Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Backup Quality Launcher Discovery Superfetch' = 'C:\qkzfycgtc\gxs6nnnbknvbl.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Machine Socket Control Identity] 'ImagePath' = 'C:\qkzfycgtc\gxs6nnnbknvbl.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Machine Socket Control Identity] 'Start' = '00000002'
- 'C:\qkzfycgtc\x6eqtdixx.exe' "c:\qkzfycgtc\gxs6nnnbknvbl.exe"
- 'C:\qkzfycgtc\gxs6nnnbknvbl.exe'
- 'C:\qkzfycgtc\annjbm2ji9rzgrmsqqrze.exe'
- C:\qkzfycgtc\gxs6nnnbknvbl.exe
- C:\qkzfycgtc\x6eqtdixx.exe
- C:\qkzfycgtc\rhtlesqpsbd
- %WINDIR%\qkzfycgtc\uaafaab2j
- C:\qkzfycgtc\uaafaab2j
- C:\qkzfycgtc\annjbm2ji9rzgrmsqqrze.exe
- C:\qkzfycgtc\x6eqtdixx.exe
- C:\qkzfycgtc\gxs6nnnbknvbl.exe
- C:\qkzfycgtc\annjbm2ji9rzgrmsqqrze.exe
- %WINDIR%\qkzfycgtc\uaafaab2j
- 'un###lgrain.org':80
- 'ag#####anabolics.com':80
- 'ch#####nafairchild.net':80
- 'ha####nhalflion.net':80
- 'ca#####eeitinthecup.org':80
- 'to###tosales.ru':80
- 'si###ypeas.net':80
- 'ch####isportsmen.ru':80
- 'cl#####ortswomen.com':80
- 'ch#####nepettigrew.net':80
- 'cl#####ndpettigrew.net':80
- 'ch#####nesackville.net':80
- 'cl#####ndsackville.net':80
- 'se#####anfairchild.ru':80
- 'se#####anhoneycutt.net':80
- 'ch#####nahoneycutt.net':80
- 'se#####anfairchild.net':80
- 'se#####ansackville.net':80
- 'cl####portsmen.com':80
- 'gu##155.cn':80
- 'ta#####pielenreiten.org':80
- 'bu####rmansion.com':80
- 'so####ryducks.com':80
- 'pi##asia.cn':80
- 'sc#####epuzzlechess.org':80
- 'ye####gdongwu.cn':80
- 'do##bate.cn':80
- 'sp##tnav.ru':80
- 'ka#######ayajivayapriroda.ru':80
- 'pr##card.ru':80
- 'gr###factory.cn':80
- 'ga#####yundongyuan.cn':80
- 'sc####ainbow.net':80
- 'na##top.ru':80
- 'ga####liongrass.net':80
- 'pr####anabolikov.ru':80
- http://un###lgrain.org/index.php
- http://ag#####anabolics.com/index.php
- http://ch#####nafairchild.net/index.php
- http://ha####nhalflion.net/index.php
- http://ca#####eeitinthecup.org/index.php
- http://to###tosales.ru/index.php
- http://si###ypeas.net/index.php
- http://ch####isportsmen.ru/index.php
- http://cl#####ortswomen.com/index.php
- http://ch#####nepettigrew.net/index.php
- http://cl#####ndpettigrew.net/index.php
- http://ch#####nesackville.net/index.php
- http://cl#####ndsackville.net/index.php
- http://se#####anfairchild.ru/index.php
- http://se#####anhoneycutt.net/index.php
- http://ch#####nahoneycutt.net/index.php
- http://se#####anfairchild.net/index.php
- http://se#####ansackville.net/index.php
- http://cl####portsmen.com/index.php
- http://gu##155.cn/index.php
- http://ta#####pielenreiten.org/index.php
- http://bu####rmansion.com/index.php
- http://so####ryducks.com/index.php
- http://pi##asia.cn/index.php
- http://sc#####epuzzlechess.org/index.php
- http://ye####gdongwu.cn/index.php
- http://do##bate.cn/index.php
- http://sp##tnav.ru/index.php
- http://ka#######ayajivayapriroda.ru/index.php
- http://pr##card.ru/index.php
- http://gr###factory.cn/index.php
- http://ga#####yundongyuan.cn/index.php
- http://sc####ainbow.net/index.php
- http://na##top.ru/index.php
