Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Parental Redirector Net.Tcp Update' = 'C:\otrxmjmz\bapmncg.exe'
- 'C:\otrxmjmz\dnilsdkyrh.exe' "c:\otrxmjmz\bapmncg.exe"
- 'C:\otrxmjmz\bapmncg.exe'
- 'C:\otrxmjmz\n3wd2p9qfzhofqvybdz.exe'
- C:\otrxmjmz\bapmncg.exe
- C:\otrxmjmz\dnilsdkyrh.exe
- C:\otrxmjmz\xliwtik
- %WINDIR%\otrxmjmz\eeu2qifkgg
- C:\otrxmjmz\eeu2qifkgg
- C:\otrxmjmz\n3wd2p9qfzhofqvybdz.exe
- C:\otrxmjmz\dnilsdkyrh.exe
- C:\otrxmjmz\bapmncg.exe
- C:\otrxmjmz\n3wd2p9qfzhofqvybdz.exe
- %WINDIR%\otrxmjmz\eeu2qifkgg
- 'mo#####president.net':80
- 'ra####president.net':80
- 'mo####gtrouble.net':80
- 'ra####caught.net':80
- 'hi####ystrong.net':80
- 'st####estrong.net':80
- 'mo####gcaught.net':80
- 'mi####caught.net':80
- 'tw####president.net':80
- 'mi####president.net':80
- 'tw####caught.net':80
- 'ra####trouble.net':80
- 'mo####gstrong.net':80
- 'ra####strong.net':80
- 'st####etrouble.net':80
- 'am####president.net':80
- 'we####rtrouble.net':80
- 'am####trouble.net':80
- 'we#####president.net':80
- 'cl###strong.net':80
- 'we####rcaught.net':80
- 'am####caught.net':80
- 'hi#####president.net':80
- 'st#####president.net':80
- 'hi####ytrouble.net':80
- 'st####ecaught.net':80
- 'we####rstrong.net':80
- 'am####strong.net':80
- 'hi####ycaught.net':80
- 'ch###strong.net':80
- 'pr####tcaught.net':80
- 'th###caught.net':80
- 'co####estrong.net':80
- 'ch####resident.net':80
- 'co####etrouble.net':80
- 'ch####rouble.net':80
- 'pr####tstrong.net':80
- 'th###strong.net':80
- 'cl###arrive.net':80
- 'th####rouble.net':80
- 'pr#####president.net':80
- 'th####resident.net':80
- 'pr####ttrouble.net':80
- 'co#####president.net':80
- 'al###caught.net':80
- 'of###caught.net':80
- 'al####resident.net':80
- 'mi####strong.net':80
- 'tw####trouble.net':80
- 'mi####trouble.net':80
- 'tw####strong.net':80
- 'of###strong.net':80
- 'co####ecaught.net':80
- 'ch###caught.net':80
- 'al###strong.net':80
- 'of####resident.net':80
- 'al####rouble.net':80
- 'of####rouble.net':80
- http://mo#####president.net/index.php?me########
- http://ra####president.net/index.php?me########
- http://mo####gtrouble.net/index.php?me########
- http://ra####caught.net/index.php?me########
- http://hi####ystrong.net/index.php?me########
- http://st####estrong.net/index.php?me########
- http://mo####gcaught.net/index.php?me########
- http://mi####caught.net/index.php?me########
- http://tw####president.net/index.php?me########
- http://mi####president.net/index.php?me########
- http://tw####caught.net/index.php?me########
- http://ra####trouble.net/index.php?me########
- http://mo####gstrong.net/index.php?me########
- http://ra####strong.net/index.php?me########
- http://st####etrouble.net/index.php?me########
- http://am####president.net/index.php?me########
- http://we####rtrouble.net/index.php?me########
- http://am####trouble.net/index.php?me########
- http://we#####president.net/index.php?me########
- http://cl###strong.net/index.php?me########
- http://we####rcaught.net/index.php?me########
- http://am####caught.net/index.php?me########
- http://hi#####president.net/index.php?me########
- http://st#####president.net/index.php?me########
- http://hi####ytrouble.net/index.php?me########
