Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Media Modules Net.Tcp Themes Protection Level' = 'C:\wkxsmzs\vdvqkkqog.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\DHCP DLL Machine Logs Problem] 'ImagePath' = 'C:\wkxsmzs\vdvqkkqog.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\DHCP DLL Machine Logs Problem] 'Start' = '00000002'
- 'C:\wkxsmzs\kmoxxlc.exe' "c:\wkxsmzs\vdvqkkqog.exe"
- 'C:\wkxsmzs\vdvqkkqog.exe'
- 'C:\wkxsmzs\yw2lzowshjleq4iy.exe'
- C:\wkxsmzs\vdvqkkqog.exe
- C:\wkxsmzs\kmoxxlc.exe
- C:\wkxsmzs\bi9ggos
- %WINDIR%\wkxsmzs\btas9q6on1v
- C:\wkxsmzs\btas9q6on1v
- C:\wkxsmzs\yw2lzowshjleq4iy.exe
- C:\wkxsmzs\kmoxxlc.exe
- C:\wkxsmzs\vdvqkkqog.exe
- C:\wkxsmzs\yw2lzowshjleq4iy.exe
- %WINDIR%\wkxsmzs\btas9q6on1v
- 'st####settle.net':80
- 'el####icbefore.net':80
- 'tr###settle.net':80
- 'tr####anguage.net':80
- 'st####language.net':80
- 'el#####clanguage.net':80
- 're####language.net':80
- 're####device.net':80
- 're####before.net':80
- 'el####icdevice.net':80
- 'st####device.net':80
- 'ga####language.net':80
- 'be####language.net':80
- 'be####device.net':80
- 'be####before.net':80
- 'ga####device.net':80
- 'st####before.net':80
- 'tr###device.net':80
- 'tr###before.net':80
- 'ga####settle.net':80
- 'be####settle.net':80
- 'de####language.net':80
- 'ni####anguage.net':80
- 'ni###device.net':80
- 'ni###before.net':80
- 'de####device.net':80
- 'ag####tbefore.net':80
- 'do###device.net':80
- 'do###before.net':80
- 'de####settle.net':80
- 'ni###settle.net':80
- 'de####before.net':80
- 'la###before.net':80
- 'ca####ndevice.net':80
- 'ca####nbefore.net':80
- 'el####icsettle.net':80
- 're####settle.net':80
- 'ca####nsettle.net':80
- 'la###settle.net':80
- 'la####anguage.net':80
- 'la###device.net':80
- 'ca####nlanguage.net':80
- http://st####settle.net/index.php
- http://el####icbefore.net/index.php
- http://tr###settle.net/index.php
- http://tr####anguage.net/index.php
- http://st####language.net/index.php
- http://el#####clanguage.net/index.php
- http://re####language.net/index.php
- http://re####device.net/index.php
- http://re####before.net/index.php
- http://el####icdevice.net/index.php
- http://st####device.net/index.php
- http://ga####language.net/index.php
- http://be####language.net/index.php
- http://be####device.net/index.php
- http://be####before.net/index.php
- http://ga####device.net/index.php
- http://st####before.net/index.php
- http://tr###device.net/index.php
- http://tr###before.net/index.php
- http://ga####settle.net/index.php
- http://be####settle.net/index.php
- http://de####language.net/index.php
- http://ni####anguage.net/index.php
- http://ni###device.net/index.php
- http://ni###before.net/index.php
- http://de####device.net/index.php
- http://ag####tbefore.net/index.php
- http://do###device.net/index.php
- http://do###before.net/index.php
- http://de####settle.net/index.php
- http://ni###settle.net/index.php
- http://de####before.net/index.php
- http://la###before.net/index.php
- http://ca####ndevice.net/index.php
- http://ca####nbefore.net/index.php
- http://el####icsettle.net/index.php
- http://re####settle.net/index.php
- http://ca####nsettle.net/index.php
- http://la###settle.net/index.php
- http://la####anguage.net/index.php
- http://la###device.net/index.php
- http://ca####nlanguage.net/index.php
- DNS ASK tr###settle.net
- DNS ASK st####settle.net
- DNS ASK st####language.net
- DNS ASK st####device.net
- DNS ASK tr####anguage.net
- DNS ASK re####device.net
- DNS ASK el#####clanguage.net
- DNS ASK el####icdevice.net
- DNS ASK el####icbefore.net
- DNS ASK re####before.net
- DNS ASK tr###device.net
- DNS ASK be####device.net
- DNS ASK ga####language.net
- DNS ASK ga####device.net
- DNS ASK ga####before.net
- DNS ASK be####before.net
- DNS ASK tr###before.net
- DNS ASK st####before.net
- DNS ASK be####settle.net
- DNS ASK be####language.net
- DNS ASK ga####settle.net
- DNS ASK re####language.net
- DNS ASK de####language.net
- DNS ASK ni####anguage.net
- DNS ASK ni###device.net
- DNS ASK ni###before.net
- DNS ASK de####device.net
- DNS ASK ag####tbefore.net
- DNS ASK do###device.net
- DNS ASK do###before.net
- DNS ASK de####settle.net
- DNS ASK ni###settle.net
- DNS ASK de####before.net
- DNS ASK la###before.net
- DNS ASK ca####ndevice.net
- DNS ASK ca####nbefore.net
- DNS ASK el####icsettle.net
- DNS ASK re####settle.net
- DNS ASK ca####nsettle.net
- DNS ASK la###settle.net
- DNS ASK la####anguage.net
- DNS ASK la###device.net
- DNS ASK ca####nlanguage.net
- ClassName: 'Shell_TrayWnd' WindowName: ''