Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Update' = '%ProgramFiles%\ufyuygiu\kuigiugoh.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Update' = '%ProgramFiles%\ufyuygiu\kuigiugoh.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe' -f "%TEMP%\aYrh.txt"
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe' -f "%TEMP%\tDjpfBNf.txt"
- '%ProgramFiles%\ufyuygiu\kuigiugoh.exe'
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe' -f "%TEMP%\NzVUeOcq.txt"
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe
- [<HKCU>\Software\IMVU\username]
- [<HKCU>\Software\Paltalk]
- [<HKCU>\Software\Yahoo\pager]
- [<HKCU>\Software\IMVU\password]
- [<HKCU>\Software\America Online\aim6\Passwords]
- [<HKCU>\Software\Microsoft\Internet Account Manager\Accounts]
- [<HKCU>\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts]
- [<HKCU>\Software\Google\Google Talk\Accounts]
- [<HKCU>\Software\Microsoft\Windows Live Mail]
- %TEMP%\NzVUeOcq.txt
- %TEMP%\KWwwBwZ.bmp
- %TEMP%\tDjpfBNf.txt
- %TEMP%\aYrh.txt
- %ProgramFiles%\ufyuygiu\kuigiugoh.exe
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\696F3DE637E6DE85B458996D49D759AD
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\696F3DE637E6DE85B458996D49D759AD
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\7396C420A8E1BC1DA97F1AF0D10BAD21
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\7396C420A8E1BC1DA97F1AF0D10BAD21
- %TEMP%\tDjpfBNf.txt
- %TEMP%\aYrh.txt
- 'co####xsoftware.com':80
- '20#.#6.232.182':80
- 'wp#d':80
- http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl via 20#.#6.232.182
- http://co####xsoftware.com/geoip/geoip.php
- http://11#.#11.111.1/wpad.dat via wp#d
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl via 20#.#6.232.182
- DNS ASK co####xsoftware.com
- DNS ASK crl.microsoft.com
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: ''