Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Logon Background Registrar Function iSCSI' = 'C:\hsqhwotljeuwtx\wvghhbtbs.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Profile Firewall Device Link Connect Human Card] 'ImagePath' = 'C:\hsqhwotljeuwtx\wvghhbtbs.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Profile Firewall Device Link Connect Human Card] 'Start' = '00000002'
- 'C:\hsqhwotljeuwtx\hboajlu.exe' "c:\hsqhwotljeuwtx\wvghhbtbs.exe"
- 'C:\hsqhwotljeuwtx\wvghhbtbs.exe'
- 'C:\hsqhwotljeuwtx\wywq2322odhatc5uij.exe'
- C:\hsqhwotljeuwtx\wvghhbtbs.exe
- C:\hsqhwotljeuwtx\hboajlu.exe
- C:\hsqhwotljeuwtx\wywq2322odhatc5uij.exe
- %WINDIR%\hsqhwotljeuwtx\ikhtgj5teaz
- C:\hsqhwotljeuwtx\ikhtgj5teaz
- C:\hsqhwotljeuwtx\hboajlu.exe
- C:\hsqhwotljeuwtx\wvghhbtbs.exe
- C:\hsqhwotljeuwtx\wywq2322odhatc5uij.exe
- %WINDIR%\hsqhwotljeuwtx\ikhtgj5teaz
- 'st####kitchen.net':80
- 'tr####ithout.net':80
- 'st####probable.net':80
- 'tr####itchen.net':80
- 'st###twagon.net':80
- 'el#####cprobable.net':80
- 'st####without.net':80
- 'tr###wagon.net':80
- 'be####kitchen.net':80
- 'ga####without.net':80
- 'be####probable.net':80
- 'ga####kitchen.net':80
- 'be###rwagon.net':80
- 'tr####robable.net':80
- 'be####without.net':80
- 'ga###rwagon.net':80
- 're####probable.net':80
- 'ca####nwithout.net':80
- 'la####ithout.net':80
- 'ca####nkitchen.net':80
- 'la####itchen.net':80
- 'de####probable.net':80
- 'ni####robable.net':80
- 'ca####nwagon.net':80
- 'la###wagon.net':80
- 'el####icwithout.net':80
- 're####without.net':80
- 'el####ickitchen.net':80
- 're####kitchen.net':80
- 'ca####nprobable.net':80
- 'la####robable.net':80
- 'el####icwagon.net':80
- 're###dwagon.net':80
- http://st####kitchen.net/index.php
- http://tr####ithout.net/index.php
- http://st####probable.net/index.php
- http://tr####itchen.net/index.php
- http://st###twagon.net/index.php
- http://el#####cprobable.net/index.php
- http://st####without.net/index.php
- http://tr###wagon.net/index.php
- http://be####kitchen.net/index.php
- http://ga####without.net/index.php
- http://be####probable.net/index.php
- http://ga####kitchen.net/index.php
- http://be###rwagon.net/index.php
- http://tr####robable.net/index.php
- http://be####without.net/index.php
- http://ga###rwagon.net/index.php
- http://re####probable.net/index.php
- http://ca####nwithout.net/index.php
- http://la####ithout.net/index.php
- http://ca####nkitchen.net/index.php
- http://la####itchen.net/index.php
- http://de####probable.net/index.php
- http://ni####robable.net/index.php
- http://ca####nwagon.net/index.php
- http://la###wagon.net/index.php
- http://el####icwithout.net/index.php
- http://re####without.net/index.php
- http://el####ickitchen.net/index.php
- http://re####kitchen.net/index.php
- http://ca####nprobable.net/index.php
- http://la####robable.net/index.php
- http://el####icwagon.net/index.php
- http://re###dwagon.net/index.php
- DNS ASK st####kitchen.net
- DNS ASK tr####ithout.net
- DNS ASK st####probable.net
- DNS ASK tr####itchen.net
- DNS ASK st###twagon.net
- DNS ASK el#####cprobable.net
- DNS ASK st####without.net
- DNS ASK tr###wagon.net
- DNS ASK tr####robable.net
- DNS ASK ga####kitchen.net
- DNS ASK be####kitchen.net
- DNS ASK ga####probable.net
- DNS ASK be####probable.net
- DNS ASK ga###rwagon.net
- DNS ASK be###rwagon.net
- DNS ASK ga####without.net
- DNS ASK be####without.net
- DNS ASK ca####nwithout.net
- DNS ASK la####ithout.net
- DNS ASK ca####nkitchen.net
- DNS ASK la####itchen.net
- DNS ASK de####probable.net
- DNS ASK ni####robable.net
- DNS ASK ca####nwagon.net
- DNS ASK la###wagon.net
- DNS ASK la####robable.net
- DNS ASK re####kitchen.net
- DNS ASK el####icwithout.net
- DNS ASK re####probable.net
- DNS ASK el####ickitchen.net
- DNS ASK re###dwagon.net
- DNS ASK ca####nprobable.net
- DNS ASK re####without.net
- DNS ASK el####icwagon.net
- ClassName: 'Shell_TrayWnd' WindowName: ''