Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Offline Encrypting Image' = 'C:\npzaycop\mcexltypqv.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Detection Coordinator Power VC] 'ImagePath' = 'C:\npzaycop\mcexltypqv.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Detection Coordinator Power VC] 'Start' = '00000002'
- 'C:\npzaycop\ugzdfjhrndt.exe' "c:\npzaycop\mcexltypqv.exe"
- 'C:\npzaycop\mcexltypqv.exe'
- 'C:\npzaycop\vi32qjfoywztk5bt.exe'
- C:\npzaycop\mcexltypqv.exe
- C:\npzaycop\ugzdfjhrndt.exe
- C:\npzaycop\vi32qjfoywztk5bt.exe
- %WINDIR%\npzaycop\hs5tppn
- C:\npzaycop\hs5tppn
- C:\npzaycop\ugzdfjhrndt.exe
- C:\npzaycop\mcexltypqv.exe
- C:\npzaycop\vi32qjfoywztk5bt.exe
- %WINDIR%\npzaycop\hs5tppn
- 'bu#####gdistance.net':80
- 'ev####gsupply.net':80
- 'bu####ngoffice.net':80
- 'ev####gdistance.net':80
- 'mo####ntarrive.net':80
- 'ou####eoffice.net':80
- 'bu####ngsupply.net':80
- 'ou####earrive.net':80
- 'ev####goffice.net':80
- 'mi####istance.net':80
- 'st####istance.net':80
- 'mi###office.net':80
- 'st###office.net':80
- 'ev####garrive.net':80
- 'bu####ngarrive.net':80
- 'mi###supply.net':80
- 'st###supply.net':80
- 'st###should.net':80
- 'st####thshould.net':80
- 'st###short.net':80
- 'st####thshort.net':80
- 'de####opinion.net':80
- 'pr####eopinion.net':80
- 'de####promise.net':80
- 'pr####epromise.net':80
- 'st####thopinion.net':80
- 'mo#####tdistance.net':80
- 'ou####esupply.net':80
- 'mo####ntoffice.net':80
- 'ou####edistance.net':80
- 'st####thpromise.net':80
- 'st####pinion.net':80
- 'mo####ntsupply.net':80
- 'st####romise.net':80
- http://bu#####gdistance.net/index.php
- http://ev####gsupply.net/index.php
- http://bu####ngoffice.net/index.php
- http://ev####gdistance.net/index.php
- http://mo####ntarrive.net/index.php
- http://ou####eoffice.net/index.php
- http://bu####ngsupply.net/index.php
- http://ou####earrive.net/index.php
- http://ev####goffice.net/index.php
- http://mi####istance.net/index.php
- http://st####istance.net/index.php
- http://mi###office.net/index.php
- http://st###office.net/index.php
- http://ev####garrive.net/index.php
- http://bu####ngarrive.net/index.php
- http://mi###supply.net/index.php
- http://st###supply.net/index.php
- http://st###should.net/index.php
- http://st####thshould.net/index.php
- http://st###short.net/index.php
- http://st####thshort.net/index.php
- http://de####opinion.net/index.php
- http://pr####eopinion.net/index.php
- http://de####promise.net/index.php
- http://pr####epromise.net/index.php
- http://st####thopinion.net/index.php
- http://mo#####tdistance.net/index.php
- http://ou####esupply.net/index.php
- http://mo####ntoffice.net/index.php
- http://ou####edistance.net/index.php
- http://st####thpromise.net/index.php
- http://st####pinion.net/index.php
- http://mo####ntsupply.net/index.php
- http://st####romise.net/index.php
- DNS ASK ev####gdistance.net
- DNS ASK bu#####gdistance.net
- DNS ASK ev####goffice.net
- DNS ASK bu####ngoffice.net
- DNS ASK ou####earrive.net
- DNS ASK mo####ntarrive.net
- DNS ASK ev####gsupply.net
- DNS ASK bu####ngsupply.net
- DNS ASK bu####ngarrive.net
- DNS ASK st###office.net
- DNS ASK mi####istance.net
- DNS ASK st###arrive.net
- DNS ASK mi###office.net
- DNS ASK st###supply.net
- DNS ASK ev####garrive.net
- DNS ASK st####istance.net
- DNS ASK mi###supply.net
- DNS ASK ou####eoffice.net
- DNS ASK st###should.net
- DNS ASK st####thshould.net
- DNS ASK st###short.net
- DNS ASK st####thshort.net
- DNS ASK de####opinion.net
- DNS ASK pr####eopinion.net
- DNS ASK de####promise.net
- DNS ASK pr####epromise.net
- DNS ASK st####thopinion.net
- DNS ASK mo#####tdistance.net
- DNS ASK ou####esupply.net
- DNS ASK mo####ntoffice.net
- DNS ASK ou####edistance.net
- DNS ASK st####thpromise.net
- DNS ASK st####pinion.net
- DNS ASK mo####ntsupply.net
- DNS ASK st####romise.net
- ClassName: 'Shell_TrayWnd' WindowName: ''