Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Services Log Spooler Firewall' = '%APPDATA%\frzyxvkaqqnh\mdugnroqppm.exe'
- '%APPDATA%\frzyxvkaqqnh\qvjlickacoyd.exe' "%APPDATA%\frzyxvkaqqnh\mdugnroqppm.exe"
- '%APPDATA%\frzyxvkaqqnh\mdugnroqppm.exe'
- %APPDATA%\frzyxvkaqqnh\mdugnroqppm.leova
- %APPDATA%\frzyxvkaqqnh\qvjlickacoyd.exe
- %APPDATA%\frzyxvkaqqnh\mdugnroqppm.exe
- %APPDATA%\frzyxvkaqqnh\qvjlickacoyd.exe
- %APPDATA%\frzyxvkaqqnh\mdugnroqppm.exe
- 'or####anguage.net':80
- 're####esettle.net':80
- 're####elanguage.net':80
- 're####edevice.net':80
- 'or###device.net':80
- 'or###settle.net':80
- 'pl####ntdevice.net':80
- 'ne#####rylanguage.net':80
- 'ne####arydevice.net':80
- 'ne####arybefore.net':80
- 'pl####ntbefore.net':80
- 'or###before.net':80
- 'le####before.net':80
- 'he####device.net':80
- 'he####before.net':80
- 'ge####language.net':80
- 'ge####settle.net':80
- 'le####device.net':80
- 'le####settle.net':80
- 're####ebefore.net':80
- 'he####settle.net':80
- 'he####language.net':80
- 'le####language.net':80
- 'pl#####tlanguage.net':80
- 'an####language.net':80
- 'gl###settle.net':80
- 'gl####anguage.net':80
- 'gl###device.net':80
- 'an####device.net':80
- 'an####settle.net':80
- 'de####device.net':80
- 'fo####dlanguage.net':80
- 'fo####ddevice.net':80
- 'fo####dbefore.net':80
- 'de####before.net':80
- 'an####before.net':80
- 'di####ultbefore.net':80
- 'he###device.net':80
- 'he###before.net':80
- 'ne####arysettle.net':80
- 'pl####ntsettle.net':80
- 'di####ultdevice.net':80
- 'di####ultsettle.net':80
- 'gl###before.net':80
- 'he###settle.net':80
- 'he####anguage.net':80
- 'di#####ltlanguage.net':80
- http://or####anguage.net/forum/search.php?em####################################
- http://re####esettle.net/forum/search.php?em####################################
- http://re####elanguage.net/forum/search.php?em####################################
- http://re####edevice.net/forum/search.php?em####################################
- http://or###device.net/forum/search.php?em####################################
- http://or###settle.net/forum/search.php?em####################################
- http://pl####ntdevice.net/forum/search.php?em####################################
- http://ne#####rylanguage.net/forum/search.php?em####################################
- http://ne####arydevice.net/forum/search.php?em####################################
- http://ne####arybefore.net/forum/search.php?em####################################
- http://pl####ntbefore.net/forum/search.php?em####################################
- http://or###before.net/forum/search.php?em####################################
- http://le####before.net/forum/search.php?em####################################
- http://he####device.net/forum/search.php?em####################################
- http://he####before.net/forum/search.php?em####################################
- http://ge####language.net/forum/search.php?em####################################
- http://ge####settle.net/forum/search.php?em####################################
- http://le####device.net/forum/search.php?em####################################
- http://le####settle.net/forum/search.php?em####################################
- http://re####ebefore.net/forum/search.php?em####################################
- http://he####settle.net/forum/search.php?em####################################
- http://he####language.net/forum/search.php?em####################################
- http://le####language.net/forum/search.php?em####################################
- http://pl#####tlanguage.net/forum/search.php?em####################################
- http://an####language.net/forum/search.php?em####################################
- http://gl###settle.net/forum/search.php?em####################################
- http://gl####anguage.net/forum/search.php?em####################################
- http://gl###device.net/forum/search.php?em####################################
- http://an####device.net/forum/search.php?em####################################
- http://an####settle.net/forum/search.php?em####################################
- http://de####device.net/forum/search.php?em####################################
- http://fo####dlanguage.net/forum/search.php?em####################################
- http://fo####ddevice.net/forum/search.php?em####################################
- http://fo####dbefore.net/forum/search.php?em####################################
- http://de####before.net/forum/search.php?em####################################
- http://an####before.net/forum/search.php?em####################################
- http://di####ultbefore.net/forum/search.php?em####################################
- http://he###device.net/forum/search.php?em####################################
- http://he###before.net/forum/search.php?em####################################
- http://ne####arysettle.net/forum/search.php?em####################################
- http://pl####ntsettle.net/forum/search.php?em####################################
- http://di####ultdevice.net/forum/search.php?em####################################
- http://di####ultsettle.net/forum/search.php?em####################################
- http://gl###before.net/forum/search.php?em####################################
- http://he###settle.net/forum/search.php?em####################################
- http://he####anguage.net/forum/search.php?em####################################
- http://di#####ltlanguage.net/forum/search.php?em####################################
- DNS ASK re####elanguage.net
- DNS ASK or####anguage.net
- DNS ASK re####esettle.net
- DNS ASK or###before.net
- DNS ASK re####edevice.net
- DNS ASK or###device.net
- DNS ASK ne####arydevice.net
- DNS ASK pl####ntdevice.net
- DNS ASK ne#####rylanguage.net
- DNS ASK or###settle.net
- DNS ASK ne####arybefore.net
- DNS ASK pl####ntbefore.net
- DNS ASK he####before.net
- DNS ASK le####before.net
- DNS ASK he####device.net
- DNS ASK ge####device.net
- DNS ASK ge####language.net
- DNS ASK ge####settle.net
- DNS ASK he####settle.net
- DNS ASK le####settle.net
- DNS ASK re####ebefore.net
- DNS ASK le####device.net
- DNS ASK he####language.net
- DNS ASK le####language.net
- DNS ASK gl####anguage.net
- DNS ASK an####language.net
- DNS ASK gl###settle.net
- DNS ASK an####before.net
- DNS ASK gl###device.net
- DNS ASK an####device.net
- DNS ASK fo####ddevice.net
- DNS ASK de####device.net
- DNS ASK fo####dlanguage.net
- DNS ASK an####settle.net
- DNS ASK fo####dbefore.net
- DNS ASK de####before.net
- DNS ASK he###before.net
- DNS ASK di####ultbefore.net
- DNS ASK he###device.net
- DNS ASK pl#####tlanguage.net
- DNS ASK ne####arysettle.net
- DNS ASK pl####ntsettle.net
- DNS ASK he###settle.net
- DNS ASK di####ultsettle.net
- DNS ASK gl###before.net
- DNS ASK di####ultdevice.net
- DNS ASK he####anguage.net
- DNS ASK di#####ltlanguage.net
- ClassName: 'Shell_TrayWnd' WindowName: ''
- ClassName: 'Indicator' WindowName: ''