Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Protected Color Connect Office' = 'C:\zeyhvrppg\ascflwug.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Bluetooth Logon DHCP Font Registrar DCOM] 'Start' = '00000002'
- 'C:\zeyhvrppg\qxpajxjz.exe' "c:\zeyhvrppg\ascflwug.exe"
- 'C:\zeyhvrppg\ascflwug.exe'
- 'C:\zeyhvrppg\kc2v2xehtaxm2wgcyk.exe'
- C:\zeyhvrppg\ascflwug.exe
- C:\zeyhvrppg\qxpajxjz.exe
- C:\zeyhvrppg\dnbemxut
- %WINDIR%\zeyhvrppg\jkkitlttpz
- C:\zeyhvrppg\jkkitlttpz
- C:\zeyhvrppg\kc2v2xehtaxm2wgcyk.exe
- C:\zeyhvrppg\qxpajxjz.exe
- C:\zeyhvrppg\ascflwug.exe
- C:\zeyhvrppg\kc2v2xehtaxm2wgcyk.exe
- %WINDIR%\zeyhvrppg\jkkitlttpz
- 'ex######ceunderstand.net':80
- 'fr####nderstand.net':80
- 'ex####encebroad.net':80
- 'fr###broad.net':80
- 'ma####almayor.net':80
- 'se####lmayor.net':80
- 'ma####albattle.net':80
- 'se####lbattle.net':80
- 'fr###behind.net':80
- 'ge####manbroad.net':80
- 'al#####understand.net':80
- 'ge####manbehind.net':80
- 'al####ybroad.net':80
- 'fr###butter.net':80
- 'ex#####ncebehind.net':80
- 'ge#####anunderstand.net':80
- 'ex#####ncebutter.net':80
- 'sw###heart.net':80
- 'le###battle.net':80
- 'sw####erfect.net':80
- 'pr####lyheart.net':80
- 'fi###hmayor.net':80
- 'le####erfect.net':80
- 'fi####battle.net':80
- 'le###mayor.net':80
- 'pr####lyperfect.net':80
- 'ma####alheart.net':80
- 'se####lheart.net':80
- 'ma####alperfect.net':80
- 'se####lperfect.net':80
- 'pr####lymayor.net':80
- 'sw###mayor.net':80
- 'pr####lybattle.net':80
- 'sw###battle.net':80
- http://ex######ceunderstand.net/index.php?me########
- http://fr####nderstand.net/index.php?me########
- http://ex####encebroad.net/index.php?me########
- http://fr###broad.net/index.php?me########
- http://ma####almayor.net/index.php?me########
- http://se####lmayor.net/index.php?me########
- http://ma####albattle.net/index.php?me########
- http://se####lbattle.net/index.php?me########
- http://fr###behind.net/index.php?me########
- http://ge####manbroad.net/index.php?me########
- http://al#####understand.net/index.php?me########
- http://ge####manbehind.net/index.php?me########
- http://al####ybroad.net/index.php?me########
- http://fr###butter.net/index.php?me########
- http://ex#####ncebehind.net/index.php?me########
- http://ge#####anunderstand.net/index.php?me########
- http://ex#####ncebutter.net/index.php?me########
- http://sw###heart.net/index.php?me########
- http://le###battle.net/index.php?me########
- http://sw####erfect.net/index.php?me########
- http://pr####lyheart.net/index.php?me########
- http://fi###hmayor.net/index.php?me########
- http://le####erfect.net/index.php?me########
- http://fi####battle.net/index.php?me########
- http://le###mayor.net/index.php?me########
- http://pr####lyperfect.net/index.php?me########
- http://ma####alheart.net/index.php?me########
- http://se####lheart.net/index.php?me########
- http://ma####alperfect.net/index.php?me########
- http://se####lperfect.net/index.php?me########
- http://pr####lymayor.net/index.php?me########
- http://sw###mayor.net/index.php?me########
- http://pr####lybattle.net/index.php?me########
- http://sw###battle.net/index.php?me########
- DNS ASK fr###broad.net
- DNS ASK ex######ceunderstand.net
- DNS ASK fr###behind.net
- DNS ASK ex####encebroad.net
- DNS ASK se####lbattle.net
- DNS ASK ma####almayor.net
- DNS ASK fr####nderstand.net
- DNS ASK ma####albattle.net
- DNS ASK ex#####ncebehind.net
- DNS ASK al####ybroad.net
- DNS ASK ge####manbroad.net
- DNS ASK al####ybehind.net
- DNS ASK ge####manbehind.net
- DNS ASK ex#####ncebutter.net
- DNS ASK fr###butter.net
- DNS ASK al#####understand.net
- DNS ASK ge#####anunderstand.net
- DNS ASK se####lmayor.net
- DNS ASK sw###heart.net
- DNS ASK le###battle.net
- DNS ASK sw####erfect.net
- DNS ASK pr####lyheart.net
- DNS ASK fi###hmayor.net
- DNS ASK le####erfect.net
- DNS ASK fi####battle.net
- DNS ASK le###mayor.net
- DNS ASK pr####lyperfect.net
- DNS ASK ma####alheart.net
- DNS ASK se####lheart.net
- DNS ASK ma####alperfect.net
- DNS ASK se####lperfect.net
- DNS ASK pr####lymayor.net
- DNS ASK sw###mayor.net
- DNS ASK pr####lybattle.net
- DNS ASK sw###battle.net
- ClassName: 'Shell_TrayWnd' WindowName: ''