Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Health Policy Adapter Framework' = 'C:\yzueukneh\uehzov6z.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Spooler Transfer AutoConnect Removal Registry] 'ImagePath' = 'C:\yzueukneh\uehzov6z.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Spooler Transfer AutoConnect Removal Registry] 'Start' = '00000002'
- 'C:\yzueukneh\ycltz1evxt9.exe' "c:\yzueukneh\uehzov6z.exe"
- 'C:\yzueukneh\uehzov6z.exe'
- 'C:\yzueukneh\uc248j9n3743xhzmc7d0g.exe'
- C:\yzueukneh\uehzov6z.exe
- C:\yzueukneh\ycltz1evxt9.exe
- C:\yzueukneh\egrrcjht
- %WINDIR%\yzueukneh\whoqxz
- C:\yzueukneh\whoqxz
- C:\yzueukneh\uc248j9n3743xhzmc7d0g.exe
- C:\yzueukneh\ycltz1evxt9.exe
- C:\yzueukneh\uehzov6z.exe
- C:\yzueukneh\uc248j9n3743xhzmc7d0g.exe
- %WINDIR%\yzueukneh\whoqxz
- %WINDIR%\yzueukneh\whoqxz
- 'ch#####neshaquila.net':80
- 'sh#####leshaquila.net':80
- 'ch#####nemarcelyn.net':80
- 'sh#####lemarcelyn.net':80
- 'ch#####nekristeen.net':80
- 'sh#####lekristeen.net':80
- 'ch#####necallahan.net':80
- 'sh#####lecallahan.net':80
- 'ce#####nekristeen.net':80
- 'ce#####nemarcelyn.net':80
- 'am#####neshaquila.net':80
- 'al#####rakristeen.net':80
- 'am#####nemarcelyn.net':80
- 'ce#####necallahan.net':80
- 'am#####nekristeen.net':80
- 'ce#####neshaquila.net':80
- 'am#####necallahan.net':80
- 'ar#####ldmarcelyn.net':80
- 'ge#####nacallahan.net':80
- 'ch#####lecallahan.net':80
- 'ge#####nashaquila.net':80
- 'ch#####leshaquila.net':80
- 'an#####lemarcelyn.net':80
- 'gu#####enmarcelyn.net':80
- 'ge#####nakristeen.net':80
- 'ch#####lekristeen.net':80
- 'ch#####lemarcelyn.net':80
- 'za#####ahshaquila.net':80
- 'ar#####ldcallahan.net':80
- 'za#####ahmarcelyn.net':80
- 'ar#####ldshaquila.net':80
- 'za#####ahkristeen.net':80
- 'ge#####namarcelyn.net':80
- 'za#####ahcallahan.net':80
- 'ar#####ldkristeen.net':80
- 'gu#####encheyenne.net':80
- 'gw#####resymphony.net':80
- 'gu#####enbradford.net':80
- 'an#####lecheyenne.net':80
- 'ch#####ankiersten.net':80
- 'gw#####rebradford.net':80
- 'ch#####ansymphony.net':80
- 'gw#####rekiersten.net':80
- 'an#####lebradford.net':80
- 'ge#####nacheyenne.net':80
- 'ch#####lecheyenne.net':80
- 'ge#####nabradford.net':80
- 'ch#####lebradford.net':80
- 'an#####lekiersten.net':80
- 'gu#####enkiersten.net':80
- 'an#####lesymphony.net':80
- 'gu#####ensymphony.net':80
- 'ch#####anbradford.net':80
- 'al#####ramarcelyn.net':80
- 'ma#####nashaquila.net':80
- 'al#####erkristeen.net':80
- 'ma#####namarcelyn.net':80
- 'al#####racallahan.net':80
- 'ma#####nakristeen.net':80
- 'al#####rashaquila.net':80
- 'ma#####nacallahan.net':80
- 'ka#####nekristeen.net':80
- 'ka#####nemarcelyn.net':80
- 'al#####ermarcelyn.net':80
- 'gw#####recheyenne.net':80
- 'ch#####ancheyenne.net':80
- 'ka#####necallahan.net':80
- 'al#####ercallahan.net':80
- 'ka#####neshaquila.net':80
- 'al#####ershaquila.net':80
- http://ch#####neshaquila.net/index.php
- http://sh#####leshaquila.net/index.php
- http://ch#####nemarcelyn.net/index.php
- http://sh#####lemarcelyn.net/index.php
- http://ch#####nekristeen.net/index.php
- http://sh#####lekristeen.net/index.php
- http://ch#####necallahan.net/index.php
- http://sh#####lecallahan.net/index.php
- http://ce#####nekristeen.net/index.php
- http://ce#####nemarcelyn.net/index.php
- http://am#####neshaquila.net/index.php
- http://al#####rakristeen.net/index.php
- http://am#####nemarcelyn.net/index.php
- http://ce#####necallahan.net/index.php
- http://am#####nekristeen.net/index.php
- http://ce#####neshaquila.net/index.php
- http://am#####necallahan.net/index.php
- http://ar#####ldmarcelyn.net/index.php
- http://ge#####nacallahan.net/index.php
- http://ch#####lecallahan.net/index.php
- http://ge#####nashaquila.net/index.php
- http://ch#####leshaquila.net/index.php
- http://an#####lemarcelyn.net/index.php
- http://gu#####enmarcelyn.net/index.php
- http://ge#####nakristeen.net/index.php
- http://ch#####lekristeen.net/index.php
- http://ch#####lemarcelyn.net/index.php
- http://za#####ahshaquila.net/index.php
