Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Font Tracking Biometric Adaptive' = 'C:\kxiansrdhhb\rmwzvlghkfs.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Initiator Web AutoConfig Computer Fax Host] 'Start' = '00000002'
- 'C:\kxiansrdhhb\lxytysszptvx.exe' "c:\kxiansrdhhb\rmwzvlghkfs.exe"
- 'C:\kxiansrdhhb\rmwzvlghkfs.exe'
- 'C:\kxiansrdhhb\tax3d0cznekjuc6rcz.exe'
- C:\kxiansrdhhb\rmwzvlghkfs.exe
- C:\kxiansrdhhb\lxytysszptvx.exe
- C:\kxiansrdhhb\tax3d0cznekjuc6rcz.exe
- %WINDIR%\kxiansrdhhb\bzoy9ixffb2z
- C:\kxiansrdhhb\bzoy9ixffb2z
- C:\kxiansrdhhb\lxytysszptvx.exe
- C:\kxiansrdhhb\rmwzvlghkfs.exe
- C:\kxiansrdhhb\tax3d0cznekjuc6rcz.exe
- %WINDIR%\kxiansrdhhb\bzoy9ixffb2z
- 'fe####probable.net':80
- 'fe####kitchen.net':80
- 're###twagon.net':80
- 'br###nwagon.net':80
- 'fe###wwagon.net':80
- 'pr####probable.net':80
- 'fe####without.net':80
- 'do###ewagon.net':80
- 're####probable.net':80
- 'br####probable.net':80
- 'de###ewagon.net':80
- 'pr####ewagon.net':80
- 're####without.net':80
- 'br####without.net':80
- 're####kitchen.net':80
- 'br####kitchen.net':80
- 'do####probable.net':80
- 'mi####ithout.net':80
- 'st####ithout.net':80
- 'mi####itchen.net':80
- 'st####itchen.net':80
- 'ev####gprobable.net':80
- 'bu#####gprobable.net':80
- 'mi###wagon.net':80
- 'st###wagon.net':80
- 'pr####without.net':80
- 'do####without.net':80
- 'pr####kitchen.net':80
- 'do####kitchen.net':80
- 'mi####robable.net':80
- 'st####robable.net':80
- 'pr###ywagon.net':80
- 'do###rwagon.net':80
- http://fe####probable.net/index.php
- http://fe####kitchen.net/index.php
- http://re###twagon.net/index.php
- http://br###nwagon.net/index.php
- http://fe###wwagon.net/index.php
- http://pr####probable.net/index.php
- http://fe####without.net/index.php
- http://do###ewagon.net/index.php
- http://re####probable.net/index.php
- http://br####probable.net/index.php
- http://de###ewagon.net/index.php
- http://pr####ewagon.net/index.php
- http://re####without.net/index.php
- http://br####without.net/index.php
- http://re####kitchen.net/index.php
- http://br####kitchen.net/index.php
- http://do####probable.net/index.php
- http://mi####ithout.net/index.php
- http://st####ithout.net/index.php
- http://mi####itchen.net/index.php
- http://st####itchen.net/index.php
- http://ev####gprobable.net/index.php
- http://bu#####gprobable.net/index.php
- http://mi###wagon.net/index.php
- http://st###wagon.net/index.php
- http://pr####without.net/index.php
- http://do####without.net/index.php
- http://pr####kitchen.net/index.php
- http://do####kitchen.net/index.php
- http://mi####robable.net/index.php
- http://st####robable.net/index.php
- http://pr###ywagon.net/index.php
- http://do###rwagon.net/index.php
- DNS ASK fe####probable.net
- DNS ASK fe####kitchen.net
- DNS ASK re###twagon.net
- DNS ASK br###nwagon.net
- DNS ASK fe###wwagon.net
- DNS ASK pr####probable.net
- DNS ASK fe####without.net
- DNS ASK do###ewagon.net
- DNS ASK br####without.net
- DNS ASK pr####ewagon.net
- DNS ASK re####probable.net
- DNS ASK pr####ewithout.net
- DNS ASK de###ewagon.net
- DNS ASK br####kitchen.net
- DNS ASK re####without.net
- DNS ASK br####probable.net
- DNS ASK re####kitchen.net
- DNS ASK mi####ithout.net
- DNS ASK st####ithout.net
- DNS ASK mi####itchen.net
- DNS ASK st####itchen.net
- DNS ASK ev####gprobable.net
- DNS ASK bu#####gprobable.net
- DNS ASK mi###wagon.net
- DNS ASK st###wagon.net
- DNS ASK st####robable.net
- DNS ASK do####kitchen.net
- DNS ASK pr####without.net
- DNS ASK do####probable.net
- DNS ASK pr####kitchen.net
- DNS ASK do###rwagon.net
- DNS ASK mi####robable.net
- DNS ASK do####without.net
- DNS ASK pr###ywagon.net
- ClassName: 'Shell_TrayWnd' WindowName: ''