Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Cryptographic SSDP Controls TP Diagnostic' = '<SYSTEM32>\npqkeypls.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\File Name Encrypting Disk Routing] 'Start' = '00000002'
- [<HKLM>\SYSTEM\ControlSet001\Services\File Name Encrypting Disk Routing] 'ImagePath' = '<SYSTEM32>\npqkeypls.exe'
- Windows Security Center
- <SYSTEM32>\wtkqljmkgv\tst
- %TEMP%\zsq8blq2sv2k4pujprdf.exe
- <SYSTEM32>\wtkqljmkgv\etc
- <SYSTEM32>\npqkeypls.exe
- <SYSTEM32>\hjwnnyj.exe
- <SYSTEM32>\wtkqljmkgv\rng
- <SYSTEM32>\wtkqljmkgv\run
- <SYSTEM32>\wtkqljmkgv\cfg
- %WINDIR%\Temp\zsq8blq2xyok4p.exe
- <SYSTEM32>\npqkeypls.exe
- <SYSTEM32>\hjwnnyj.exe
- <DRIVERS>\etc\hosts
- %WINDIR%\Temp\zsq8blq2xyok4p.exe
- 'el#####arimagine.com':80
- 'dr###form.net':80
- 'na###orm.net':80
- 'dr###agree.net':80
- 'na###gree.net':80
- 'dr###touch.net':80
- 'na###ouch.net':80
- 'dr###word.net':80
- 'na###ord.net':80
- 'fi###hard.net':80
- 'qu###hard.net':80
- 'fi###clock.net':80
- 'qu###clock.net':80
- 'fi###make.net':80
- 'qu###make.net':80
- 'fi###rush.net':80
- 'qu###rush.net':80
- 'bo###ard.net':80
- 'ga###ard.net':80
- 'bo###lock.net':80
- 'ga###lock.net':80
- 'bo###ake.net':80
- 'ga###ake.net':80
- 'bo###ush.net':80
- 'ga###ush.net':80
- 'le###hard.net':80
- 'fa###ard.net':80
- 'le###clock.net':80
- 'fa###lock.net':80
- 'le###make.net':80
- 'we####dayword.net':80
- 'fa###ake.net':80
- 'se###ord.net':80
- 'se###ouch.net':80
- 'mo###uia.com':80
- 'pe###hecon.com':80
- 'th###rrefk.com':80
- 'ta###wash.net':80
- 'sa###ave.net':80
- 'yo###njoy.net':80
- 'lo###oss.net':80
- 'so###about.net':80
- 'li###hot.net':80
- 'ab###ach.net':80
- 'ju###ray.net':80
- 'mo###ray.net':80
- 'we###gree.net':80
- 'st###touch.net':80
- 'we###ouch.net':80
- 'st###word.net':80
- 'we###ord.net':80
- 'af###form.net':80
- 'fo###form.net':80
- 'af###agree.net':80
- 'fo###agree.net':80
- 'af###touch.net':80
- 'fo###touch.net':80
- 'af###word.net':80
- 'fo###word.net':80
- 'se###orm.net':80
- 'we####dayform.net':80
- 'se###gree.net':80
- 'we####dayagree.net':80
- 'we####daytouch.net':80
- 'le###rush.net':80
- http://el#####arimagine.com/forum/search.php?me#########################################
- http://dr###form.net/forum/search.php?me#########################################
- http://na###orm.net/forum/search.php?me#########################################
- http://dr###agree.net/forum/search.php?me#########################################
- http://na###gree.net/forum/search.php?me#########################################
- http://dr###touch.net/forum/search.php?me#########################################
- http://na###ouch.net/forum/search.php?me#########################################
- http://dr###word.net/forum/search.php?me#########################################
- http://na###ord.net/forum/search.php?me#########################################
- http://fi###hard.net/forum/search.php?me#########################################
- http://qu###hard.net/forum/search.php?me#########################################
- http://fi###clock.net/forum/search.php?me#########################################
- http://qu###clock.net/forum/search.php?me#########################################
- http://fi###make.net/forum/search.php?me#########################################
- http://qu###make.net/forum/search.php?me#########################################
- http://fi###rush.net/forum/search.php?me#########################################
- http://qu###rush.net/forum/search.php?me#########################################
- http://bo###ard.net/forum/search.php?me#########################################
- http://ga###ard.net/forum/search.php?me#########################################
- http://bo###lock.net/forum/search.php?me#########################################
- http://ga###lock.net/forum/search.php?me#########################################
- http://bo###ake.net/forum/search.php?me#########################################
- http://ga###ake.net/forum/search.php?me#########################################
- http://bo###ush.net/forum/search.php?me#########################################
- http://ga###ush.net/forum/search.php?me#########################################
- http://le###hard.net/forum/search.php?me#########################################
- http://fa###ard.net/forum/search.php?me#########################################
- http://le###clock.net/forum/search.php?me#########################################
- http://fa###lock.net/forum/search.php?me#########################################
- http://le###make.net/forum/search.php?me#########################################
- http://we####dayword.net/forum/search.php?me#########################################