- http://ga####liongrass.net/index.php
- http://pr####anabolikov.ru/index.php
- DNS ASK he#####onjeremiah.net
- DNS ASK br#####tejohnathan.net
- DNS ASK br#####tethaddeus.net
- DNS ASK th#####naperegrine.net
- DNS ASK je#####onthaddeus.net
- DNS ASK ce#####neperegrine.net
- DNS ASK ce#####nejeremiah.net
- DNS ASK ce#####nejohnathan.net
- DNS ASK th#####nathaddeus.net
- DNS ASK ce#####nethaddeus.net
- DNS ASK je#####onjohnathan.net
- DNS ASK kr#####lejeremiah.net
- DNS ASK ge#####nejohnathan.ru
- DNS ASK br#####tejeremiah.net
- DNS ASK ge#####nejohnathan.net
- DNS ASK ge#####nethaddeus.net
- DNS ASK he#####tathaddeus.net
- DNS ASK he#####tajohnathan.net
- DNS ASK je#####onperegrine.ru
- DNS ASK th#####nathaddeus.ru
- DNS ASK je#####onperegrine.net
- DNS ASK je#####onjeremiah.net
- DNS ASK br#####teperegrine.net
- DNS ASK ce#####nejeremiah.ru
- DNS ASK gr#####lethaddeus.net
- DNS ASK si#####erthaddeus.net
- DNS ASK gr#####lethaddeus.ru
- DNS ASK gr#####leperegrine.net
- DNS ASK si#####erperegrine.net
- DNS ASK gr#####lejohnathan.net
- DNS ASK de#####stfairchild.ru
- DNS ASK la#####iahoneycutt.net
- DNS ASK de#####stfairchild.net
- DNS ASK si#####erjohnathan.net
- DNS ASK la#####iafairchild.net
- DNS ASK si#####erjeremiah.net
- DNS ASK kr#####leperegrine.ru
- DNS ASK he#####onperegrine.net
- DNS ASK kr#####leperegrine.net
- DNS ASK th#####najeremiah.net
- DNS ASK th#####najohnathan.net
- DNS ASK kr#####lethaddeus.net
- DNS ASK he#####onjohnathan.ru
- DNS ASK gr#####lejeremiah.net
- DNS ASK he#####onjohnathan.net
- DNS ASK he#####onthaddeus.net
- DNS ASK kr#####lejohnathan.net
- DNS ASK an#####lajeremiah.net
- DNS ASK an#####laperegrine.net
- DNS ASK ga#####lejeremiah.ru
- DNS ASK si#####erelyzabeth.net
- DNS ASK ga#####lejeremiah.net
- DNS ASK ga#####leperegrine.net
- DNS ASK ga#####lejohnathan.net
- DNS ASK ga#####lajeremiah.net
- DNS ASK an#####lathaddeus.ru
- DNS ASK ga#####lethaddeus.net
- DNS ASK an#####lathaddeus.net
- DNS ASK gr#####leelyzabeth.net
- DNS ASK he#####onelyzabeth.net
- DNS ASK gr#####leshavonne.net
- DNS ASK kr#####leelyzabeth.ru
- DNS ASK he#####onterrance.net
- DNS ASK kr#####leelyzabeth.net
- DNS ASK si#####ershavonne.net
- DNS ASK si#####erbrittania.ru
- DNS ASK si#####erterrance.net
- DNS ASK gr#####leterrance.net
- DNS ASK gr#####lebrittania.net
- DNS ASK si#####erbrittania.net
- DNS ASK an#####lajohnathan.net
- DNS ASK gr#####orthaddeus.net
- DNS ASK sh#####lejohnathan.net
- DNS ASK sh#####lethaddeus.ru
- DNS ASK gr#####orperegrine.net
- DNS ASK sh#####lethaddeus.net
- DNS ASK gr#####orjohnathan.net
- DNS ASK ge#####neperegrine.net
- DNS ASK he#####taperegrine.net
- DNS ASK he#####tajeremiah.ru
- DNS ASK ge#####nejeremiah.net
- DNS ASK he#####tajeremiah.net
- DNS ASK sh#####leperegrine.net
- DNS ASK br#####iaperegrine.net
- DNS ASK ga#####lathaddeus.net
- DNS ASK ga#####laperegrine.ru
- DNS ASK br#####iajeremiah.net
- DNS ASK ga#####laperegrine.net
- DNS ASK br#####iajohnathan.net
- DNS ASK sh#####lejeremiah.net
- DNS ASK gr#####orjeremiah.net
- DNS ASK br#####iajohnathan.ru
