Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Counter Browser Interactive' = '<SYSTEM32>\vmoorbmjg.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\KtmRm DCOM Removal Tools Client] 'ImagePath' = '<SYSTEM32>\vmoorbmjg.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\KtmRm DCOM Removal Tools Client] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\ccxorlyavv.exe' "<SYSTEM32>\vmoorbmjg.exe"
- '%WINDIR%\Temp\e8owb7w02iw4z0.exe' -r 45791 tcp
- '%TEMP%\e8owb7w02er9z0agcpmh.exe'
- '<SYSTEM32>\vmoorbmjg.exe'
- <SYSTEM32>\zcrdjpsoujqwhfn\run
- <SYSTEM32>\zcrdjpsoujqwhfn\rng
- %WINDIR%\Temp\e8owb7w02iw4z0.exe
- <SYSTEM32>\zcrdjpsoujqwhfn\cfg
- <SYSTEM32>\ccxorlyavv.exe
- %TEMP%\e8owb7w02er9z0agcpmh.exe
- <SYSTEM32>\zcrdjpsoujqwhfn\tst
- <SYSTEM32>\vmoorbmjg.exe
- <SYSTEM32>\zcrdjpsoujqwhfn\etc
- <SYSTEM32>\ccxorlyavv.exe
- <SYSTEM32>\vmoorbmjg.exe
- %WINDIR%\Temp\e8owb7w02iw4z0.exe
- <DRIVERS>\etc\hosts
- %TEMP%\e8owb7w02er9z0agcpmh.exe
- 'vi###aise.net':80
- 'lr###reach.net':80
- 'vi###each.net':80
- 'lr###croud.net':80
- 'vi###roud.net':80
- 'lr###raise.net':80
- 'fi###roud.net':80
- 'pl###raise.net':80
- 'fi###aise.net':80
- 'pl###price.net':80
- 'fi###rice.net':80
- 'pl###croud.net':80
- 'yo###rice.net':80
- 'tr###croud.net':80
- 'yo###roud.net':80
- 'wa###orn.net':80
- 'ta###orn.net':80
- 'tr###price.net':80
- 'yo###each.net':80
- 'lr###price.net':80
- 'vi###rice.net':80
- 'tr###raise.net':80
- 'yo###aise.net':80
- 'tr###reach.net':80
- 'pl###reach.net':80
- 'to###each.net':80
- 'fa###each.net':80
- 'we###rice.net':80
- 'fa###roud.net':80
- 'to###aise.net':80
- 'fa###aise.net':80
- 'we###aise.net':80
- 've###aise.net':80
- 'we###each.net':80
- 've###rice.net':80
- 'we###roud.net':80
- 've###roud.net':80
- 'se###croud.net':80
- 'le###croud.net':80
- 'se###raise.net':80
- 'fi###each.net':80
- 'se###price.net':80
- 'le###price.net':80
- 'to###rice.net':80
- 'fa###rice.net':80
- 'to###roud.net':80
- 'le###raise.net':80
- 'se###reach.net':80
- 'le###reach.net':80
- 'se###august.net':80
- 'le###august.net':80
- 'se###born.net':80
- 'ri###nstorm.net':80
- 'se###paid.net':80
- 'le###paid.net':80
- 'to###aid.net':80
- 'fa###aid.net':80
- 'to###ugust.net':80
- 'le###born.net':80
- 'to###loth.net':80
- 'fa###loth.net':80
- 'cr#####onaraminta.net':80
- 'le###form.net':80
- 'mo###ugust.net':80
- 'ef###tbuilt.net':80
- 'th###while.net':80
- 'jo####ymeasure.net':80
- 'pr####tbottom.net':80
- 'ca####nbring.net':80
- 'al###being.net':80
- 'mi###hown.net':80
- 'ab###ell.net':80
- 'mo###olor.net':80
- 'fa###ugust.net':80
- 'mu###ugust.net':80
- 'pi###born.net':80
- 'mu###orn.net':80
- 'pi###paid.net':80
- 'mu###aid.net':80
- 'pi###august.net':80
- 'ta###aid.net':80
- 'wa###ugust.net':80
- 'ta###ugust.net':80
- 'wa###loth.net':80
- 'ta###loth.net':80
- 'wa###aid.net':80
- 've###loth.net':80
- 'we###aid.net':80
- 've###aid.net':80
- 'to###orn.net':80
- 'fa###orn.net':80
