Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Auto Studio AutoConnect Parental' = '<SYSTEM32>\evlxbzcqe.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Spooler Workstation Update Print] 'ImagePath' = '<SYSTEM32>\evlxbzcqe.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Spooler Workstation Update Print] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\hesuzimebu.exe' "<SYSTEM32>\evlxbzcqe.exe"
- '%WINDIR%\Temp\gbjhqp33djnx.exe' -r 42051 tcp
- '%TEMP%\gbjhqp2wi5nxgjzl9b.exe'
- '<SYSTEM32>\evlxbzcqe.exe'
- <SYSTEM32>\zacadsf\run
- <SYSTEM32>\zacadsf\rng
- %WINDIR%\Temp\gbjhqp33djnx.exe
- <SYSTEM32>\zacadsf\cfg
- <SYSTEM32>\hesuzimebu.exe
- %TEMP%\gbjhqp2wi5nxgjzl9b.exe
- <SYSTEM32>\zacadsf\tst
- <SYSTEM32>\evlxbzcqe.exe
- <SYSTEM32>\zacadsf\etc
- <SYSTEM32>\hesuzimebu.exe
- <SYSTEM32>\evlxbzcqe.exe
- %WINDIR%\Temp\gbjhqp33djnx.exe
- <DRIVERS>\etc\hosts
- %TEMP%\gbjhqp2wi5nxgjzl9b.exe
- 'wh###first.net':80
- 'up###uess.net':80
- 'up###irst.net':80
- 'up###ill.net':80
- 'wh###kill.net':80
- 'wh###guess.net':80
- 'sa###ill.net':80
- 'sp###irst.net':80
- 'sp###ill.net':80
- 'sp###tood.net':80
- 'sa###tood.net':80
- 'wh###stood.net':80
- 'so###stood.net':80
- 'ar###kill.net':80
- 'ar###stood.net':80
- 'dr###gold.net':80
- 'wi###old.net':80
- 'so###kill.net':80
- 'so###guess.net':80
- 'up###tood.net':80
- 'ar###guess.net':80
- 'ar###first.net':80
- 'so###first.net':80
- 'sa###irst.net':80
- 'gr###first.net':80
- 'eq###guess.net':80
- 'eq###first.net':80
- 'eq###kill.net':80
- 'gr###kill.net':80
- 'gr###guess.net':80
- 'vi###kill.net':80
- 'sp###first.net':80
- 'sp###kill.net':80
- 'sp###stood.net':80
- 'vi###stood.net':80
- 'gr###stood.net':80
- 'ta###stood.net':80
- 'gl###ill.net':80
- 'gl###tood.net':80
- 'sp###uess.net':80
- 'sa###uess.net':80
- 'ta###kill.net':80
- 'ta###guess.net':80
- 'eq###stood.net':80
- 'gl###uess.net':80
- 'gl###irst.net':80
- 'ta###first.net':80
- 'mo###ver.net':80
- 'ju###ver.net':80
- 'ju###ome.net':80
- 'ri###nstorm.net':80
- 'mo###ome.net':80
- 'mo###rain.net':80
- 'hi###ome.net':80
- 'wh###ome.net':80
- 'ju###old.net':80
- 'ju###rain.net':80
- 'mo###old.net':80
- 'al###being.net':80
- 'cr#####onaraminta.net':80
- 'le###form.net':80
- 'jo####ymeasure.net':80
- 'ef###tbuilt.net':80
- 'th###while.net':80
- 'mo###ugust.net':80
- 'pr####tbottom.net':80
- 'ca####nbring.net':80
- 'mo###olor.net':80
- 'mi###hown.net':80
- 'ab###ell.net':80
- 'hi###ver.net':80
- 'th###grain.net':80
- 'th###gold.net':80
- 'th###over.net':80
- 'lo###old.net':80
- 'th###home.net':80
- 'dr###home.net':80
- 'dr###grain.net':80
- 'wi###rain.net':80
- 'wi###ver.net':80
- 'wi###ome.net':80
- 'dr###over.net':80
- 'fe###old.net':80
- 'hi###old.net':80
- 'wh###old.net':80
- 'wh###rain.net':80
- 'wh###ver.net':80
- 'hi###rain.net':80
- 'fe###ome.net':80
- 'fe###rain.net':80
- 'lo###rain.net':80
- 'lo###ver.net':80
- 'lo###ome.net':80
- 'fe###ver.net':80
- http://wh###first.net/index.php
- http://up###uess.net/index.php
- http://up###irst.net/index.php
- http://up###ill.net/index.php
- http://wh###kill.net/index.php
- http://wh###guess.net/index.php
- http://sa###ill.net/index.php
- http://sp###irst.net/index.php
- http://sp###ill.net/index.php
- http://sp###tood.net/index.php
- http://sa###tood.net/index.php
- http://wh###stood.net/index.php
- http://so###stood.net/index.php
- http://ar###kill.net/index.php
- http://ar###stood.net/index.php
- http://dr###gold.net/index.php
- http://wi###old.net/index.php
- http://so###kill.net/index.php
- http://so###guess.net/index.php
- http://up###tood.net/index.php
- http://ar###guess.net/index.php
- http://ar###first.net/index.php
- http://so###first.net/index.php
- http://sa###irst.net/index.php
- http://gr###first.net/index.php
- http://eq###guess.net/index.php
- http://eq###first.net/index.php
- http://eq###kill.net/index.php
- http://gr###kill.net/index.php
- http://gr###guess.net/index.php
- http://vi###kill.net/index.php
- http://sp###first.net/index.php
- http://sp###kill.net/index.php
- http://sp###stood.net/index.php
- http://vi###stood.net/index.php
- http://gr###stood.net/index.php
- http://ta###stood.net/index.php
- http://gl###ill.net/index.php
