Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Superfetch Solutions Peer Telephony' = '<SYSTEM32>\crmqzsbiagj.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Connection Background Defragmenter Host] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\ftlkbfnqyb.exe' "<SYSTEM32>\crmqzsbiagj.exe"
- '%WINDIR%\Temp\tc2p8whrn83bauc.exe' -r 20866 tcp
- '%TEMP%\tc2p8whk18ec7ucs7tbablj.exe'
- '<SYSTEM32>\crmqzsbiagj.exe'
- <SYSTEM32>\rlcdmpkfrbr\run
- <SYSTEM32>\rlcdmpkfrbr\rng
- %WINDIR%\Temp\tc2p8whrn83bauc.exe
- <SYSTEM32>\rlcdmpkfrbr\cfg
- %TEMP%\tc2p8whk18ec7ucs7tbablj.exe
- <SYSTEM32>\rlcdmpkfrbr\tst
- <SYSTEM32>\ftlkbfnqyb.exe
- <SYSTEM32>\crmqzsbiagj.exe
- <SYSTEM32>\ftlkbfnqyb.exe
- <SYSTEM32>\crmqzsbiagj.exe
- %WINDIR%\Temp\tc2p8whrn83bauc.exe
- %TEMP%\tc2p8whk18ec7ucs7tbablj.exe
- 'ri###ear.net':80
- 'fa###hear.net':80
- 'fa###rule.net':80
- 'fa###hunt.net':80
- 'ri###ule.net':80
- 'fi###monday.net':80
- 'so###feed.net':80
- 'so###monday.net':80
- 'so###under.net':80
- 'fi###under.net':80
- 'ri###unt.net':80
- 'ca###ear.net':80
- 'no###how.net':80
- 'po###hear.net':80
- 'po###rule.net':80
- 'ca###ule.net':80
- 'ri###how.net':80
- 'fa###show.net':80
- 'no###ear.net':80
- 'no###unt.net':80
- 'no###ule.net':80
- 'we###onday.net':80
- 'fe###eed.net':80
- 'fe###onday.net':80
- 'fe###nder.net':80
- 'we###nder.net':80
- 'ta###under.net':80
- 'le###nder.net':80
- 'we###end.net':80
- 'we###eed.net':80
- 'fe###end.net':80
- 'li###end.net':80
- 'th###under.net':80
- 'li###nder.net':80
- 'fi###lend.net':80
- 'fi###feed.net':80
- 'so###lend.net':80
- 'li###eed.net':80
- 'th###lend.net':80
- 'th###feed.net':80
- 'th###monday.net':80
- 'li###onday.net':80
- 'ca###unt.net':80
- 'fi###hear.net':80
- 'th###show.net':80
- 'so###hear.net':80
- 'th###while.net':80
- 'fi###rule.net':80
- 'th###rule.net':80
- 'li###ule.net':80
- 'li###unt.net':80
- 'li###how.net':80
- 'th###hunt.net':80
- 'ef###tbuilt.net':80
- 'se####strong.net':80
- 'si######edwerryhouse.net':80
- 'de####promise.net':80
- 'or###thrown.net':80
- 'jo####ymeasure.net':80
- 'of####urprise.net':80
- 'ri###nstorm.net':80
- 'gw#####ynhuddleston.net':80
- 'mo####gduring.net':80
- 'ch####nother.net':80
- 'ta###rule.net':80
- 'le###ule.net':80
- 'le###unt.net':80
- 'le###how.net':80
- 'ta###hunt.net':80
- 'ca###how.net':80
- 'po###hunt.net':80
- 'po###show.net':80
- 'ta###hear.net':80
- 'le###ear.net':80
- 'ta###show.net':80
- 'we###how.net':80
- 'fe###unt.net':80
- 'fe###how.net':80
- 'th###hear.net':80
- 'li###ear.net':80
- 'fe###ear.net':80
- 'we###ear.net':80
- 'we###ule.net':80
- 'we###unt.net':80
- 'fe###ule.net':80
- http://ri###ear.net/index.php
- http://fa###hear.net/index.php
- http://fa###rule.net/index.php
- http://fa###hunt.net/index.php
- http://ri###ule.net/index.php
- http://fi###monday.net/index.php
- http://so###feed.net/index.php
- http://so###monday.net/index.php
- http://so###under.net/index.php
- http://fi###under.net/index.php
- http://ri###unt.net/index.php
- http://ca###ear.net/index.php
- http://no###how.net/index.php
- http://po###hear.net/index.php
- http://po###rule.net/index.php
- http://ca###ule.net/index.php
- http://ri###how.net/index.php
- http://fa###show.net/index.php
- http://no###ear.net/index.php
- http://no###unt.net/index.php
- http://no###ule.net/index.php
- http://we###onday.net/index.php
- http://fe###eed.net/index.php
- http://fe###onday.net/index.php
- http://fe###nder.net/index.php
- http://we###nder.net/index.php
- http://ta###under.net/index.php
- http://le###nder.net/index.php
- http://we###end.net/index.php
- http://we###eed.net/index.php
- http://fe###end.net/index.php
- http://li###end.net/index.php
- http://th###under.net/index.php
- http://li###nder.net/index.php
- http://fi###lend.net/index.php
