Technical Information
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] 'Shell' = 'Explorer.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'kwckoakr' = '%TEMP%\bwlcpkdthozvhjhfh.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'bovejwhpv' = '%TEMP%\kgwocysjygspcfedgm.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'kwckoakr' = 'xwpkbaxrjujjzfhjpybgf.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'bovejwhpv' = 'uocseyqfsyidopmj.exe .'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'penyfuhrzaf' = 'bwlcpkdthozvhjhfh.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'mcmygwkvegmd' = 'bwlcpkdthozvhjhfh.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'vglsvgp' = '%TEMP%\bwlcpkdthozvhjhfh.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'bovejwhpv' = '%TEMP%\bwlcpkdthozvhjhfh.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'kwckoakr' = 'bwlcpkdthozvhjhfh.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'penyfuhrzaf' = 'uocseyqfsyidopmj.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'bovejwhpv' = '%TEMP%\uocseyqfsyidopmj.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'uiqagugpww' = 'bwlcpkdthozvhjhfh.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'meqeogwjuygzih' = '%TEMP%\kgwocysjygspcfedgm.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'lcnajapblovnv' = '%TEMP%\igysigcvmwkjydefksuy.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'vglsvgp' = '%TEMP%\kgwocysjygspcfedgm.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'uiqagugpww' = 'xwpkbaxrjujjzfhjpybgf.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'penyfuhrzaf' = 'igysigcvmwkjydefksuy.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'mcmygwkvegmd' = 'xwpkbaxrjujjzfhjpybgf.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'uiqagugpww' = 'uocseyqfsyidopmj.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'mcmygwkvegmd' = 'vsjcrojbranlzdddhop.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'meqeogwjuygzih' = '%TEMP%\igysigcvmwkjydefksuy.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'kwckoakr' = '%TEMP%\kgwocysjygspcfedgm.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'mcmygwkvegmd' = 'igysigcvmwkjydefksuy.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'lcnajapblovnv' = '%TEMP%\bwlcpkdthozvhjhfh.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'bovejwhpv' = 'vsjcrojbranlzdddhop.exe .'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'kwckoakr' = '%TEMP%\igysigcvmwkjydefksuy.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'lcnajapblovnv' = '%TEMP%\vsjcrojbranlzdddhop.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'vglsvgp' = '%TEMP%\vsjcrojbranlzdddhop.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'lcnajapblovnv' = '%TEMP%\xwpkbaxrjujjzfhjpybgf.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'kwckoakr' = 'igysigcvmwkjydefksuy.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'bovejwhpv' = 'bwlcpkdthozvhjhfh.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'uiqagugpww' = 'kgwocysjygspcfedgm.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'penyfuhrzaf' = 'vsjcrojbranlzdddhop.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'mcmygwkvegmd' = 'uocseyqfsyidopmj.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'meqeogwjuygzih' = '%TEMP%\xwpkbaxrjujjzfhjpybgf.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'lcnajapblovnv' = '%TEMP%\kgwocysjygspcfedgm.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'vglsvgp' = '%TEMP%\xwpkbaxrjujjzfhjpybgf.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'kwckoakr' = '%TEMP%\xwpkbaxrjujjzfhjpybgf.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'bovejwhpv' = '%TEMP%\vsjcrojbranlzdddhop.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'kwckoakr' = 'vsjcrojbranlzdddhop.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'bovejwhpv' = 'kgwocysjygspcfedgm.exe .'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'penyfuhrzaf' = 'kgwocysjygspcfedgm.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'meqeogwjuygzih' = '%TEMP%\vsjcrojbranlzdddhop.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'vglsvgp' = '%TEMP%\uocseyqfsyidopmj.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'kwckoakr' = '%TEMP%\uocseyqfsyidopmj.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'bovejwhpv' = '%TEMP%\igysigcvmwkjydefksuy.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'kwckoakr' = 'kgwocysjygspcfedgm.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'bovejwhpv' = 'igysigcvmwkjydefksuy.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'uiqagugpww' = 'vsjcrojbranlzdddhop.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'uiqagugpww' = 'igysigcvmwkjydefksuy.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'penyfuhrzaf' = 'xwpkbaxrjujjzfhjpybgf.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'meqeogwjuygzih' = '%TEMP%\bwlcpkdthozvhjhfh.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'meqeogwjuygzih' = '%TEMP%\uocseyqfsyidopmj.exe'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] 'lcnajapblovnv' = '%TEMP%\uocseyqfsyidopmj.exe .'
