Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Debugger Human Identity Application' = 'C:\z7frzipo\r7yw9tp.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Group Tools Defender Themes Tablet] 'ImagePath' = 'C:\z7frzipo\r7yw9tp.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Group Tools Defender Themes Tablet] 'Start' = '00000002'
- 'C:\z7frzipo\szxugzi.exe' "c:\z7frzipo\r7yw9tp.exe"
- 'C:\z7frzipo\r7yw9tp.exe'
- 'C:\z7frzipo\wkjajw2wbnc6arhlyyriar.exe'
- C:\z7frzipo\r7yw9tp.exe
- C:\z7frzipo\szxugzi.exe
- C:\z7frzipo\yscb6qxffsy
- %WINDIR%\z7frzipo\vnyuzfhcx
- C:\z7frzipo\vnyuzfhcx
- C:\z7frzipo\wkjajw2wbnc6arhlyyriar.exe
- C:\z7frzipo\szxugzi.exe
- C:\z7frzipo\r7yw9tp.exe
- C:\z7frzipo\wkjajw2wbnc6arhlyyriar.exe
- %WINDIR%\z7frzipo\vnyuzfhcx
- 'pr####anabolikov.ru':80
- 'pi##asia.cn':80
- 'al######eastrickland.net':80
- 'al######eabreckenridge.net':80
- 'ch####isportsmen.ru':80
- 'si###ypeas.net':80
- 'ga#####yundongyuan.cn':80
- 'ca#####eeitinthecup.org':80
- 'na##top.ru':80
- 'al#####riacartwright.ru':80
- 'al######iabenjaminson.net':80
- 're######nebenjaminson.net':80
- 'al######iacartwright.net':80
- 'ch######ellecartwright.net':80
- 'er######debreckenridge.net':80
- 'al#####reastrickland.ru':80
- 'er######destrickland.net':80
- 'ch######ellebenjaminson.net':80
- 'sc####ainbow.net':80
- 'ag#####anabolics.com':80
- 'gu##155.cn':80
- 'un###lgrain.org':80
- 'ta#####pielenreiten.org':80
- 'do##bate.cn':80
- 'to###tosales.ru':80
- 'ga####liongrass.net':80
- 'cl#####ortswomen.com':80
- 'gr###factory.cn':80
- 'sp##tnav.ru':80
- 'cl####portsmen.com':80
- 'ka#######ayajivayapriroda.ru':80
- 'ha####nhalflion.net':80
- 'pr##card.ru':80
- 'sc#####epuzzlechess.org':80
- 'bu####rmansion.com':80
- 'ye####gdongwu.cn':80
- 'so####ryducks.com':80
- http://pr####anabolikov.ru/index.php
- http://pi##asia.cn/index.php
- http://al######eastrickland.net/index.php
- http://al######eabreckenridge.net/index.php
- http://ch####isportsmen.ru/index.php
- http://si###ypeas.net/index.php
- http://ga#####yundongyuan.cn/index.php
- http://ca#####eeitinthecup.org/index.php
- http://na##top.ru/index.php
- http://al#####riacartwright.ru/index.php
- http://al######iabenjaminson.net/index.php
- http://re######nebenjaminson.net/index.php
- http://al######iacartwright.net/index.php
- http://ch######ellecartwright.net/index.php
- http://er######debreckenridge.net/index.php
- http://al#####reastrickland.ru/index.php
- http://er######destrickland.net/index.php
- http://ch######ellebenjaminson.net/index.php
- http://sc####ainbow.net/index.php
- http://ag#####anabolics.com/index.php
- http://gu##155.cn/index.php
- http://un###lgrain.org/index.php
- http://ta#####pielenreiten.org/index.php
- http://do##bate.cn/index.php
- http://to###tosales.ru/index.php
- http://ga####liongrass.net/index.php
- http://cl#####ortswomen.com/index.php
- http://gr###factory.cn/index.php
- http://sp##tnav.ru/index.php
- http://cl####portsmen.com/index.php
- http://ka#######ayajivayapriroda.ru/index.php
- http://ha####nhalflion.net/index.php
- http://pr##card.ru/index.php
- http://sc#####epuzzlechess.org/index.php
- http://bu####rmansion.com/index.php
- http://ye####gdongwu.cn/index.php
- http://so####ryducks.com/index.php
- DNS ASK al######eabenjaminson.net
- DNS ASK mo######rychancellor.net
- DNS ASK al#####reacartwright.ru
- DNS ASK er######debenjaminson.net
- DNS ASK mo######rycartwright.net
- DNS ASK mo######rybenjaminson.net
- DNS ASK mo######ryblackbourne.net
- DNS ASK mo######ryblackbourne.ru
- DNS ASK al######eacartwright.net
- DNS ASK er######dechancellor.net
- DNS ASK er#####udechancellor.ru
- DNS ASK ca#####nepleasance.net
- DNS ASK me#####herpleasance.net
- DNS ASK er######deblackbourne.net
- DNS ASK er######decartwright.net
- DNS ASK al######eachancellor.net
- DNS ASK al######eablackbourne.net
- DNS ASK ch######elbenjaminson.ru
- DNS ASK ch######nnechancellor.ru
- DNS ASK ma######tablackbourne.net
- DNS ASK ma######tachancellor.net
- DNS ASK ch######nnechancellor.net