- http://ar#####ldcallahan.net/index.php
- http://za#####ahmarcelyn.net/index.php
- http://ar#####ldshaquila.net/index.php
- http://za#####ahkristeen.net/index.php
- http://ge#####namarcelyn.net/index.php
- http://za#####ahcallahan.net/index.php
- http://ar#####ldkristeen.net/index.php
- http://gu#####encheyenne.net/index.php
- http://gw#####resymphony.net/index.php
- http://gu#####enbradford.net/index.php
- http://an#####lecheyenne.net/index.php
- http://ch#####ankiersten.net/index.php
- http://gw#####rebradford.net/index.php
- http://ch#####ansymphony.net/index.php
- http://gw#####rekiersten.net/index.php
- http://an#####lebradford.net/index.php
- http://ge#####nacheyenne.net/index.php
- http://ch#####lecheyenne.net/index.php
- http://ge#####nabradford.net/index.php
- http://ch#####lebradford.net/index.php
- http://an#####lekiersten.net/index.php
- http://gu#####enkiersten.net/index.php
- http://an#####lesymphony.net/index.php
- http://gu#####ensymphony.net/index.php
- http://ch#####anbradford.net/index.php
- http://al#####ramarcelyn.net/index.php
- http://ma#####nashaquila.net/index.php
- http://al#####erkristeen.net/index.php
- http://ma#####namarcelyn.net/index.php
- http://al#####racallahan.net/index.php
- http://ma#####nakristeen.net/index.php
- http://al#####rashaquila.net/index.php
- http://ma#####nacallahan.net/index.php
- http://ka#####nekristeen.net/index.php
- http://ka#####nemarcelyn.net/index.php
- http://al#####ermarcelyn.net/index.php
- http://gw#####recheyenne.net/index.php
- http://ch#####ancheyenne.net/index.php
- http://ka#####necallahan.net/index.php
- http://al#####ercallahan.net/index.php
- http://ka#####neshaquila.net/index.php
- http://al#####ershaquila.net/index.php
- DNS ASK sh#####leshaquila.net
- DNS ASK ch#####necallahan.net
- DNS ASK sh#####lemarcelyn.net
- DNS ASK ch#####neshaquila.net
- DNS ASK sh#####lekristeen.net
- DNS ASK ar#####ldmarcelyn.net
- DNS ASK sh#####lecallahan.net
- DNS ASK ch#####nekristeen.net
- DNS ASK ch#####nemarcelyn.net
- DNS ASK am#####neshaquila.net
- DNS ASK ce#####neshaquila.net
- DNS ASK am#####nemarcelyn.net
- DNS ASK ce#####nemarcelyn.net
- DNS ASK am#####nekristeen.net
- DNS ASK ce#####nekristeen.net
- DNS ASK am#####necallahan.net
- DNS ASK ce#####necallahan.net
- DNS ASK za#####ahmarcelyn.net
- DNS ASK ch#####lecallahan.net
- DNS ASK ge#####nakristeen.net
- DNS ASK ch#####leshaquila.net
- DNS ASK ge#####nacallahan.net
- DNS ASK gu#####enmarcelyn.net
- DNS ASK an#####leshaquila.net
- DNS ASK ch#####lekristeen.net
- DNS ASK an#####lemarcelyn.net
- DNS ASK ge#####nashaquila.net
- DNS ASK ar#####ldcallahan.net
- DNS ASK za#####ahcallahan.net
- DNS ASK ar#####ldshaquila.net
- DNS ASK za#####ahshaquila.net
- DNS ASK ge#####namarcelyn.net
- DNS ASK ch#####lemarcelyn.net
- DNS ASK ar#####ldkristeen.net
- DNS ASK za#####ahkristeen.net
- DNS ASK al#####rakristeen.net
- DNS ASK gu#####encheyenne.net
- DNS ASK gw#####resymphony.net
- DNS ASK gu#####enbradford.net
- DNS ASK an#####lecheyenne.net
- DNS ASK ch#####ankiersten.net
- DNS ASK gw#####rebradford.net
- DNS ASK ch#####ansymphony.net
- DNS ASK gw#####rekiersten.net
- DNS ASK an#####lebradford.net
- DNS ASK ge#####nacheyenne.net
- DNS ASK ch#####lecheyenne.net
- DNS ASK ge#####nabradford.net
- DNS ASK ch#####lebradford.net
- DNS ASK an#####lekiersten.net
- DNS ASK gu#####enkiersten.net
- DNS ASK an#####lesymphony.net
- DNS ASK gu#####ensymphony.net
- DNS ASK ch#####anbradford.net
- DNS ASK al#####ramarcelyn.net
- DNS ASK ma#####nashaquila.net
- DNS ASK al#####erkristeen.net
- DNS ASK ma#####namarcelyn.net
- DNS ASK al#####racallahan.net
- DNS ASK ma#####nakristeen.net
- DNS ASK al#####rashaquila.net
- DNS ASK ma#####nacallahan.net
- DNS ASK ka#####nekristeen.net
- DNS ASK ka#####nemarcelyn.net
- DNS ASK al#####ermarcelyn.net
- DNS ASK gw#####recheyenne.net
- DNS ASK ch#####ancheyenne.net
- DNS ASK ka#####necallahan.net
- DNS ASK al#####ercallahan.net
- DNS ASK ka#####neshaquila.net
- DNS ASK al#####ershaquila.net