Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'vudazixisrud' = '%HOMEPATH%\vudazixisrud.exe'
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\Preferred
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-2052111302-484763869-725345543-1003\ec702f375e1b12d218f67ab9ef19ca23_23ef5514-3059-436f-a4a7-4cefaab20eb1
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\d66bbd8e-fdda-4d55-86a2-228d567c9b70
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\ee5be91c-eea7-4383-b247-4e367dc733ad
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\egao[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\YPORKZYZ\topex[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\buzzkillmedia[1].htm
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\graintrain[1].htm
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\07486f06-2bea-46ee-9458-c76bd644de0f
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\ef778e65-ad6a-4c6c-9ff1-40bfbff769ba
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\17113508-fda6-40d4-92a6-267760b71f9b
- %HOMEPATH%\vudazixisrud.exe
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\f97d5e56-9d92-407d-b450-f45a4c073f08
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\4c094e7e-a1ca-414b-8f8a-5f9acf39c7cb
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\4c337305-92b5-4adc-8ae5-7bec81d44ce9
- %APPDATA%\Microsoft\Protect\S-1-5-21-2052111302-484763869-725345543-1003\40b9e84c-67ca-44c1-9f09-19cb91ee96ba
- 'gr###train.coop':80
- 'eg##.net':80
- 'to##x.ro':80
- 'sm##.live.com':25
- '67.##5.160.76':25
- 'bu####llmedia.com':80
- to##x.ro/
- eg##.net/
- DNS ASK my####center.com
- DNS ASK so#####rganizing.com
- DNS ASK au####ansurfing.at
- DNS ASK sh###yspizza.ph
- DNS ASK ga###marine.com
- DNS ASK le###ridica.com
- DNS ASK ju####nnect.co.za
- DNS ASK ic###ain.com
- DNS ASK bu####ss-edge.com
- DNS ASK ac###nvestor.ca
- DNS ASK ch####supplies.net
- DNS ASK ga######onlinemagazine.com
- DNS ASK na###sklep.pl
- DNS ASK ix###ctor.com
- DNS ASK sm##.#ompuserve.com
- DNS ASK re##soft.ru
- DNS ASK ce####kalip.com.tr
- DNS ASK ap###farm.org
- DNS ASK et###les.com
- DNS ASK xn########h8abch1g1b0ap6a9vxa.com
- DNS ASK op###er.com.au
- DNS ASK cs##c.org
- DNS ASK ct###rocess.org
- DNS ASK im###.com.pl
- DNS ASK sa###david.com
- DNS ASK do####ntasies.com
- DNS ASK ca###choice.org
- DNS ASK ko###-sa.com
- DNS ASK sa####connection.ca
- DNS ASK xi###group.com
- DNS ASK te###ra.co.jp
- DNS ASK th#####ldsongroup.com
- DNS ASK ge###r.gen.tr
- DNS ASK to###ipe.com
- DNS ASK os####-school.com
- DNS ASK fr#####entauction.com
- DNS ASK au####direkt.net
- DNS ASK th###tospas.com
- DNS ASK au#####ica-travel.com
- DNS ASK or####networks.net
- DNS ASK es####-hotelier.com
- DNS ASK en####odrigo.com.br
- DNS ASK ho###hd.com.br
- DNS ASK sh###zil.com
- DNS ASK up###on89.com
- DNS ASK pa###enna.com
- DNS ASK ar###2aa.org
- DNS ASK aj##.net
- DNS ASK ul##dsu.org
- DNS ASK ur##asu.net
- DNS ASK wi#####emarketing.com
- DNS ASK pr######nsolutionsky.com
- DNS ASK ac##l.lt
- DNS ASK ms##ys.com
- DNS ASK ru###eberg.com
- DNS ASK ti###urkey.com
- DNS ASK ma#####siecologia.com
- DNS ASK om##p.co.jp
- DNS ASK ma####grimes.co.uk
- DNS ASK bu####llmedia.com
- DNS ASK gr###train.coop
- DNS ASK sm##.###global.yahoo.com
- DNS ASK sm##.live.com
- DNS ASK sm##.#ail.yahoo.com
- DNS ASK de####scueusa.com
- DNS ASK th###rgery.com
- DNS ASK lo###tic.com
- DNS ASK bi#####sbeefjerky.com
- DNS ASK eg##.net
- DNS ASK to##x.ro
- DNS ASK sz###tufi.com
- DNS ASK gu###man.com.br
- DNS ASK ey###oup.com
- DNS ASK ph###clubs.com
- DNS ASK sg###nting.ca
- DNS ASK ac#####oambiente.com
- DNS ASK tv##ra.net
- DNS ASK di##d.com
- DNS ASK ma##.#irmail.net
- DNS ASK ko###hi-hp.com
- DNS ASK pe####sion.co.in
- DNS ASK te##ole.com
- DNS ASK be#####rebusiness.org
- DNS ASK ka####okuren.com
- DNS ASK cg###ngland.com
- DNS ASK sm##.#irectcon.net
- DNS ASK fr#####high.school.nz
- DNS ASK tr###alau.com
- DNS ASK me###orti.com
- DNS ASK ko######ireprotection.com
- DNS ASK ni####ictionary.com
- DNS ASK ma####.us2.mcsv.net
- DNS ASK be###reks.com
- ClassName: 'Indicator' WindowName: '(null)'