- http://st####ecaught.net/index.php?me########
- http://we####rstrong.net/index.php?me########
- http://am####strong.net/index.php?me########
- http://hi####ycaught.net/index.php?me########
- http://ch###strong.net/index.php?me########
- http://pr####tcaught.net/index.php?me########
- http://th###caught.net/index.php?me########
- http://co####estrong.net/index.php?me########
- http://ch####resident.net/index.php?me########
- http://co####etrouble.net/index.php?me########
- http://ch####rouble.net/index.php?me########
- http://pr####tstrong.net/index.php?me########
- http://th###strong.net/index.php?me########
- http://cl###arrive.net/index.php?me########
- http://th####rouble.net/index.php?me########
- http://pr#####president.net/index.php?me########
- http://th####resident.net/index.php?me########
- http://pr####ttrouble.net/index.php?me########
- http://co#####president.net/index.php?me########
- http://al###caught.net/index.php?me########
- http://of###caught.net/index.php?me########
- http://al####resident.net/index.php?me########
- http://mi####strong.net/index.php?me########
- http://tw####trouble.net/index.php?me########
- http://mi####trouble.net/index.php?me########
- http://tw####strong.net/index.php?me########
- http://of###strong.net/index.php?me########
- http://co####ecaught.net/index.php?me########
- http://ch###caught.net/index.php?me########
- http://al###strong.net/index.php?me########
- http://of####resident.net/index.php?me########
- http://al####rouble.net/index.php?me########
- http://of####rouble.net/index.php?me########
- DNS ASK mo#####president.net
- DNS ASK ra####president.net
- DNS ASK mo####gtrouble.net
- DNS ASK ra####caught.net
- DNS ASK hi####ystrong.net
- DNS ASK st####estrong.net
- DNS ASK mo####gcaught.net
- DNS ASK mi####caught.net
- DNS ASK tw####president.net
- DNS ASK mi####president.net
- DNS ASK tw####caught.net
- DNS ASK ra####trouble.net
- DNS ASK mo####gstrong.net
- DNS ASK ra####strong.net
- DNS ASK st####etrouble.net
- DNS ASK am####president.net
- DNS ASK we####rtrouble.net
- DNS ASK am####trouble.net
- DNS ASK we#####president.net
- DNS ASK cl###strong.net
- DNS ASK we####rcaught.net
- DNS ASK am####caught.net
- DNS ASK hi#####president.net
- DNS ASK st#####president.net
- DNS ASK hi####ytrouble.net
- DNS ASK st####ecaught.net
- DNS ASK we####rstrong.net
- DNS ASK am####strong.net
- DNS ASK hi####ycaught.net
- DNS ASK ch###strong.net
- DNS ASK pr####tcaught.net
- DNS ASK th###caught.net
- DNS ASK co####estrong.net
- DNS ASK ch####resident.net
- DNS ASK co####etrouble.net
- DNS ASK ch####rouble.net
- DNS ASK pr####tstrong.net
- DNS ASK th###strong.net
- DNS ASK cl###arrive.net
- DNS ASK th####rouble.net
- DNS ASK pr#####president.net
- DNS ASK th####resident.net
- DNS ASK pr####ttrouble.net
- DNS ASK co#####president.net
- DNS ASK al###caught.net
- DNS ASK of###caught.net
- DNS ASK al####resident.net
- DNS ASK mi####strong.net
- DNS ASK tw####trouble.net
- DNS ASK mi####trouble.net
- DNS ASK tw####strong.net
- DNS ASK of###strong.net
- DNS ASK co####ecaught.net
- DNS ASK ch###caught.net
- DNS ASK al###strong.net
- DNS ASK of####resident.net
- DNS ASK al####rouble.net
- DNS ASK of####rouble.net
- ClassName: 'Shell_TrayWnd' WindowName: ''