Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'PC Logon DHCP Debugger Thread Isolation Config' = 'C:\bzlczlqc\jrgmmcvie.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Play Background Virtual] 'Start' = '00000002'
- 'C:\bzlczlqc\xjxzmtbsnvt.exe' "c:\bzlczlqc\jrgmmcvie.exe"
- 'C:\bzlczlqc\jrgmmcvie.exe'
- 'C:\bzlczlqc\wp2m40xxixsstjf.exe'
- C:\bzlczlqc\jrgmmcvie.exe
- C:\bzlczlqc\xjxzmtbsnvt.exe
- C:\bzlczlqc\fvamcuspq
- %WINDIR%\bzlczlqc\o6gtkxt
- C:\bzlczlqc\o6gtkxt
- C:\bzlczlqc\wp2m40xxixsstjf.exe
- C:\bzlczlqc\xjxzmtbsnvt.exe
- C:\bzlczlqc\jrgmmcvie.exe
- C:\bzlczlqc\wp2m40xxixsstjf.exe
- %WINDIR%\bzlczlqc\o6gtkxt
- 'co####eindeed.net':80
- 'ch###during.net':80
- 'co####enotice.net':80
- 'ch###indeed.net':80
- 'al###length.net':80
- 'of###notice.net':80
- 'co####eduring.net':80
- 'of###length.net':80
- 'ch###notice.net':80
- 'th###indeed.net':80
- 'pr####tindeed.net':80
- 'th###notice.net':80
- 'pr####tnotice.net':80
- 'ch###length.net':80
- 'co####elength.net':80
- 'th###during.net':80
- 'pr####tduring.net':80
- 'mi####during.net':80
- 'tw####during.net':80
- 'mi####indeed.net':80
- 'tw####indeed.net':80
- 'ra####notice.net':80
- 'mo####gnotice.net':80
- 'ra####length.net':80
- 'mo####glength.net':80
- 'tw####notice.net':80
- 'al###indeed.net':80
- 'of###during.net':80
- 'al###notice.net':80
- 'of###indeed.net':80
- 'tw####length.net':80
- 'mi####notice.net':80
- 'al###during.net':80
- 'mi####length.net':80
- 'ga####eearly.net':80
- 'be####public.net':80
- 'ga###rcatch.net':80
- 'be####eearly.net':80
- 'ga###rdress.net':80
- 'fl###catch.net':80
- 'ga####public.net':80
- 'be###rdress.net':80
- 'be###rcatch.net':80
- 'st####eearly.net':80
- 'tr###eearly.net':80
- 'st###tcatch.net':80
- 'tr###catch.net':80
- 'st###tdress.net':80
- 'tr###dress.net':80
- 'st####public.net':80
- 'tr###public.net':80
- 'qu###public.net':80
- 'se####public.net':80
- 'qu###eearly.net':80
- 'se####eearly.net':80
- 'th###length.net':80
- 'pr####tlength.net':80
- 'qu###dress.net':80
- 'se###ndress.net':80
- 'se###ncatch.net':80
- 'br###eearly.net':80
- 'fl###public.net':80
- 'br###catch.net':80
- 'fl###eearly.net':80
- 'br###dress.net':80
- 'qu###catch.net':80
- 'br###public.net':80
- 'fl###dress.net':80
- http://co####eindeed.net/index.php?me########
- http://ch###during.net/index.php?me########
- http://co####enotice.net/index.php?me########
- http://ch###indeed.net/index.php?me########
- http://al###length.net/index.php?me########
- http://of###notice.net/index.php?me########
- http://co####eduring.net/index.php?me########
- http://of###length.net/index.php?me########
- http://ch###notice.net/index.php?me########
- http://th###indeed.net/index.php?me########
- http://pr####tindeed.net/index.php?me########
- http://th###notice.net/index.php?me########
- http://pr####tnotice.net/index.php?me########
- http://ch###length.net/index.php?me########
- http://co####elength.net/index.php?me########
- http://th###during.net/index.php?me########
- http://pr####tduring.net/index.php?me########
- http://mi####during.net/index.php?me########
- http://tw####during.net/index.php?me########
- http://mi####indeed.net/index.php?me########
- http://tw####indeed.net/index.php?me########
- http://ra####notice.net/index.php?me########
- http://mo####gnotice.net/index.php?me########
- http://ra####length.net/index.php?me########
- http://mo####glength.net/index.php?me########
- http://tw####notice.net/index.php?me########
- http://al###indeed.net/index.php?me########
- http://of###during.net/index.php?me########
- http://al###notice.net/index.php?me########
- http://of###indeed.net/index.php?me########
