Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Engine Studio UPnP Tablet Intelligent' = 'C:\tplozosjr\hgbjuqjh.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SPP Themes Mapper SNMP Sharing Layer] 'Start' = '00000002'
- 'C:\tplozosjr\letovorxdue.exe' "c:\tplozosjr\hgbjuqjh.exe"
- 'C:\tplozosjr\hgbjuqjh.exe'
- 'C:\tplozosjr\ai3l97shqkj9gs.exe'
- C:\tplozosjr\hgbjuqjh.exe
- C:\tplozosjr\letovorxdue.exe
- C:\tplozosjr\ai3l97shqkj9gs.exe
- %WINDIR%\tplozosjr\vfokqjw
- C:\tplozosjr\vfokqjw
- C:\tplozosjr\letovorxdue.exe
- C:\tplozosjr\hgbjuqjh.exe
- C:\tplozosjr\ai3l97shqkj9gs.exe
- %WINDIR%\tplozosjr\vfokqjw
- 'ri###wagon.net':80
- 'wh####rwagon.net':80
- 'ri####ithout.net':80
- 'wh####rwithout.net':80
- 'fo####nkitchen.net':80
- 'su####kitchen.net':80
- 'fo####nprobable.net':80
- 'su####probable.net':80
- 'th###hwagon.net':80
- 'fi###ewagon.net':80
- 'th####without.net':80
- 'fi####without.net':80
- 'ri####itchen.net':80
- 'wh####rkitchen.net':80
- 'ri####robable.net':80
- 'wh####rprobable.net':80
- 'fo####nwithout.net':80
- 'pe###nwagon.net':80
- 'be####eprobable.net':80
- 'pe####without.net':80
- 'ma####ewagon.net':80
- 'ex####kitchen.net':80
- 'be####ewithout.net':80
- 'ex####probable.net':80
- 'be####ekitchen.net':80
- 'su###nwagon.net':80
- 'ma####eprobable.net':80
- 'su####without.net':80
- 'fo####nwagon.net':80
- 'pe####kitchen.net':80
- 'ma####ewithout.net':80
- 'pe####probable.net':80
- 'ma####ekitchen.net':80
- http://ri###wagon.net/index.php
- http://wh####rwagon.net/index.php
- http://ri####ithout.net/index.php
- http://wh####rwithout.net/index.php
- http://fo####nkitchen.net/index.php
- http://su####kitchen.net/index.php
- http://fo####nprobable.net/index.php
- http://su####probable.net/index.php
- http://th###hwagon.net/index.php
- http://fi###ewagon.net/index.php
- http://th####without.net/index.php
- http://fi####without.net/index.php
- http://ri####itchen.net/index.php
- http://wh####rkitchen.net/index.php
- http://ri####robable.net/index.php
- http://wh####rprobable.net/index.php
- http://fo####nwithout.net/index.php
- http://pe###nwagon.net/index.php
- http://be####eprobable.net/index.php
- http://pe####without.net/index.php
- http://ma####ewagon.net/index.php
- http://ex####kitchen.net/index.php
- http://be####ewithout.net/index.php
- http://ex####probable.net/index.php
- http://be####ekitchen.net/index.php
- http://su###nwagon.net/index.php
- http://ma####eprobable.net/index.php
- http://su####without.net/index.php
- http://fo####nwagon.net/index.php
- http://pe####kitchen.net/index.php
- http://ma####ewithout.net/index.php
- http://pe####probable.net/index.php
- http://ma####ekitchen.net/index.php
- DNS ASK ri###wagon.net
- DNS ASK wh####rwagon.net
- DNS ASK ri####ithout.net
- DNS ASK wh####rwithout.net
- DNS ASK fo####nkitchen.net
- DNS ASK su####kitchen.net
- DNS ASK fo####nprobable.net
- DNS ASK su####probable.net
- DNS ASK th###hwagon.net
- DNS ASK fi###ewagon.net
- DNS ASK th####without.net
- DNS ASK fi####without.net
- DNS ASK ri####itchen.net
- DNS ASK wh####rkitchen.net
- DNS ASK ri####robable.net
- DNS ASK wh####rprobable.net
- DNS ASK fo####nwithout.net
- DNS ASK pe###nwagon.net
- DNS ASK be####eprobable.net
- DNS ASK pe####without.net
- DNS ASK ma####ewagon.net
- DNS ASK ex####kitchen.net
- DNS ASK be####ewithout.net
- DNS ASK ex####probable.net
- DNS ASK be####ekitchen.net
- DNS ASK su###nwagon.net
- DNS ASK ma####eprobable.net
- DNS ASK su####without.net
- DNS ASK fo####nwagon.net
- DNS ASK pe####kitchen.net
- DNS ASK ma####ewithout.net
- DNS ASK pe####probable.net
- DNS ASK ma####ekitchen.net
- ClassName: 'Shell_TrayWnd' WindowName: ''