- http://fa###ake.net/forum/search.php?me#########################################
- http://se###ord.net/forum/search.php?me#########################################
- http://se###ouch.net/forum/search.php?me#########################################
- http://mo###uia.com/forum/search.php?me#########################################
- http://pe###hecon.com/forum/search.php?me#########################################
- http://th###rrefk.com/forum/search.php?me#########################################
- http://ta###wash.net/forum/search.php?me#########################################
- http://sa###ave.net/forum/search.php?me#########################################
- http://yo###njoy.net/forum/search.php?me#########################################
- http://lo###oss.net/forum/search.php?me#########################################
- http://so###about.net/forum/search.php?me#########################################
- http://li###hot.net/forum/search.php?me#########################################
- http://ab###ach.net/forum/search.php?me#########################################
- http://ju###ray.net/forum/search.php?me#########################################
- http://mo###ray.net/forum/search.php?me#########################################
- http://we###gree.net/forum/search.php?me#########################################
- http://st###touch.net/forum/search.php?me#########################################
- http://we###ouch.net/forum/search.php?me#########################################
- http://st###word.net/forum/search.php?me#########################################
- http://we###ord.net/forum/search.php?me#########################################
- http://af###form.net/forum/search.php?me#########################################
- http://fo###form.net/forum/search.php?me#########################################
- http://af###agree.net/forum/search.php?me#########################################
- http://fo###agree.net/forum/search.php?me#########################################
- http://af###touch.net/forum/search.php?me#########################################
- http://fo###touch.net/forum/search.php?me#########################################
- http://af###word.net/forum/search.php?me#########################################
- http://fo###word.net/forum/search.php?me#########################################
- http://se###orm.net/forum/search.php?me#########################################
- http://we####dayform.net/forum/search.php?me#########################################
- http://se###gree.net/forum/search.php?me#########################################
- http://we####dayagree.net/forum/search.php?me#########################################
- http://we####daytouch.net/forum/search.php?me#########################################
- http://le###rush.net/forum/search.php?me#########################################
- DNS ASK el#####arimagine.com
- DNS ASK dr###form.net
- DNS ASK na###orm.net
- DNS ASK dr###agree.net
- DNS ASK na###gree.net
- DNS ASK dr###touch.net
- DNS ASK na###ouch.net
- DNS ASK dr###word.net
- DNS ASK na###ord.net
- DNS ASK fi###hard.net
- DNS ASK qu###hard.net
- DNS ASK fi###clock.net
- DNS ASK qu###clock.net
- DNS ASK fi###make.net
- DNS ASK qu###make.net
- DNS ASK qu###rush.net
- DNS ASK le###rush.net
- DNS ASK bo###ard.net
- DNS ASK ga###ard.net
- DNS ASK bo###lock.net
- DNS ASK ga###lock.net
- DNS ASK bo###ake.net
- DNS ASK ga###ake.net
- DNS ASK bo###ush.net
- DNS ASK ga###ush.net
- DNS ASK le###hard.net
- DNS ASK fa###ard.net
- DNS ASK le###clock.net
- DNS ASK fa###lock.net
- DNS ASK le###make.net
- DNS ASK fa###ake.net
- DNS ASK we####dayword.net
- DNS ASK fi###rush.net
- DNS ASK se###ord.net
- DNS ASK st###word.net
- DNS ASK mo###uia.com
- DNS ASK pe###hecon.com
- DNS ASK th###rrefk.com
- DNS ASK ta###wash.net
- DNS ASK sa###ave.net
- DNS ASK yo###njoy.net
- DNS ASK lo###oss.net
- DNS ASK so###about.net
- DNS ASK li###hot.net
- DNS ASK ab###ach.net
- DNS ASK ju###ray.net
- DNS ASK mo###ray.net
- DNS ASK we###gree.net
- DNS ASK we####daytouch.net
- DNS ASK fa###ush.net
- DNS ASK se###ouch.net
- DNS ASK we####dayagree.net
- DNS ASK se###gree.net
- DNS ASK we####dayform.net
- DNS ASK se###orm.net
- DNS ASK fo###word.net
- DNS ASK we###ouch.net
- DNS ASK af###word.net
- DNS ASK af###touch.net
- DNS ASK fo###agree.net
- DNS ASK af###agree.net
- DNS ASK fo###form.net
- DNS ASK af###form.net
- DNS ASK we###ord.net
- DNS ASK fo###touch.net
- DNS ASK st###touch.net
- '23#.#55.255.250':1900
- '%TEMP%\zsq8blq2sv2k4pujprdf.exe'
- '<SYSTEM32>\npqkeypls.exe'
- '<SYSTEM32>\hjwnnyj.exe' "<SYSTEM32>\npqkeypls.exe"
- '%WINDIR%\Temp\zsq8blq2xyok4p.exe' -r 33264 tcp