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'vglsvgp' = '%TEMP%\igysigcvmwkjydefksuy.exe'
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'kwckoakr' = '%TEMP%\vsjcrojbranlzdddhop.exe'
- hidden files
- Registry Editor (RegEdit)
- User Account Control (UAC)
- %TEMP%\iswceo.exe
- %WINDIR%\syswow64\ycaawacbyoinitahsgoyca.wac
- %ProgramFiles(x86)%\ycaawacbyoinitahsgoyca.wac
- %LOCALAPPDATA%\ycaawacbyoinitahsgoyca.wac
- %WINDIR%\ycaawacbyoinitahsgoyca.wac
- %TEMP%\ycaawacbyoinitahsgoyca.wac
- %WINDIR%\syswow64\penyfuhrzafvbxphdcvqfozgvisabgwcy.ied
- %ProgramFiles(x86)%\penyfuhrzafvbxphdcvqfozgvisabgwcy.ied
- %LOCALAPPDATA%\penyfuhrzafvbxphdcvqfozgvisabgwcy.ied
- %WINDIR%\penyfuhrzafvbxphdcvqfozgvisabgwcy.ied
- %TEMP%\penyfuhrzafvbxphdcvqfozgvisabgwcy.ied
- %WINDIR%\syswow64\ycaawacbyoinitahsgoyca.wac
- %ProgramFiles(x86)%\ycaawacbyoinitahsgoyca.wac
- %LOCALAPPDATA%\ycaawacbyoinitahsgoyca.wac
- %WINDIR%\ycaawacbyoinitahsgoyca.wac
- %TEMP%\ycaawacbyoinitahsgoyca.wac
- %WINDIR%\syswow64\penyfuhrzafvbxphdcvqfozgvisabgwcy.ied
- %ProgramFiles(x86)%\penyfuhrzafvbxphdcvqfozgvisabgwcy.ied
- %LOCALAPPDATA%\penyfuhrzafvbxphdcvqfozgvisabgwcy.ied
- %WINDIR%\penyfuhrzafvbxphdcvqfozgvisabgwcy.ied
- %TEMP%\penyfuhrzafvbxphdcvqfozgvisabgwcy.ied
- 'sh####ipaddress.com':80
- 'wh#####yipaddress.com':80
- 'wh###smyip.com':80
- 'google.com':80
- 'hk###qwuttn.com':80
- '<LOCALNET>.28.2':445
- '<LOCALNET>.28.2':139
- http://www.sh####ipaddress.com/
- http://wh#####yipaddress.com/
- http://www.wh###smyip.com/
- http://www.google.com/
- http://hk###qwuttn.com/
- DNS ASK zk##py.info
- DNS ASK ra####qyspss.net
- DNS ASK to###csoldp.org
- DNS ASK xt###zfx.info
- DNS ASK dd###kvaxl.info
- DNS ASK jc##pl.info
- DNS ASK tw###cvbdyl.org
- DNS ASK gs##zen.net
- DNS ASK ye###eua.org
- DNS ASK be###sfbvcf.net
- DNS ASK tw##ut.info
- DNS ASK qc###ugjlt.info
- DNS ASK ta###pvy.info
- DNS ASK fv###sku.net
- DNS ASK wl##ua.net
- DNS ASK ou###qgg.info
- DNS ASK wo##uv.info
- DNS ASK ds###xmytr.info
- DNS ASK hk###qwuttn.com
- DNS ASK google.com
- DNS ASK wh###smyip.com
- DNS ASK wh###smyip.ca
- DNS ASK wh#####yipaddress.com
- DNS ASK wh#####yip.everdot.org
- DNS ASK sh####ipaddress.com
- DNS ASK cq###vzz.info
- 'localhost':65123
- 'localhost':64718
- '%TEMP%\iswceo.exe' "-"