- http://fi###feed.net/index.php
- http://so###lend.net/index.php
- http://li###eed.net/index.php
- http://th###lend.net/index.php
- http://th###feed.net/index.php
- http://th###monday.net/index.php
- http://li###onday.net/index.php
- http://ca###unt.net/index.php
- http://fi###hear.net/index.php
- http://th###show.net/index.php
- http://so###hear.net/index.php
- http://th###while.net/index.php
- http://fi###rule.net/index.php
- http://th###rule.net/index.php
- http://li###ule.net/index.php
- http://li###unt.net/index.php
- http://li###how.net/index.php
- http://th###hunt.net/index.php
- http://ef###tbuilt.net/index.php
- http://se####strong.net/index.php
- http://si######edwerryhouse.net/index.php
- http://de####promise.net/index.php
- http://or###thrown.net/index.php
- http://jo####ymeasure.net/index.php
- http://of####urprise.net/index.php
- http://ri###nstorm.net/index.php
- http://gw#####ynhuddleston.net/index.php
- http://mo####gduring.net/index.php
- http://ch####nother.net/index.php
- http://ta###rule.net/index.php
- http://le###ule.net/index.php
- http://le###unt.net/index.php
- http://le###how.net/index.php
- http://ta###hunt.net/index.php
- http://ca###how.net/index.php
- http://po###hunt.net/index.php
- http://po###show.net/index.php
- http://ta###hear.net/index.php
- http://le###ear.net/index.php
- http://ta###show.net/index.php
- http://we###how.net/index.php
- http://fe###unt.net/index.php
- http://fe###how.net/index.php
- http://th###hear.net/index.php
- http://li###ear.net/index.php
- http://fe###ear.net/index.php
- http://we###ear.net/index.php
- http://we###ule.net/index.php
- http://we###unt.net/index.php
- http://fe###ule.net/index.php
- DNS ASK fa###rule.net
- DNS ASK ri###ear.net
- DNS ASK ri###ule.net
- DNS ASK ri###unt.net
- DNS ASK fa###hunt.net
- DNS ASK so###monday.net
- DNS ASK fi###monday.net
- DNS ASK fi###under.net
- DNS ASK fa###hear.net
- DNS ASK so###under.net
- DNS ASK fa###show.net
- DNS ASK po###hear.net
- DNS ASK ca###ear.net
- DNS ASK ca###ule.net
- DNS ASK ca###unt.net
- DNS ASK po###rule.net
- DNS ASK no###ear.net
- DNS ASK ri###how.net
- DNS ASK no###ule.net
- DNS ASK no###how.net
- DNS ASK no###unt.net
- DNS ASK so###feed.net
- DNS ASK we###onday.net
- DNS ASK fe###eed.net
- DNS ASK fe###onday.net
- DNS ASK fe###nder.net
- DNS ASK we###nder.net
- DNS ASK ta###under.net
- DNS ASK le###nder.net
- DNS ASK we###end.net
- DNS ASK we###eed.net
- DNS ASK fe###end.net
- DNS ASK li###end.net
- DNS ASK th###under.net
- DNS ASK li###nder.net
- DNS ASK fi###lend.net
- DNS ASK fi###feed.net
- DNS ASK so###lend.net
- DNS ASK li###eed.net
- DNS ASK th###lend.net
- DNS ASK th###feed.net
- DNS ASK th###monday.net
- DNS ASK li###onday.net
- DNS ASK fi###hear.net
- DNS ASK th###show.net
- DNS ASK so###hear.net
- DNS ASK th###while.net
- DNS ASK fi###rule.net
- DNS ASK th###rule.net
- DNS ASK li###ule.net
- DNS ASK li###unt.net
- DNS ASK li###how.net
- DNS ASK th###hunt.net
- DNS ASK ef###tbuilt.net
- DNS ASK se####strong.net
- DNS ASK si######edwerryhouse.net
- DNS ASK de####promise.net
- DNS ASK or###thrown.net
- DNS ASK jo####ymeasure.net
- DNS ASK of####urprise.net
- DNS ASK ri###nstorm.net
- DNS ASK gw#####ynhuddleston.net
- DNS ASK mo####gduring.net
- DNS ASK ch####nother.net
- DNS ASK ta###rule.net
- DNS ASK le###ule.net
- DNS ASK le###unt.net
- DNS ASK le###how.net
- DNS ASK ta###hunt.net
- DNS ASK ca###how.net
- DNS ASK po###hunt.net
- DNS ASK po###show.net
- DNS ASK ta###hear.net
- DNS ASK le###ear.net
- DNS ASK ta###show.net
- DNS ASK we###how.net
- DNS ASK fe###unt.net
- DNS ASK fe###how.net
- DNS ASK th###hear.net
- DNS ASK li###ear.net
- DNS ASK fe###ear.net
- DNS ASK we###ear.net
- DNS ASK we###ule.net
- DNS ASK we###unt.net
- DNS ASK fe###ule.net
- '23#.#55.255.250':1900