Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Tools Grouping Now Cache Block' = 'C:\swoxnrlefyfrj\qonblkvftb.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Connectivity Manager Tablet Volume] 'ImagePath' = 'C:\swoxnrlefyfrj\qonblkvftb.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Connectivity Manager Tablet Volume] 'Start' = '00000002'
- 'C:\swoxnrlefyfrj\keikbpuuncil.exe' "c:\swoxnrlefyfrj\qonblkvftb.exe"
- 'C:\swoxnrlefyfrj\qonblkvftb.exe'
- 'C:\swoxnrlefyfrj\djnpl2i1bcnuvcrwcpkgm.exe'
- C:\swoxnrlefyfrj\qonblkvftb.exe
- C:\swoxnrlefyfrj\keikbpuuncil.exe
- C:\swoxnrlefyfrj\npkp6r
- %WINDIR%\swoxnrlefyfrj\jtmezysopaj
- C:\swoxnrlefyfrj\jtmezysopaj
- C:\swoxnrlefyfrj\djnpl2i1bcnuvcrwcpkgm.exe
- C:\swoxnrlefyfrj\keikbpuuncil.exe
- C:\swoxnrlefyfrj\qonblkvftb.exe
- C:\swoxnrlefyfrj\djnpl2i1bcnuvcrwcpkgm.exe
- %WINDIR%\swoxnrlefyfrj\jtmezysopaj
- 'ni###afraid.net':80
- 'de####afraid.net':80
- 'de####dinner.net':80
- 'de####measure.net':80
- 'ni###dinner.net':80
- 'ca####nmeasure.net':80
- 'la###dinner.net':80
- 'la####easure.net':80
- 'ni###circle.net':80
- 'de####circle.net':80
- 'ni####easure.net':80
- 'do####easure.net':80
- 'ag####tdinner.net':80
- 'ag####tmeasure.net':80
- 'qu###carry.net':80
- 'se###ncarry.net':80
- 'ag####tcircle.net':80
- 'do###circle.net':80
- 'do###afraid.net':80
- 'do###dinner.net':80
- 'ag####tafraid.net':80
- 'tr####easure.net':80
- 'st####dinner.net':80
- 'st####measure.net':80
- 're####circle.net':80
- 'el####iccircle.net':80
- 'st####circle.net':80
- 'tr###circle.net':80
- 'tr###afraid.net':80
- 'tr###dinner.net':80
- 'st####afraid.net':80
- 'el####icafraid.net':80
- 'la###circle.net':80
- 'ca####ncircle.net':80
- 'ca####nafraid.net':80
- 'ca####ndinner.net':80
- 'la###afraid.net':80
- 'el####icdinner.net':80
- 're####afraid.net':80
- 're####dinner.net':80
- 're####measure.net':80
- 'el####icmeasure.net':80
- 'se###nbuilt.net':80
- 'tr###father.net':80
- 'st###tapple.net':80
- 'st####father.net':80
- 're###dcarry.net':80
- 'el####iccarry.net':80
- 'st###tcarry.net':80
- 'tr###carry.net':80
- 'tr###built.net':80
- 'tr###apple.net':80
- 'st###tbuilt.net':80
- 'el####icbuilt.net':80
- 'la###carry.net':80
- 'ca####ncarry.net':80
- 'ca####nbuilt.net':80
- 'ca####napple.net':80
- 'la###built.net':80
- 'el####icapple.net':80
- 're###dbuilt.net':80
- 're###dapple.net':80
- 're####father.net':80
- 'el####icfather.net':80
- 'fl###carry.net':80
- 'br###carry.net':80
- 'br###built.net':80
- 'br###apple.net':80
- 'fl###built.net':80
- 'se###napple.net':80
- 'qu###built.net':80
- 'qu###apple.net':80
- 'qu###father.net':80
- 'se####father.net':80
- 'fl###apple.net':80
- 'ga###rapple.net':80
- 'be###rbuilt.net':80
- 'be###rapple.net':80
- 'be####father.net':80
- 'ga####father.net':80
- 'fl###father.net':80
- 'br###father.net':80
- 'ga###rcarry.net':80
- 'ga###rbuilt.net':80
- 'be###rcarry.net':80
- http://ni###afraid.net/index.php
- http://de####afraid.net/index.php
- http://de####dinner.net/index.php
- http://de####measure.net/index.php
- http://ni###dinner.net/index.php
- http://ca####nmeasure.net/index.php
- http://la###dinner.net/index.php
- http://la####easure.net/index.php
- http://ni###circle.net/index.php
- http://de####circle.net/index.php
- http://ni####easure.net/index.php
- http://do####easure.net/index.php
- http://ag####tdinner.net/index.php
- http://ag####tmeasure.net/index.php
- http://qu###carry.net/index.php
- http://se###ncarry.net/index.php
- http://ag####tcircle.net/index.php
- http://do###circle.net/index.php
- http://do###afraid.net/index.php
- http://do###dinner.net/index.php
- http://ag####tafraid.net/index.php
- http://tr####easure.net/index.php
- http://st####dinner.net/index.php
- http://st####measure.net/index.php
- http://re####circle.net/index.php
- http://el####iccircle.net/index.php
- http://st####circle.net/index.php
- http://tr###circle.net/index.php
- http://tr###afraid.net/index.php
- http://tr###dinner.net/index.php
- http://st####afraid.net/index.php
- http://el####icafraid.net/index.php
- http://la###circle.net/index.php
- http://ca####ncircle.net/index.php