- DNS ASK ch######nnecartwright.net
- DNS ASK ma######tabenjaminson.net
- DNS ASK ch######nneblackbourne.net
- DNS ASK ma######tacartwright.net
- DNS ASK ch######herbenjaminson.net
- DNS ASK te######ceblackbourne.net
- DNS ASK ch######herblackbourne.net
- DNS ASK te######cechancellor.net
- DNS ASK ch######herchancellor.net
- DNS ASK ch######hercartwright.net
- DNS ASK te######cebenjaminson.net
- DNS ASK te######cecartwright.net
- DNS ASK te#####ncecartwright.ru
- DNS ASK me#####herfrederica.net
- DNS ASK wi#####edbertrand.net
- DNS ASK wi#####edphilander.net
- DNS ASK ka#####napleasance.ru
- DNS ASK sy#####erbertrand.net
- DNS ASK sy#####erfrederica.ru
- DNS ASK wi#####edfrederica.net
- DNS ASK sy#####erphilander.net
- DNS ASK sy#####erfrederica.net
- DNS ASK ka#####napleasance.net
- DNS ASK br#####nnphilander.net
- DNS ASK br#####nnphilander.ru
- DNS ASK br#####nnbertrand.net
- DNS ASK ka#####nabertrand.net
- DNS ASK ka#####nafrederica.net
- DNS ASK br#####nnpleasance.net
- DNS ASK br#####nnfrederica.net
- DNS ASK ka#####naphilander.net
- DNS ASK sy#####erpleasance.net
- DNS ASK ca#####nebertrand.net
- DNS ASK me#####herbertrand.net
- DNS ASK jo#####nepleasance.net
- DNS ASK ma#####inefrederica.net
- DNS ASK me#####herphilander.ru
- DNS ASK ca#####nefrederica.net
- DNS ASK ca#####nephilander.net
- DNS ASK me#####herphilander.net
- DNS ASK jo#####nepleasance.ru
- DNS ASK ma#####inebertrand.net
- DNS ASK jo#####nephilander.net
- DNS ASK wi#####edpleasance.net
- DNS ASK jo#####nebertrand.net
- DNS ASK ma#####inepleasance.net
- DNS ASK jo#####nefrederica.net
- DNS ASK ma#####inebertrand.ru
- DNS ASK ma#####inephilander.net
- DNS ASK ch####isportsmen.ru
- DNS ASK ca#####eeitinthecup.org
- DNS ASK pr####anabolikov.ru
- DNS ASK pi##asia.cn
- DNS ASK ga#####yundongyuan.cn
- DNS ASK sc####ainbow.net
- DNS ASK na##top.ru
- DNS ASK si###ypeas.net
- DNS ASK al######eabreckenridge.net
- DNS ASK ch######ellecartwright.net
- DNS ASK er######destrickland.net
- DNS ASK al#####riacartwright.ru
- DNS ASK al######iabenjaminson.net
- DNS ASK al#####reastrickland.ru
- DNS ASK al######eastrickland.net
- DNS ASK ch######ellebenjaminson.net
- DNS ASK er######debreckenridge.net
- DNS ASK ka#######ayajivayapriroda.ru
- DNS ASK gu##155.cn
- DNS ASK do##bate.cn
- DNS ASK ta#####pielenreiten.org
- DNS ASK ag#####anabolics.com
- DNS ASK to###tosales.ru
- DNS ASK ga####liongrass.net
- DNS ASK cl#####ortswomen.com
- DNS ASK gr###factory.cn
- DNS ASK un###lgrain.org
- DNS ASK cl####portsmen.com
- DNS ASK pr##card.ru
- DNS ASK ha####nhalflion.net
- DNS ASK sp##tnav.ru
- DNS ASK sc#####epuzzlechess.org
- DNS ASK bu####rmansion.com
- DNS ASK ye####gdongwu.cn
- DNS ASK so####ryducks.com
- DNS ASK al######iacartwright.net
- DNS ASK ja######necartwright.net
- DNS ASK re######necartwright.net
- DNS ASK ch######elblackbourne.net
- DNS ASK al######iablackbourne.net
- DNS ASK ki######ighcartwright.net
- DNS ASK ch######elbenjaminson.net
- DNS ASK be######techancellor.net
- DNS ASK ge######nablackbourne.ru
- DNS ASK re######neblackbourne.net
- DNS ASK ja######nechancellor.net
- DNS ASK ge######nachancellor.net
- DNS ASK ma######tabenjaminson.ru
- DNS ASK ch######nnebenjaminson.net
- DNS ASK ja######nebenjaminson.net
- DNS ASK ch######ellechancellor.net
- DNS ASK ja######neblackbourne.net
- DNS ASK re#####nnechancellor.ru
- DNS ASK be######tebenjaminson.net
- DNS ASK be######teblackbourne.ru
- DNS ASK ki######ighbenjaminson.ru
- DNS ASK ge######nablackbourne.net
- DNS ASK ge######nacartwright.net
- DNS ASK ge######nabenjaminson.net
- DNS ASK re######nebenjaminson.net
- DNS ASK ki######ighbenjaminson.net
- DNS ASK ch######elleblackbourne.net
- DNS ASK al######iachancellor.net
- DNS ASK ch######elchancellor.net
- DNS ASK ch#####belcartwright.ru
- DNS ASK re######nechancellor.net
- DNS ASK be######tecartwright.net
- DNS ASK ki######ighblackbourne.net
- DNS ASK ki######ighchancellor.net
- DNS ASK ch######elcartwright.net
- DNS ASK be######teblackbourne.net