Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'AutoConnect Tunneling Media Assistant Resolution' = 'C:\sjfyugjwxocro\obdiftie.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Remote Themes NGEN Config] 'Start' = '00000002'
- 'C:\sjfyugjwxocro\sdsddfy.exe' "c:\sjfyugjwxocro\obdiftie.exe"
- 'C:\sjfyugjwxocro\obdiftie.exe'
- 'C:\sjfyugjwxocro\bntlg2mhws3mbugspnv.exe'
- C:\sjfyugjwxocro\obdiftie.exe
- C:\sjfyugjwxocro\sdsddfy.exe
- C:\sjfyugjwxocro\bntlg2mhws3mbugspnv.exe
- %WINDIR%\sjfyugjwxocro\atkcs9m
- C:\sjfyugjwxocro\atkcs9m
- C:\sjfyugjwxocro\sdsddfy.exe
- C:\sjfyugjwxocro\obdiftie.exe
- C:\sjfyugjwxocro\bntlg2mhws3mbugspnv.exe
- %WINDIR%\sjfyugjwxocro\atkcs9m
- 'de###eproud.net':80
- 'pr####eproud.net':80
- 'de####complete.net':80
- 'pr####ecomplete.net':80
- 'de####welcome.net':80
- 'pr####ewelcome.net':80
- 'de####around.net':80
- 'pr####earound.net':80
- 'st###proud.net':80
- 'st####thproud.net':80
- 'st####omplete.net':80
- 'st#####hcomplete.net':80
- 'st####elcome.net':80
- 'st####thwelcome.net':80
- 'st###around.net':80
- 'st####tharound.net':80
- 're####complete.net':80
- 'fe###wproud.net':80
- 'do####around.net':80
- 'fe####complete.net':80
- 'do###eproud.net':80
- 'fe####welcome.net':80
- 'pr####complete.net':80
- 'fe####around.net':80
- 'do####welcome.net':80
- 'br###nproud.net':80
- 're####around.net':80
- 'br####complete.net':80
- 're###tproud.net':80
- 'br####welcome.net':80
- 'do####complete.net':80
- 'br####around.net':80
- 're####welcome.net':80
- http://de###eproud.net/index.php
- http://pr####eproud.net/index.php
- http://de####complete.net/index.php
- http://pr####ecomplete.net/index.php
- http://de####welcome.net/index.php
- http://pr####ewelcome.net/index.php
- http://de####around.net/index.php
- http://pr####earound.net/index.php
- http://st###proud.net/index.php
- http://st####thproud.net/index.php
- http://st####omplete.net/index.php
- http://st#####hcomplete.net/index.php
- http://st####elcome.net/index.php
- http://st####thwelcome.net/index.php
- http://st###around.net/index.php
- http://st####tharound.net/index.php
- http://re####complete.net/index.php
- http://fe###wproud.net/index.php
- http://do####around.net/index.php
- http://fe####complete.net/index.php
- http://do###eproud.net/index.php
- http://fe####welcome.net/index.php
- http://pr####complete.net/index.php
- http://fe####around.net/index.php
- http://do####welcome.net/index.php
- http://br###nproud.net/index.php
- http://re####around.net/index.php
- http://br####complete.net/index.php
- http://re###tproud.net/index.php
- http://br####welcome.net/index.php
- http://do####complete.net/index.php
- http://br####around.net/index.php
- http://re####welcome.net/index.php
- DNS ASK de###eproud.net
- DNS ASK pr####eproud.net
- DNS ASK de####complete.net
- DNS ASK pr####ecomplete.net
- DNS ASK de####welcome.net
- DNS ASK pr####ewelcome.net
- DNS ASK de####around.net
- DNS ASK pr####earound.net
- DNS ASK st####thwelcome.net
- DNS ASK st#####hcomplete.net
- DNS ASK st###proud.net
- DNS ASK mo####ntnature.net
- DNS ASK st####omplete.net
- DNS ASK st####tharound.net
- DNS ASK st####elcome.net
- DNS ASK st####thproud.net
- DNS ASK st###around.net
- DNS ASK fe###wproud.net
- DNS ASK do####around.net
- DNS ASK fe####complete.net
- DNS ASK do###eproud.net
- DNS ASK fe####welcome.net
- DNS ASK pr####complete.net
- DNS ASK fe####around.net
- DNS ASK do####welcome.net
- DNS ASK do####complete.net
- DNS ASK re###tproud.net
- DNS ASK br###nproud.net
- DNS ASK re####complete.net
- DNS ASK br####complete.net
- DNS ASK re####welcome.net
- DNS ASK br####welcome.net
- DNS ASK re####around.net
- DNS ASK br####around.net
- ClassName: 'Shell_TrayWnd' WindowName: ''