- http://ca####nafraid.net/index.php
- http://ca####ndinner.net/index.php
- http://la###afraid.net/index.php
- http://el####icdinner.net/index.php
- http://re####afraid.net/index.php
- http://re####dinner.net/index.php
- http://re####measure.net/index.php
- http://el####icmeasure.net/index.php
- http://se###nbuilt.net/index.php
- http://tr###father.net/index.php
- http://st###tapple.net/index.php
- http://st####father.net/index.php
- http://re###dcarry.net/index.php
- http://el####iccarry.net/index.php
- http://st###tcarry.net/index.php
- http://tr###carry.net/index.php
- http://tr###built.net/index.php
- http://tr###apple.net/index.php
- http://st###tbuilt.net/index.php
- http://el####icbuilt.net/index.php
- http://la###carry.net/index.php
- http://ca####ncarry.net/index.php
- http://ca####nbuilt.net/index.php
- http://ca####napple.net/index.php
- http://la###built.net/index.php
- http://el####icapple.net/index.php
- http://re###dbuilt.net/index.php
- http://re###dapple.net/index.php
- http://re####father.net/index.php
- http://el####icfather.net/index.php
- http://fl###carry.net/index.php
- http://br###carry.net/index.php
- http://br###built.net/index.php
- http://br###apple.net/index.php
- http://fl###built.net/index.php
- http://se###napple.net/index.php
- http://qu###built.net/index.php
- http://qu###apple.net/index.php
- http://qu###father.net/index.php
- http://se####father.net/index.php
- http://fl###apple.net/index.php
- http://ga###rapple.net/index.php
- http://be###rbuilt.net/index.php
- http://be###rapple.net/index.php
- http://be####father.net/index.php
- http://ga####father.net/index.php
- http://fl###father.net/index.php
- http://br###father.net/index.php
- http://ga###rcarry.net/index.php
- http://ga###rbuilt.net/index.php
- http://be###rcarry.net/index.php
- DNS ASK ni###afraid.net
- DNS ASK de####afraid.net
- DNS ASK de####dinner.net
- DNS ASK de####measure.net
- DNS ASK ni###dinner.net
- DNS ASK ca####nmeasure.net
- DNS ASK la###dinner.net
- DNS ASK la####easure.net
- DNS ASK ni###circle.net
- DNS ASK de####circle.net
- DNS ASK ni####easure.net
- DNS ASK do####easure.net
- DNS ASK ag####tdinner.net
- DNS ASK ag####tmeasure.net
- DNS ASK qu###carry.net
- DNS ASK se###ncarry.net
- DNS ASK ag####tcircle.net
- DNS ASK do###circle.net
- DNS ASK do###afraid.net
- DNS ASK do###dinner.net
- DNS ASK ag####tafraid.net
- DNS ASK tr####easure.net
- DNS ASK st####dinner.net
- DNS ASK st####measure.net
- DNS ASK re####circle.net
- DNS ASK el####iccircle.net
- DNS ASK st####circle.net
- DNS ASK tr###circle.net
- DNS ASK tr###afraid.net
- DNS ASK tr###dinner.net
- DNS ASK st####afraid.net
- DNS ASK el####icafraid.net
- DNS ASK la###circle.net
- DNS ASK ca####ncircle.net
- DNS ASK ca####nafraid.net
- DNS ASK ca####ndinner.net
- DNS ASK la###afraid.net
- DNS ASK el####icdinner.net
- DNS ASK re####afraid.net
- DNS ASK re####dinner.net
- DNS ASK re####measure.net
- DNS ASK el####icmeasure.net
- DNS ASK se###nbuilt.net
- DNS ASK tr###father.net
- DNS ASK st###tapple.net
- DNS ASK st####father.net
- DNS ASK re###dcarry.net
- DNS ASK el####iccarry.net
- DNS ASK st###tcarry.net
- DNS ASK tr###carry.net
- DNS ASK tr###built.net
- DNS ASK tr###apple.net
- DNS ASK st###tbuilt.net
- DNS ASK el####icbuilt.net
- DNS ASK la###carry.net
- DNS ASK ca####ncarry.net
- DNS ASK ca####nbuilt.net
- DNS ASK ca####napple.net
- DNS ASK la###built.net
- DNS ASK el####icapple.net
- DNS ASK re###dbuilt.net
- DNS ASK re###dapple.net
- DNS ASK re####father.net
- DNS ASK el####icfather.net
- DNS ASK fl###carry.net
- DNS ASK br###carry.net
- DNS ASK br###built.net
- DNS ASK br###apple.net
- DNS ASK fl###built.net
- DNS ASK se###napple.net
- DNS ASK qu###built.net
- DNS ASK qu###apple.net
- DNS ASK qu###father.net
- DNS ASK se####father.net
- DNS ASK fl###apple.net
- DNS ASK ga###rapple.net
- DNS ASK be###rbuilt.net
- DNS ASK be###rapple.net
- DNS ASK be####father.net
- DNS ASK ga####father.net
- DNS ASK fl###father.net
- DNS ASK br###father.net
- DNS ASK ga###rcarry.net
- DNS ASK ga###rbuilt.net
- DNS ASK be###rcarry.net
- ClassName: 'Shell_TrayWnd' WindowName: ''