdkmp12cq.exe
- %WINDIR%\jrwvrebqes\qgr9vvx5lcq
- 'ag####tbrown.net':80
- 'do###brown.net':80
- 'ag####tready.net':80
- 'do###ready.net':80
- 'ag####tdaughter.net':80
- 'do####aughter.net':80
- 'ag####tpeople.net':80
- 'do###people.net':80
- 'qu####xplain.net':80
- 'se####explain.net':80
- 'qu####nstead.net':80
- 'se####instead.net':80
- 'qu###inside.net':80
- 'se####inside.net':80
- 'qu###bright.net':80
- 'se####bright.net':80
- 'la###brown.net':80
- 'ca####nbrown.net':80
- 'la###ready.net':80
- 'ca####nready.net':80
- 'la####aughter.net':80
- 'ca####ndaughter.net':80
- 'la###people.net':80
- 'ca####npeople.net':80
- 'ni###brown.net':80
- 'de###ebrown.net':80
- 'ni###ready.net':80
- 'de###eready.net':80
- 'ni####aughter.net':80
- 'de####daughter.net':80
- 'ni###people.net':80
- 'de####people.net':80
- 'st####explain.net':80
- 'tr####xplain.net':80
- 'st####instead.net':80
- 'tr####nstead.net':80
- 'st####inside.net':80
- 'tr###inside.net':80
- 'st####bright.net':80
- 'tr###bright.net':80
- 're####explain.net':80
- 'el####icexplain.net':80
- 're####instead.net':80
- 'el####icinstead.net':80
- 're####inside.net':80
- 'el####icinside.net':80
- 're####bright.net':80
- 'el####icbright.net':80
- 'fl####xplain.net':80
- 'br####xplain.net':80
- 'fl####nstead.net':80
- 'br####nstead.net':80
- 'fl###inside.net':80
- 'br###inside.net':80
- 'fl###bright.net':80
- 'br###bright.net':80
- 'be####explain.net':80
- 'ga####explain.net':80
- 'be####instead.net':80
- 'ga####instead.net':80
- 'be####inside.net':80
- 'ga####inside.net':80
- 'be####bright.net':80
- 'ga####bright.net':80
- http://ag####tbrown.net/index.php?me########
- http://do###brown.net/index.php?me########
- http://ag####tready.net/index.php?me########
- http://do###ready.net/index.php?me########
- http://ag####tdaughter.net/index.php?me########
- http://do####aughter.net/index.php?me########
- http://ag####tpeople.net/index.php?me########
- http://do###people.net/index.php?me########
- http://qu####xplain.net/index.php?me########
- http://se####explain.net/index.php?me########
- http://qu####nstead.net/index.php?me########
- http://se####instead.net/index.php?me########
- http://qu###inside.net/index.php?me########
- http://se####inside.net/index.php?me########
- http://qu###bright.net/index.php?me########
- http://se####bright.net/index.php?me########
- http://la###brown.net/index.php?me########
- http://ca####nbrown.net/index.php?me########
- http://la###ready.net/index.php?me########
- http://ca####nready.net/index.php?me########
- http://la####aughter.net/index.php?me########
- http://ca####ndaughter.net/index.php?me########
- http://la###people.net/index.php?me########
- http://ca####npeople.net/index.php?me########
- http://ni###brown.net/index.php?me########
- http://de###ebrown.net/index.php?me########
- http://ni###ready.net/index.php?me########
- http://de###eready.net/index.php?me########
- http://ni####aughter.net/index.php?me########
- http://de####daughter.net/index.php?me########
- http://ni###people.net/index.php?me########
- http://de####people.net/index.php?me########
- http://st####explain.net/index.php?me########
- http://tr####xplain.net/index.php?me########
- http://st####instead.net/index.php?me########
- http://tr####nstead.net/index.php?me########
- http://st####inside.net/index.php?me########
- http://tr###inside.net/index.php?me########
- http://st####bright.net/index.php?me########
- http://tr###bright.net/index.php?me########
- http://re####explain.net/index.php?me########
- http://el####icexplain.net/index.php?me########
- http://re####instead.net/index.php?me########
- http://el####icinstead.net/index.php?me########
- http://re####inside.net/index.php?me########
- http://el####icinside.net/index.php?me########
- http://re####bright.net/index.php?me########
- http://el####icbright.net/index.php?me########
- http://fl####xplain.net/index.php?me########
- http://br####xplain.net/index.php?me########
- http://fl####nstead.net/index.php?me########
- http://br####nstead.net/index.php?me########
- http://fl###inside.net/index.php?me########
- http://br###inside.net/index.php?me########
- http://fl###bright.net/index.php?me########
- http://br###bright.net/index.php?me########
- http://be####explain.net/index.php?me########
- http://ga####explain.net/index.php?me########
- http://be####instead.net/index.php?me########
- http://ga####instead.net/index.php?me########
- http://be####inside.net/index.php?me########
- http://ga####inside.net/index.php?me########
- http://be####bright.net/index.php?me########
- http://ga####bright.net/index.php?me########
- DNS ASK do###brown.net
- DNS ASK ag####tpeople.net
- DNS ASK do###ready.net
- DNS ASK ag####tbrown.net
- DNS ASK do####aughter.net
- DNS ASK ni###ready.net
- DNS ASK do###people.net
- DNS ASK ag####tdaughter.net
- DNS ASK se####explain.net
- DNS ASK qu###bright.net
- DNS ASK se####instead.net
- DNS ASK qu####xplain.net
- DNS ASK se####inside.net
- DNS ASK ag####tready.net
- DNS ASK se####bright.net
- DNS ASK qu###inside.net
- DNS ASK ca####nbrown.net
- DNS ASK la###people.net
- DNS ASK ca####nready.net
- DNS ASK la###brown.net
- DNS ASK ca####ndaughter.net
- DNS ASK re###dready.net
- DNS ASK ca####npeople.net
- DNS ASK la####aughter.net
- DNS ASK de###ebrown.net
- DNS ASK ni###people.net
- DNS ASK de###eready.net
- DNS ASK ni###brown.net
- DNS ASK de####daughter.net
- DNS ASK la###ready.net
- DNS ASK de####people.net
- DNS ASK ni####aughter.net
- DNS ASK qu####nstead.net
- DNS ASK st####explain.net
- DNS ASK tr####xplain.net
- DNS ASK st####instead.net
- DNS ASK tr####nstead.net
- DNS ASK st####inside.net
- DNS ASK tr###inside.net
- DNS ASK st####bright.net
- DNS ASK tr###bright.net
- DNS ASK re####explain.net
- DNS ASK el####icexplain.net
- DNS ASK re####instead.net
- DNS ASK el####icinstead.net
- DNS ASK re####inside.net
- DNS ASK el####icinside.net
- DNS ASK re####bright.net
- DNS ASK el####icbright.net
- DNS ASK fl####xplain.net
- DNS ASK br####xplain.net
- DNS ASK fl####nstead.net
- DNS ASK br####nstead.net
- DNS ASK fl###inside.net
- DNS ASK br###inside.net
- DNS ASK fl###bright.net
- DNS ASK br###bright.net
- DNS ASK be####explain.net
- DNS ASK ga####explain.net
- DNS ASK be####instead.net
- DNS ASK ga####instead.net
- DNS ASK be####inside.net
- DNS ASK ga####inside.net
- DNS ASK be####bright.net
- DNS ASK ga####bright.net
- ClassName: 'Shell_TrayWnd' WindowName: ''