Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Discovery Support DLL Tablet' = '%APPDATA%\fmkwvzsezjpk\jarkkglhnxg.exe'
- '%APPDATA%\fmkwvzsezjpk\ivvlwouvxnl.exe' "%APPDATA%\fmkwvzsezjpk\jarkkglhnxg.exe"
- '%APPDATA%\fmkwvzsezjpk\jarkkglhnxg.exe'
- %APPDATA%\fmkwvzsezjpk\jarkkglhnxg.kmm8
- %APPDATA%\fmkwvzsezjpk\ivvlwouvxnl.exe
- %APPDATA%\fmkwvzsezjpk\jarkkglhnxg.exe
- %APPDATA%\fmkwvzsezjpk\ivvlwouvxnl.exe
- %APPDATA%\fmkwvzsezjpk\jarkkglhnxg.exe
- 'va####sdaughter.net':80
- 're####people.net':80
- 'de####nation.net':80
- 're####daughter.net':80
- 'va####sbrown.net':80
- 're###nready.net':80
- 'va####speople.net':80
- 're###nbrown.net':80
- 'fo####dnation.net':80
- 'fo#####condition.net':80
- 'de####condition.net':80
- 'gl###nation.net':80
- 'an####nation.net':80
- 'fo####dsoldier.net':80
- 'de####soldier.net':80
- 'fo####dplease.net':80
- 'de####please.net':80
- 'he####people.net':80
- 'le####people.net':80
- 'he####daughter.net':80
- 'le####daughter.net':80
- 'he###nready.net':80
- 'le###rready.net':80
- 'he###nbrown.net':80
- 'le###rbrown.net':80
- 'he###ready.net':80
- 'he####aughter.net':80
- 'ge####people.net':80
- 'va####sready.net':80
- 'ge####daughter.net':80
- 'he###brown.net':80
- 'ge###eready.net':80
- 'he###people.net':80
- 'ge###ebrown.net':80
- va####sdaughter.net/forum/search.php?em#####################################
- re####people.net/forum/search.php?em#####################################
- de####nation.net/forum/search.php?em#####################################
- re####daughter.net/forum/search.php?em#####################################
- va####sbrown.net/forum/search.php?em#####################################
- re###nready.net/forum/search.php?em#####################################
- va####speople.net/forum/search.php?em#####################################
- re###nbrown.net/forum/search.php?em#####################################
- fo####dnation.net/forum/search.php?em#####################################
- fo#####condition.net/forum/search.php?em#####################################
- de####condition.net/forum/search.php?em#####################################
- gl###nation.net/forum/search.php?em#####################################
- an####nation.net/forum/search.php?em#####################################
- fo####dsoldier.net/forum/search.php?em#####################################
- de####soldier.net/forum/search.php?em#####################################
- fo####dplease.net/forum/search.php?em#####################################
- de####please.net/forum/search.php?em#####################################
- he####people.net/forum/search.php?em#####################################
- le####people.net/forum/search.php?em#####################################
- he####daughter.net/forum/search.php?em#####################################
- le####daughter.net/forum/search.php?em#####################################
- he###nready.net/forum/search.php?em#####################################
- le###rready.net/forum/search.php?em#####################################
- he###nbrown.net/forum/search.php?em#####################################
- le###rbrown.net/forum/search.php?em#####################################
- he###ready.net/forum/search.php?em#####################################
- he####aughter.net/forum/search.php?em#####################################
- ge####people.net/forum/search.php?em#####################################
- va####sready.net/forum/search.php?em#####################################
- ge####daughter.net/forum/search.php?em#####################################
- he###brown.net/forum/search.php?em#####################################
- ge###eready.net/forum/search.php?em#####################################
- he###people.net/forum/search.php?em#####################################
- ge###ebrown.net/forum/search.php?em#####################################
- DNS ASK va####sdaughter.net
- DNS ASK re####people.net
- DNS ASK de####nation.net
- DNS ASK re####daughter.net
- DNS ASK va####sbrown.net
- DNS ASK re###nready.net
- DNS ASK va####speople.net
- DNS ASK re###nbrown.net
- DNS ASK fo####dnation.net
- DNS ASK fo#####condition.net
- DNS ASK de####condition.net
- DNS ASK gl###nation.net
- DNS ASK an####nation.net
- DNS ASK fo####dsoldier.net
- DNS ASK de####soldier.net
- DNS ASK fo####dplease.net
- DNS ASK de####please.net
- DNS ASK he####people.net
- DNS ASK le####people.net
- DNS ASK he####daughter.net
- DNS ASK le####daughter.net
- DNS ASK he###nready.net
- DNS ASK le###rready.net
- DNS ASK he###nbrown.net
- DNS ASK le###rbrown.net
- DNS ASK he###ready.net
- DNS ASK he####aughter.net
- DNS ASK ge####people.net
- DNS ASK va####sready.net
- DNS ASK ge####daughter.net
- DNS ASK he###brown.net
- DNS ASK ge###eready.net
- DNS ASK he###people.net
- DNS ASK ge###ebrown.net
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''