Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Drive SPP Telephony Netlogon Panel' = 'C:\gyozyuluywztebv\dkfviccdptgm.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Firewall Mapper Fax Tools Error Builder] 'Start' = '00000002'
- 'C:\gyozyuluywztebv\zsyuowqeq.exe' "c:\gyozyuluywztebv\dkfviccdptgm.exe"
- 'C:\gyozyuluywztebv\dkfviccdptgm.exe'
- 'C:\gyozyuluywztebv\gy31diijvpxvxjjrq.exe'
- C:\gyozyuluywztebv\dkfviccdptgm.exe
- C:\gyozyuluywztebv\zsyuowqeq.exe
- C:\gyozyuluywztebv\viesdlbfzdf
- %WINDIR%\gyozyuluywztebv\wenxpjn2oan
- C:\gyozyuluywztebv\wenxpjn2oan
- C:\gyozyuluywztebv\gy31diijvpxvxjjrq.exe
- C:\gyozyuluywztebv\zsyuowqeq.exe
- C:\gyozyuluywztebv\dkfviccdptgm.exe
- C:\gyozyuluywztebv\gy31diijvpxvxjjrq.exe
- %WINDIR%\gyozyuluywztebv\wenxpjn2oan
- 'be####branch.net':80
- 'tr####uarter.net':80
- 'be####believe.net':80
- 'ga####branch.net':80
- 'st####receive.net':80
- 'tr####elieve.net':80
- 'st####quarter.net':80
- 'tr####eceive.net':80
- 'fl###branch.net':80
- 'ga####quarter.net':80
- 'fl####elieve.net':80
- 'br###branch.net':80
- 'be####receive.net':80
- 'ga####believe.net':80
- 'be####quarter.net':80
- 'ga####receive.net':80
- 'st####believe.net':80
- 'ca####nquarter.net':80
- 'la####uarter.net':80
- 'el####icbranch.net':80
- 're####branch.net':80
- 'ca####nbelieve.net':80
- 'la####elieve.net':80
- 'ca####nreceive.net':80
- 'la####eceive.net':80
- 'el####icquarter.net':80
- 're####quarter.net':80
- 'tr###branch.net':80
- 'st####branch.net':80
- 'el####icbelieve.net':80
- 're####believe.net':80
- 'el####icreceive.net':80
- 're####receive.net':80
- http://be####branch.net/index.php?me########
- http://tr####uarter.net/index.php?me########
- http://be####believe.net/index.php?me########
- http://ga####branch.net/index.php?me########
- http://st####receive.net/index.php?me########
- http://tr####elieve.net/index.php?me########
- http://st####quarter.net/index.php?me########
- http://tr####eceive.net/index.php?me########
- http://fl###branch.net/index.php?me########
- http://ga####quarter.net/index.php?me########
- http://fl####elieve.net/index.php?me########
- http://br###branch.net/index.php?me########
- http://be####receive.net/index.php?me########
- http://ga####believe.net/index.php?me########
- http://be####quarter.net/index.php?me########
- http://ga####receive.net/index.php?me########
- http://st####believe.net/index.php?me########
- http://ca####nquarter.net/index.php?me########
- http://la####uarter.net/index.php?me########
- http://el####icbranch.net/index.php?me########
- http://re####branch.net/index.php?me########
- http://ca####nbelieve.net/index.php?me########
- http://la####elieve.net/index.php?me########
- http://ca####nreceive.net/index.php?me########
- http://la####eceive.net/index.php?me########
- http://el####icquarter.net/index.php?me########
- http://re####quarter.net/index.php?me########
- http://tr###branch.net/index.php?me########
- http://st####branch.net/index.php?me########
- http://el####icbelieve.net/index.php?me########
- http://re####believe.net/index.php?me########
- http://el####icreceive.net/index.php?me########
- http://re####receive.net/index.php?me########
- DNS ASK be####branch.net
- DNS ASK tr####uarter.net
- DNS ASK be####believe.net
- DNS ASK ga####branch.net
- DNS ASK st####receive.net
- DNS ASK tr####elieve.net
- DNS ASK st####quarter.net
- DNS ASK tr####eceive.net
- DNS ASK ga####believe.net
- DNS ASK br###branch.net
- DNS ASK fl###branch.net
- DNS ASK br####elieve.net
- DNS ASK fl####elieve.net
- DNS ASK ga####receive.net
- DNS ASK be####receive.net
- DNS ASK ga####quarter.net
- DNS ASK be####quarter.net
- DNS ASK ca####nquarter.net
- DNS ASK la####uarter.net
- DNS ASK el####icbranch.net
- DNS ASK re####branch.net
- DNS ASK ca####nbelieve.net
- DNS ASK la####elieve.net
- DNS ASK ca####nreceive.net
- DNS ASK la####eceive.net
- DNS ASK re####believe.net
- DNS ASK st####branch.net
- DNS ASK el####icquarter.net
- DNS ASK st####believe.net
- DNS ASK tr###branch.net
- DNS ASK re####receive.net
- DNS ASK el####icbelieve.net
- DNS ASK re####quarter.net
- DNS ASK el####icreceive.net
- ClassName: 'Shell_TrayWnd' WindowName: ''