Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Superfetch Builder Locator Grouping Acquisition' = 'C:\rjwxxwme\lafwhphbl.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Access SSDP Authentication Event Host Grouping] 'ImagePath' = 'C:\rjwxxwme\lafwhphbl.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Access SSDP Authentication Event Host Grouping] 'Start' = '00000002'
- 'C:\rjwxxwme\vqetlam.exe' "c:\rjwxxwme\lafwhphbl.exe"
- 'C:\rjwxxwme\lafwhphbl.exe'
- 'C:\rjwxxwme\uw2p5eo5pudq3gotncd.exe'
- C:\rjwxxwme\lafwhphbl.exe
- C:\rjwxxwme\vqetlam.exe
- C:\rjwxxwme\uw2p5eo5pudq3gotncd.exe
- %WINDIR%\rjwxxwme\jbklqr8whbw
- C:\rjwxxwme\jbklqr8whbw
- C:\rjwxxwme\vqetlam.exe
- C:\rjwxxwme\lafwhphbl.exe
- C:\rjwxxwme\uw2p5eo5pudq3gotncd.exe
- %WINDIR%\rjwxxwme\jbklqr8whbw
- 'st####lothes.net':80
- 'mi####lothes.net':80
- 'st###health.net':80
- 'mi###health.net':80
- 'st####istant.net':80
- 'pr####separate.net':80
- 'do####health.net':80
- 'mi####istant.net':80
- 'do####separate.net':80
- 'ev####ghealth.net':80
- 'bu####ngclothes.net':80
- 'ev####gseparate.net':80
- 'bu####nghealth.net':80
- 'ev####gclothes.net':80
- 'st####eparate.net':80
- 'mi####eparate.net':80
- 'bu####ngdistant.net':80
- 'ev####gdistant.net':80
- 'br####health.net':80
- 're####health.net':80
- 'br####separate.net':80
- 're####separate.net':80
- 'br####clothes.net':80
- 're####distant.net':80
- 'pr####eseparate.net':80
- 're####clothes.net':80
- 'br####distant.net':80
- 'pr####clothes.net':80
- 'do####distant.net':80
- 'pr####health.net':80
- 'do####clothes.net':80
- 'pr####distant.net':80
- 'fe####clothes.net':80
- 'fe####distant.net':80
- 'fe####separate.net':80
- 'fe####health.net':80
- 'pr####esmell.net':80
- 'de###esmell.net':80
- 'br####future.net':80
- 're####future.net':80
- 'pr####eearly.net':80
- 'de####safety.net':80
- 'pr####efuture.net':80
- 'de###eearly.net':80
- 'pr####esafety.net':80
- 'do####future.net':80
- 'br###nsmell.net':80
- 'do####safety.net':80
- 'fe####future.net':80
- 're###tsmell.net':80
- 'br####safety.net':80
- 're####safety.net':80
- 'br###nearly.net':80
- 're###tearly.net':80
- 'mo####nthealth.net':80
- 'ou####ehealth.net':80
- 'mo#####tseparate.net':80
- 'ou####eseparate.net':80
- 'mo####ntclothes.net':80
- 'ou####edistant.net':80
- 'bu#####gseparate.net':80
- 'ou####eclothes.net':80
- 'mo####ntdistant.net':80
- 'st###smell.net':80
- 'st####thearly.net':80
- 'de####future.net':80
- 'st####thsmell.net':80
- 'st###early.net':80
- 'st####thfuture.net':80
- 'st###future.net':80
- 'st####thsafety.net':80
- 'st###safety.net':80
- http://st####lothes.net/index.php
- http://mi####lothes.net/index.php
- http://st###health.net/index.php
- http://mi###health.net/index.php
- http://st####istant.net/index.php
- http://pr####separate.net/index.php
- http://do####health.net/index.php
- http://mi####istant.net/index.php
- http://do####separate.net/index.php
- http://ev####ghealth.net/index.php
- http://bu####ngclothes.net/index.php
- http://ev####gseparate.net/index.php
- http://bu####nghealth.net/index.php
- http://ev####gclothes.net/index.php
- http://st####eparate.net/index.php
- http://mi####eparate.net/index.php
- http://bu####ngdistant.net/index.php
- http://ev####gdistant.net/index.php
- http://br####health.net/index.php
- http://re####health.net/index.php
- http://br####separate.net/index.php
- http://re####separate.net/index.php
- http://br####clothes.net/index.php
- http://re####distant.net/index.php
- http://pr####eseparate.net/index.php
- http://re####clothes.net/index.php
- http://br####distant.net/index.php
- http://pr####clothes.net/index.php
- http://do####distant.net/index.php
