Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Solutions Filtering UPnP Protection Smart DLL' = '<SYSTEM32>\mcvhtfj.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Link-Layer Diagnostic] 'ImagePath' = '<SYSTEM32>\mcvhtfj.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Link-Layer Diagnostic] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\jfxcucbqexn.exe' "<SYSTEM32>\mcvhtfj.exe"
- '%WINDIR%\Temp\hf5tq4jxjeijxs6rla.exe' -r 39388 tcp
- '%TEMP%\hf5tq4jbj22x5s6rlaxe7h7ofd.exe'
- '<SYSTEM32>\mcvhtfj.exe'
- <SYSTEM32>\uzdncdlglnz\run
- <SYSTEM32>\uzdncdlglnz\cli
- %WINDIR%\Temp\hf5tq4jxjeijxs6rla.exe
- <SYSTEM32>\uzdncdlglnz\cfg
- <SYSTEM32>\uzdncdlglnz\rng
- %TEMP%\hf5tq4jbj22x5s6rlaxe7h7ofd.exe
- <SYSTEM32>\uzdncdlglnz\tst
- <SYSTEM32>\jfxcucbqexn.exe
- <SYSTEM32>\mcvhtfj.exe
- <SYSTEM32>\jfxcucbqexn.exe
- <SYSTEM32>\mcvhtfj.exe
- %WINDIR%\Temp\hf5tq4jxjeijxs6rla.exe
- %TEMP%\hf5tq4jbj22x5s6rlaxe7h7ofd.exe
- '19#.#7.134.20':44965
- '62.##1.108.194':20068
- '81.##7.50.99':52074
- '2.##.167.151':22437
- '87.##.238.184':44724
- '79.##7.196.121':45688
- '17#.#50.138.208':20422
- '86.##.69.232':41590
- '81.##4.87.112':37714
- '22#.#1.110.45':48008
- '73.##.228.84':36884
- '61.##6.2.217':25840
- '86.##5.10.227':45279
- '10#.#28.239.221':49777
- '88.#48.36.4':25752
- '18#.#42.73.242':26662
- '21#.#7.168.28':52231
- '18#.#49.85.10':32097
- '78.#7.87.58':21017
- '17#.37.2.43':44303
- '18#.#39.143.239':37599
- '18#.#22.32.59':46084
- '91.##.35.122':26126
- '82.##7.164.91':40801
- '62.##.253.114':51156
- '18#.#5.131.224':26337
- '24.##9.216.168':33794
- '98.##.239.20':20922
- '86.##5.19.130':27743
- '93.##7.67.155':25640
- '70.##5.4.143':41500
- '10#.#4.136.243':42581
- '41.#6.20.41':48405
- '19#.#6.240.249':21875
- '41.#42.27.1':45860
- '10#.#46.77.146':33927
- '10#.#25.112.152':47507
- '11#.#18.187.28':42065
- '84.##2.194.230':27426
- '78.##5.171.93':23699
- '80.##1.86.158':33631
- '21#.#07.110.82':26314
- '18#.#0.223.209':25741
- '77.##7.13.68':30018
- '95.##7.243.188':49038
- '10#.#02.79.27':36272
- '18#.#44.248.140':28122
- '2.##.19.50':35833
- '20#.#70.58.131':37727
- '95.##.58.101':23245
- '20#.#36.131.186':52293
- '20#.#23.152.97':27682
- '77.##8.205.139':22969
- '94.##1.114.138':44254
- '79.##3.139.198':21201
- '19#.#0.96.220':41884
- '12#.#60.112.138':27440
- '19#.#47.86.10':25432
- '74.#5.64.25':22739
- '18#.#45.182.189':37331
- '84.##8.128.25':27132
- '20#.#7.225.58':33073
- '11#.#6.137.96':49919
- '18#.2.4.92':44843
- '41.##8.41.238':29356
- '15#.#82.245.137':33982
- '2.##.156.247':35711
- '12#.#60.123.173':36805
- '72.##1.47.203':22399
- '23#.#55.255.250':1900