- http://tw####length.net/index.php?me########
- http://mi####notice.net/index.php?me########
- http://al###during.net/index.php?me########
- http://mi####length.net/index.php?me########
- http://ga####eearly.net/index.php?me########
- http://be####public.net/index.php?me########
- http://ga###rcatch.net/index.php?me########
- http://be####eearly.net/index.php?me########
- http://ga###rdress.net/index.php?me########
- http://fl###catch.net/index.php?me########
- http://ga####public.net/index.php?me########
- http://be###rdress.net/index.php?me########
- http://be###rcatch.net/index.php?me########
- http://st####eearly.net/index.php?me########
- http://tr###eearly.net/index.php?me########
- http://st###tcatch.net/index.php?me########
- http://tr###catch.net/index.php?me########
- http://st###tdress.net/index.php?me########
- http://tr###dress.net/index.php?me########
- http://st####public.net/index.php?me########
- http://tr###public.net/index.php?me########
- http://qu###public.net/index.php?me########
- http://se####public.net/index.php?me########
- http://qu###eearly.net/index.php?me########
- http://se####eearly.net/index.php?me########
- http://th###length.net/index.php?me########
- http://pr####tlength.net/index.php?me########
- http://qu###dress.net/index.php?me########
- http://se###ndress.net/index.php?me########
- http://se###ncatch.net/index.php?me########
- http://br###eearly.net/index.php?me########
- http://fl###public.net/index.php?me########
- http://br###catch.net/index.php?me########
- http://fl###eearly.net/index.php?me########
- http://br###dress.net/index.php?me########
- http://qu###catch.net/index.php?me########
- http://br###public.net/index.php?me########
- http://fl###dress.net/index.php?me########
- DNS ASK ch###during.net
- DNS ASK co####eduring.net
- DNS ASK ch###indeed.net
- DNS ASK co####eindeed.net
- DNS ASK of###notice.net
- DNS ASK al###notice.net
- DNS ASK of###length.net
- DNS ASK al###length.net
- DNS ASK co####enotice.net
- DNS ASK pr####tindeed.net
- DNS ASK th###during.net
- DNS ASK pr####tnotice.net
- DNS ASK th###indeed.net
- DNS ASK co####elength.net
- DNS ASK ch###notice.net
- DNS ASK pr####tduring.net
- DNS ASK ch###length.net
- DNS ASK tw####during.net
- DNS ASK ra####length.net
- DNS ASK tw####indeed.net
- DNS ASK mi####during.net
- DNS ASK mo####gnotice.net
- DNS ASK ra####indeed.net
- DNS ASK mo####glength.net
- DNS ASK ra####notice.net
- DNS ASK mi####indeed.net
- DNS ASK of###during.net
- DNS ASK al###during.net
- DNS ASK of###indeed.net
- DNS ASK al###indeed.net
- DNS ASK mi####notice.net
- DNS ASK tw####notice.net
- DNS ASK mi####length.net
- DNS ASK tw####length.net
- DNS ASK th###notice.net
- DNS ASK ga####eearly.net
- DNS ASK be####public.net
- DNS ASK ga###rcatch.net
- DNS ASK be####eearly.net
- DNS ASK ga###rdress.net
- DNS ASK fl###catch.net
- DNS ASK ga####public.net
- DNS ASK be###rdress.net
- DNS ASK be###rcatch.net
- DNS ASK st####eearly.net
- DNS ASK tr###eearly.net
- DNS ASK st###tcatch.net
- DNS ASK tr###catch.net
- DNS ASK st###tdress.net
- DNS ASK tr###dress.net
- DNS ASK st####public.net
- DNS ASK tr###public.net
- DNS ASK qu###public.net
- DNS ASK se####public.net
- DNS ASK qu###eearly.net
- DNS ASK se####eearly.net
- DNS ASK th###length.net
- DNS ASK pr####tlength.net
- DNS ASK qu###dress.net
- DNS ASK se###ndress.net
- DNS ASK se###ncatch.net
- DNS ASK br###eearly.net
- DNS ASK fl###public.net
- DNS ASK br###catch.net
- DNS ASK fl###eearly.net
- DNS ASK br###dress.net
- DNS ASK qu###catch.net
- DNS ASK br###public.net
- DNS ASK fl###dress.net
- ClassName: 'Shell_TrayWnd' WindowName: ''