- http://pr####health.net/index.php
- http://do####clothes.net/index.php
- http://pr####distant.net/index.php
- http://fe####clothes.net/index.php
- http://fe####distant.net/index.php
- http://fe####separate.net/index.php
- http://fe####health.net/index.php
- http://pr####esmell.net/index.php
- http://de###esmell.net/index.php
- http://br####future.net/index.php
- http://re####future.net/index.php
- http://pr####eearly.net/index.php
- http://de####safety.net/index.php
- http://pr####efuture.net/index.php
- http://de###eearly.net/index.php
- http://pr####esafety.net/index.php
- http://do####future.net/index.php
- http://br###nsmell.net/index.php
- http://do####safety.net/index.php
- http://fe####future.net/index.php
- http://re###tsmell.net/index.php
- http://br####safety.net/index.php
- http://re####safety.net/index.php
- http://br###nearly.net/index.php
- http://re###tearly.net/index.php
- http://mo####nthealth.net/index.php
- http://ou####ehealth.net/index.php
- http://mo#####tseparate.net/index.php
- http://ou####eseparate.net/index.php
- http://mo####ntclothes.net/index.php
- http://ou####edistant.net/index.php
- http://bu#####gseparate.net/index.php
- http://ou####eclothes.net/index.php
- http://mo####ntdistant.net/index.php
- http://st###smell.net/index.php
- http://st####thearly.net/index.php
- http://de####future.net/index.php
- http://st####thsmell.net/index.php
- http://st###early.net/index.php
- http://st####thfuture.net/index.php
- http://st###future.net/index.php
- http://st####thsafety.net/index.php
- http://st###safety.net/index.php
- DNS ASK mi####lothes.net
- DNS ASK st####istant.net
- DNS ASK mi###health.net
- DNS ASK st####lothes.net
- DNS ASK mi####istant.net
- DNS ASK do####health.net
- DNS ASK pr####health.net
- DNS ASK do####separate.net
- DNS ASK pr####separate.net
- DNS ASK bu####ngclothes.net
- DNS ASK ev####gclothes.net
- DNS ASK bu####nghealth.net
- DNS ASK ev####ghealth.net
- DNS ASK bu####ngdistant.net
- DNS ASK mi####eparate.net
- DNS ASK st###health.net
- DNS ASK ev####gdistant.net
- DNS ASK st####eparate.net
- DNS ASK re####health.net
- DNS ASK br####clothes.net
- DNS ASK re####separate.net
- DNS ASK br####health.net
- DNS ASK re####clothes.net
- DNS ASK pr####eseparate.net
- DNS ASK de####separate.net
- DNS ASK br####distant.net
- DNS ASK re####distant.net
- DNS ASK do####distant.net
- DNS ASK pr####distant.net
- DNS ASK do####clothes.net
- DNS ASK pr####clothes.net
- DNS ASK fe####separate.net
- DNS ASK fe####distant.net
- DNS ASK br####separate.net
- DNS ASK fe####health.net
- DNS ASK fe####clothes.net
- DNS ASK ev####gseparate.net
- DNS ASK pr####esmell.net
- DNS ASK de###esmell.net
- DNS ASK br####future.net
- DNS ASK re####future.net
- DNS ASK pr####eearly.net
- DNS ASK de####safety.net
- DNS ASK pr####efuture.net
- DNS ASK de###eearly.net
- DNS ASK pr####esafety.net
- DNS ASK do####future.net
- DNS ASK br###nsmell.net
- DNS ASK do####safety.net
- DNS ASK fe####future.net
- DNS ASK re###tsmell.net
- DNS ASK br####safety.net
- DNS ASK re####safety.net
- DNS ASK br###nearly.net
- DNS ASK re###tearly.net
- DNS ASK mo####nthealth.net
- DNS ASK ou####ehealth.net
- DNS ASK mo#####tseparate.net
- DNS ASK ou####eseparate.net
- DNS ASK mo####ntclothes.net
- DNS ASK ou####edistant.net
- DNS ASK bu#####gseparate.net
- DNS ASK ou####eclothes.net
- DNS ASK mo####ntdistant.net
- DNS ASK st###smell.net
- DNS ASK st####thearly.net
- DNS ASK de####future.net
- DNS ASK st####thsmell.net
- DNS ASK st###early.net
- DNS ASK st####thfuture.net
- DNS ASK st###future.net
- DNS ASK st####thsafety.net
- DNS ASK st###safety.net
- ClassName: 'Shell_TrayWnd' WindowName: ''