- 'we###loth.net':80
- 've###orn.net':80
- 'pi###cloth.net':80
- 'mu###loth.net':80
- 'we###ugust.net':80
- 've###ugust.net':80
- 'we###orn.net':80
- http://vi###aise.net/index.php
- http://lr###reach.net/index.php
- http://vi###each.net/index.php
- http://lr###croud.net/index.php
- http://vi###roud.net/index.php
- http://lr###raise.net/index.php
- http://fi###roud.net/index.php
- http://pl###raise.net/index.php
- http://fi###aise.net/index.php
- http://pl###price.net/index.php
- http://fi###rice.net/index.php
- http://pl###croud.net/index.php
- http://yo###rice.net/index.php
- http://tr###croud.net/index.php
- http://yo###roud.net/index.php
- http://wa###orn.net/index.php
- http://ta###orn.net/index.php
- http://tr###price.net/index.php
- http://yo###each.net/index.php
- http://lr###price.net/index.php
- http://vi###rice.net/index.php
- http://tr###raise.net/index.php
- http://yo###aise.net/index.php
- http://tr###reach.net/index.php
- http://pl###reach.net/index.php
- http://to###each.net/index.php
- http://fa###each.net/index.php
- http://we###rice.net/index.php
- http://fa###roud.net/index.php
- http://to###aise.net/index.php
- http://fa###aise.net/index.php
- http://we###aise.net/index.php
- http://ve###aise.net/index.php
- http://we###each.net/index.php
- http://ve###rice.net/index.php
- http://we###roud.net/index.php
- http://ve###roud.net/index.php
- http://se###croud.net/index.php
- http://le###croud.net/index.php
- http://se###raise.net/index.php
- http://fi###each.net/index.php
- http://se###price.net/index.php
- http://le###price.net/index.php
- http://to###rice.net/index.php
- http://fa###rice.net/index.php
- http://to###roud.net/index.php
- http://le###raise.net/index.php
- http://se###reach.net/index.php
- http://le###reach.net/index.php
- http://se###august.net/index.php
- http://le###august.net/index.php
- http://se###born.net/index.php
- http://ri###nstorm.net/index.php
- http://se###paid.net/index.php
- http://le###paid.net/index.php
- http://to###aid.net/index.php
- http://fa###aid.net/index.php
- http://to###ugust.net/index.php
- http://le###born.net/index.php
- http://to###loth.net/index.php
- http://fa###loth.net/index.php
- http://cr#####onaraminta.net/index.php
- http://le###form.net/index.php
- http://mo###ugust.net/index.php
- http://ef###tbuilt.net/index.php
- http://th###while.net/index.php
- http://jo####ymeasure.net/index.php
- http://pr####tbottom.net/index.php
- http://ca####nbring.net/index.php
- http://al###being.net/index.php
- http://mi###hown.net/index.php
- http://ab###ell.net/index.php
- http://mo###olor.net/index.php
- http://fa###ugust.net/index.php
- http://mu###ugust.net/index.php
- http://pi###born.net/index.php
- http://mu###orn.net/index.php
- http://pi###paid.net/index.php
- http://mu###aid.net/index.php
- http://pi###august.net/index.php
- http://ta###aid.net/index.php
- http://wa###ugust.net/index.php
- http://ta###ugust.net/index.php