- http://gl###tood.net/index.php
- http://sp###uess.net/index.php
- http://sa###uess.net/index.php
- http://ta###kill.net/index.php
- http://ta###guess.net/index.php
- http://eq###stood.net/index.php
- http://gl###uess.net/index.php
- http://gl###irst.net/index.php
- http://ta###first.net/index.php
- http://mo###ver.net/index.php
- http://ju###ver.net/index.php
- http://ju###ome.net/index.php
- http://ri###nstorm.net/index.php
- http://mo###ome.net/index.php
- http://mo###rain.net/index.php
- http://hi###ome.net/index.php
- http://wh###ome.net/index.php
- http://ju###old.net/index.php
- http://ju###rain.net/index.php
- http://mo###old.net/index.php
- http://al###being.net/index.php
- http://cr#####onaraminta.net/index.php
- http://le###form.net/index.php
- http://jo####ymeasure.net/index.php
- http://ef###tbuilt.net/index.php
- http://th###while.net/index.php
- http://mo###ugust.net/index.php
- http://pr####tbottom.net/index.php
- http://ca####nbring.net/index.php
- http://mo###olor.net/index.php
- http://mi###hown.net/index.php
- http://ab###ell.net/index.php
- http://hi###ver.net/index.php
- http://th###grain.net/index.php
- http://th###gold.net/index.php
- http://th###over.net/index.php
- http://lo###old.net/index.php
- http://th###home.net/index.php
- http://dr###home.net/index.php
- http://dr###grain.net/index.php
- http://wi###rain.net/index.php
- http://wi###ver.net/index.php
- http://wi###ome.net/index.php
- http://dr###over.net/index.php
- http://fe###old.net/index.php
- http://hi###old.net/index.php
- http://wh###old.net/index.php
- http://wh###rain.net/index.php
- http://wh###ver.net/index.php
- http://hi###rain.net/index.php
- http://fe###ome.net/index.php
- http://fe###rain.net/index.php
- http://lo###rain.net/index.php
- http://lo###ver.net/index.php
- http://lo###ome.net/index.php
- http://fe###ver.net/index.php
- DNS ASK wh###first.net
- DNS ASK up###uess.net
- DNS ASK up###irst.net
- DNS ASK up###ill.net
- DNS ASK wh###kill.net
- DNS ASK wh###guess.net
- DNS ASK sa###ill.net
- DNS ASK sp###irst.net
- DNS ASK sp###ill.net
- DNS ASK sp###tood.net
- DNS ASK sa###tood.net
- DNS ASK wh###stood.net
- DNS ASK so###stood.net
- DNS ASK ar###kill.net
- DNS ASK ar###stood.net
- DNS ASK dr###gold.net
- DNS ASK wi###old.net
- DNS ASK so###kill.net
- DNS ASK so###guess.net
- DNS ASK up###tood.net
- DNS ASK ar###guess.net
- DNS ASK ar###first.net
- DNS ASK so###first.net
- DNS ASK sa###irst.net
- DNS ASK gr###first.net
- DNS ASK eq###guess.net
- DNS ASK eq###first.net
- DNS ASK eq###kill.net
- DNS ASK gr###kill.net
- DNS ASK gr###guess.net
- DNS ASK vi###kill.net
- DNS ASK sp###first.net
- DNS ASK sp###kill.net
- DNS ASK sp###stood.net
- DNS ASK vi###stood.net
- DNS ASK gr###stood.net
- DNS ASK ta###stood.net
- DNS ASK gl###ill.net
- DNS ASK gl###tood.net
- DNS ASK sp###uess.net
- DNS ASK sa###uess.net
- DNS ASK ta###kill.net
- DNS ASK ta###guess.net
- DNS ASK eq###stood.net
- DNS ASK gl###uess.net
- DNS ASK gl###irst.net
- DNS ASK ta###first.net
- DNS ASK wi###rain.net
- DNS ASK mo###ver.net
- DNS ASK ju###ver.net
- DNS ASK ju###ome.net
- DNS ASK ri###nstorm.net
- DNS ASK mo###ome.net
- DNS ASK mo###rain.net
- DNS ASK hi###ome.net
- DNS ASK wh###ome.net
- DNS ASK ju###old.net
- DNS ASK ju###rain.net
- DNS ASK mo###old.net
- DNS ASK al###being.net
- DNS ASK cr#####onaraminta.net
- DNS ASK le###form.net
- DNS ASK jo####ymeasure.net
- DNS ASK ef###tbuilt.net
- DNS ASK th###while.net
- DNS ASK mo###ugust.net
- DNS ASK pr####tbottom.net
- DNS ASK ca####nbring.net
- DNS ASK mo###olor.net
- DNS ASK mi###hown.net
- DNS ASK ab###ell.net
- DNS ASK th###over.net
- DNS ASK th###grain.net
- DNS ASK th###home.net
- DNS ASK fe###old.net
- DNS ASK lo###old.net
- DNS ASK th###gold.net
- DNS ASK wi###ver.net
- DNS ASK dr###grain.net
- DNS ASK dr###over.net
- DNS ASK dr###home.net
- DNS ASK wi###ome.net
- DNS ASK lo###rain.net
- DNS ASK wh###rain.net
- DNS ASK hi###old.net
- DNS ASK hi###rain.net
- DNS ASK hi###ver.net
- DNS ASK wh###ver.net
- DNS ASK wh###old.net
- DNS ASK lo###ver.net
- DNS ASK fe###rain.net
- DNS ASK fe###ver.net
- DNS ASK fe###ome.net
- DNS ASK lo###ome.net
- '23#.#55.255.250':1900