- DNS ASK ga#####lajohnathan.net
- DNS ASK br#####iathaddeus.net
- DNS ASK de#####sthoneycutt.net
- DNS ASK se#####anfairchild.ru
- DNS ASK se#####anfairchild.net
- DNS ASK cl#####ndpettigrew.net
- DNS ASK cl#####ndsackville.net
- DNS ASK ch#####nepettigrew.net
- DNS ASK se#####ansackville.net
- DNS ASK ha####nhalflion.net
- DNS ASK un###lgrain.org
- DNS ASK ch#####nafairchild.net
- DNS ASK se#####anhoneycutt.net
- DNS ASK ch#####nahoneycutt.net
- DNS ASK ch#####nesackville.net
- DNS ASK ja#####tasackville.ru
- DNS ASK ch#####nefairchild.net
- DNS ASK ja#####ynpettigrew.net
- DNS ASK ro#####nesackville.net
- DNS ASK co#####cepettigrew.net
- DNS ASK ja#####ynpettigrew.ru
- DNS ASK cr#####onfairchild.ru
- DNS ASK cl#####ndfairchild.net
- DNS ASK cr#####onfairchild.net
- DNS ASK ja#####tahoneycutt.net
- DNS ASK ro#####nefairchild.net
- DNS ASK ag#####anabolics.com
- DNS ASK bu####rmansion.com
- DNS ASK cl####portsmen.com
- DNS ASK ta#####pielenreiten.org
- DNS ASK sc####ainbow.net
- DNS ASK na##top.ru
- DNS ASK gu##155.cn
- DNS ASK pi##asia.cn
- DNS ASK sc#####epuzzlechess.org
- DNS ASK do##bate.cn
- DNS ASK so####ryducks.com
- DNS ASK ye####gdongwu.cn
- DNS ASK pr####anabolikov.ru
- DNS ASK to###tosales.ru
- DNS ASK si###ypeas.net
- DNS ASK cl#####ortswomen.com
- DNS ASK ca#####eeitinthecup.org
- DNS ASK ch####isportsmen.ru
- DNS ASK pr##card.ru
- DNS ASK ga#####yundongyuan.cn
- DNS ASK ga####liongrass.net
- DNS ASK ka#######ayajivayapriroda.ru
- DNS ASK gr###factory.cn
- DNS ASK sp##tnav.ru
- DNS ASK ch#####tahoneycutt.net
- DNS ASK pr#####lapettigrew.net
- DNS ASK ma#####ansackville.net
- DNS ASK ka#####rafairchild.net
- DNS ASK ka#####rafairchild.ru
- DNS ASK ch#####tafairchild.net
- DNS ASK ch#####tasackville.ru
- DNS ASK ka#####rapettigrew.net
- DNS ASK ch#####tasackville.net
- DNS ASK ka#####rahoneycutt.net
- DNS ASK ka#####rasackville.net
- DNS ASK pr#####lasackville.net
- DNS ASK la#####iapettigrew.ru
- DNS ASK de#####stpettigrew.net
- DNS ASK la#####iapettigrew.net
- DNS ASK la#####iasackville.net
- DNS ASK de#####stsackville.net
- DNS ASK pr#####lafairchild.net
- DNS ASK pr#####lahoneycutt.net
- DNS ASK ma#####anpettigrew.net
- DNS ASK ma#####anhoneycutt.ru
- DNS ASK ma#####anfairchild.net
- DNS ASK ma#####anhoneycutt.net
- DNS ASK ch#####tapettigrew.net
- DNS ASK ha#####tapettigrew.ru
- DNS ASK ja#####ynfairchild.net
- DNS ASK cl#####ndhoneycutt.net
- DNS ASK ha#####tapettigrew.net
- DNS ASK cr#####onhoneycutt.net
- DNS ASK ja#####ynhoneycutt.net
- DNS ASK ja#####tapettigrew.net
- DNS ASK ro#####nehoneycutt.net
- DNS ASK ja#####tafairchild.net
- DNS ASK cr#####onpettigrew.net
- DNS ASK cr#####onsackville.net
- DNS ASK ha#####tasackville.net
- DNS ASK co#####cehoneycutt.ru
- DNS ASK co#####cesackville.net
- DNS ASK co#####cehoneycutt.net
- DNS ASK co#####cefairchild.net
- DNS ASK ha#####tafairchild.net
- DNS ASK ja#####ynsackville.net
- DNS ASK ro#####nepettigrew.net
- DNS ASK ja#####tasackville.net
- DNS ASK ha#####tahoneycutt.net
- DNS ASK ch#####nehoneycutt.ru
- DNS ASK ch#####nehoneycutt.net