- http://wa###loth.net/index.php
- http://ta###loth.net/index.php
- http://wa###aid.net/index.php
- http://ve###loth.net/index.php
- http://we###aid.net/index.php
- http://ve###aid.net/index.php
- http://to###orn.net/index.php
- http://fa###orn.net/index.php
- http://we###loth.net/index.php
- http://ve###orn.net/index.php
- http://pi###cloth.net/index.php
- http://mu###loth.net/index.php
- http://we###ugust.net/index.php
- http://ve###ugust.net/index.php
- http://we###orn.net/index.php
- DNS ASK vi###aise.net
- DNS ASK lr###reach.net
- DNS ASK vi###each.net
- DNS ASK lr###croud.net
- DNS ASK vi###roud.net
- DNS ASK lr###raise.net
- DNS ASK fi###roud.net
- DNS ASK pl###raise.net
- DNS ASK fi###aise.net
- DNS ASK pl###price.net
- DNS ASK fi###rice.net
- DNS ASK pl###croud.net
- DNS ASK yo###rice.net
- DNS ASK tr###croud.net
- DNS ASK yo###roud.net
- DNS ASK wa###orn.net
- DNS ASK ta###orn.net
- DNS ASK tr###price.net
- DNS ASK yo###each.net
- DNS ASK lr###price.net
- DNS ASK vi###rice.net
- DNS ASK tr###raise.net
- DNS ASK yo###aise.net
- DNS ASK tr###reach.net
- DNS ASK pl###reach.net
- DNS ASK to###each.net
- DNS ASK fa###each.net
- DNS ASK we###rice.net
- DNS ASK fa###roud.net
- DNS ASK to###aise.net
- DNS ASK fa###aise.net
- DNS ASK we###aise.net
- DNS ASK ve###aise.net
- DNS ASK we###each.net
- DNS ASK ve###rice.net
- DNS ASK we###roud.net
- DNS ASK ve###roud.net
- DNS ASK se###croud.net
- DNS ASK le###croud.net
- DNS ASK se###raise.net
- DNS ASK fi###each.net
- DNS ASK se###price.net
- DNS ASK le###price.net
- DNS ASK to###rice.net
- DNS ASK fa###rice.net
- DNS ASK to###roud.net
- DNS ASK le###raise.net
- DNS ASK se###reach.net
- DNS ASK le###reach.net
- DNS ASK ta###ugust.net
- DNS ASK se###august.net
- DNS ASK le###august.net
- DNS ASK se###born.net
- DNS ASK ri###nstorm.net
- DNS ASK se###paid.net
- DNS ASK le###paid.net
- DNS ASK to###aid.net
- DNS ASK fa###aid.net
- DNS ASK to###ugust.net
- DNS ASK le###born.net
- DNS ASK to###loth.net
- DNS ASK fa###loth.net
- DNS ASK cr#####onaraminta.net
- DNS ASK le###form.net
- DNS ASK mo###ugust.net
- DNS ASK ef###tbuilt.net
- DNS ASK th###while.net
- DNS ASK jo####ymeasure.net
- DNS ASK pr####tbottom.net
- DNS ASK ca####nbring.net
- DNS ASK al###being.net
- DNS ASK mi###hown.net
- DNS ASK ab###ell.net
- DNS ASK mo###olor.net
- DNS ASK pi###august.net
- DNS ASK mu###ugust.net
- DNS ASK pi###born.net
- DNS ASK mu###loth.net
- DNS ASK pi###paid.net
- DNS ASK mu###aid.net
- DNS ASK wa###aid.net
- DNS ASK ta###aid.net
- DNS ASK wa###ugust.net
- DNS ASK mu###orn.net
- DNS ASK wa###loth.net
- DNS ASK ta###loth.net
- DNS ASK we###loth.net
- DNS ASK ve###loth.net
- DNS ASK we###aid.net
- DNS ASK fa###ugust.net
- DNS ASK to###orn.net
- DNS ASK fa###orn.net
- DNS ASK we###orn.net
- DNS ASK ve###orn.net
- DNS ASK pi###cloth.net
- DNS ASK ve###aid.net
- DNS ASK we###ugust.net
- DNS ASK ve###ugust.net
- '23#.#55.255.250':1900