Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ibn' = '"%ProgramFiles%\Guffaw\kika.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'simplicity' = '"%ProgramFiles%\Guffaw\kika.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ibnsimplicity' = '"%ProgramFiles%\bayberry\impiety.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'simplicityibn' = '"%ProgramFiles%\bayberry\impiety.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'ibnibn' = '"%ProgramFiles%\Mcgrane\kika.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'simplicitysimplicity' = '"%ProgramFiles%\Mcgrane\kika.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'collects' = '"%ProgramFiles%\Guffaw\kika.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'unbelieving' = '"%ProgramFiles%\Guffaw\kika.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'collectsunbelieving' = '"%ProgramFiles%\bayberry\impiety.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'unbelievingcollects' = '"%ProgramFiles%\bayberry\impiety.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'collectscollects' = '"%ProgramFiles%\Mcgrane\kika.exe"'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'unbelievingunbelieving' = '"%ProgramFiles%\Mcgrane\kika.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'conacher' = '"%ProgramFiles%\bikes\conacher.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'oie' = '"%ProgramFiles%\Guffaw\kika.exe"'
- %HOMEPATH%\Start Menu\Programs\Startup\hendershot.lnk
- %HOMEPATH%\Start Menu\Programs\Startup\hendershothendershot.lnk
- '<SYSTEM32>\taskkill.exe' /im chrome.exe
- %TEMP%\nss2.tmp\20190.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\2-u20KmI18KmI02LPQ06uKmI[1].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\u20KmI18KmI02LPQ06uKmI[2].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\2-u20KmI18KmI02LPQ06uKmI[3].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\2-u20KmI18KmI02LPQ06uKmI[2].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\2-u20KmI18KmI02LPQ06uKmI[1].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[24].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[23].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[22].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\2-u20KmI18KmI02LPQ06uKmI[1].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\2-u20KmI18KmI02LPQ06uKmI[2].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[19].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[18].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[17].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[16].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[15].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[14].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[13].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[12].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[21].asp
- %WINDIR%\dudgeon.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\2-u20KmI18KmI02LPQ06uKmI[2].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[21].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[20].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[19].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[18].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[17].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[16].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[15].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[14].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[13].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[12].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[11].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[10].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[9].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[8].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[7].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[6].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[5].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[4].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[3].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[11].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[20].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[10].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\2-u20KmI18KmI02LPQ06uKmI[7].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[9].asp
- %ProgramFiles%\Guffaw\kika.exe
- %ProgramFiles%\Mcgrane\impiety.exe
- %ProgramFiles%\Mcgrane\kika.exe
- %TEMP%\nsb5.tmp\SimpleFC.dll
- <LS_APPDATA>\impiety.exe
- <LS_APPDATA>\kika.exe
- %ProgramFiles%\bayberry\impiety.exe
- %ProgramFiles%\bayberry\impiety.dll
- %ProgramFiles%\bayberry\bayberry.exe
- %ProgramFiles%\Guffaw\kika.dll
- %TEMP%\nso7.tmp\AccessControl.dll
- %ProgramFiles%\Guffaw\Guffaw.exe
- %TEMP%\nss2.tmp\112762.exe
- %TEMP%\nss2.tmp\Microsoft.Win32.TaskScheduler.dll
- %TEMP%\nss2.tmp\NMspades.exe
- %TEMP%\nss2.tmp\129911.exe
- %TEMP%\nss2.tmp\99309.exe
- %TEMP%\nss2.tmp\66961.exe
- %TEMP%\nss2.tmp\38824.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[22].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[2].asp
- %ProgramFiles%\bikes\conacher.exe
- %TEMP%\nszA.tmp\nsB.tmp
- %ProgramFiles%\lemur\lemur.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[8].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[7].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[6].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[5].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\2-u20KmI18KmI02LPQ06uKmI[6].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[4].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\2-u20KmI18KmI02LPQ06uKmI[5].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\2-u20KmI18KmI02LPQ06uKmI[4].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[3].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[2].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\u20KmI18KmI02LPQ06uKmI[1].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\2-u20KmI18KmI02LPQ06uKmI[3].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\2-u20KmI18KmI02LPQ06uKmI[2].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[1].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\u20KmI18KmI02LPQ06uKmI[1].asp
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\u20KmI18KmI02LPQ06uKmI[1].asp
- %TEMP%\nslD.tmp\ShellLink.dll
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\2-u20KmI18KmI02LPQ06uKmI[1].asp
- %TEMP%\nszA.tmp\nsExec.dll
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\YPORKZYZ\u20KmI18KmI02LPQ06uKmI[23].asp
- %TEMP%\nsb5.tmp\SimpleFC.dll
- %TEMP%\nso7.tmp\AccessControl.dll
- %TEMP%\nslD.tmp\ShellLink.dll
- 'localhost':1038
- 'localhost':1039
- 'localhost':1040
- 'ma####eshayford.pw':80
- 'localhost':1049
- http://www.ma####eshayford.pw/2-u20KmI18KmI02LPQ06uKmI.asp?ke########################################### via ma####eshayford.pw
- http://www.ma####eshayford.pw/u20KmI18KmI02LPQ06uKmI.asp?kn############################################# via ma####eshayford.pw
- DNS ASK www.ma####eshayford.pw
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: 'Chrome_WidgetWin_0' WindowName: ''
- ClassName: '' WindowName: ''
- '%TEMP%\nss2.tmp\NMspades.exe' "%ProgramFiles%\Guffaw\kika.exe" "74701802"
- '%TEMP%\nss2.tmp\66961.exe'
- '%ProgramFiles%\bikes\conacher.exe'
- '%TEMP%\nss2.tmp\112762.exe'
- '%TEMP%\nss2.tmp\NMspades.exe' "%ProgramFiles%\lemur\lemur.exe" "k27239781"
- '%TEMP%\nss2.tmp\NMspades.exe' "%ProgramFiles%\Mcgrane\impiety.exe" "2723978127239781"
- '%TEMP%\nss2.tmp\NMspades.exe' "%ProgramFiles%\Mcgrane\kika.exe" "27239781"
- '%TEMP%\nszA.tmp\nsB.tmp' taskkill /im chrome.exe
- '%ProgramFiles%\Mcgrane\impiety.exe'
- '%TEMP%\nss2.tmp\NMspades.exe' "<LS_APPDATA>\impiety.exe" "7126773771267737"
- '%TEMP%\nss2.tmp\NMspades.exe' "<LS_APPDATA>\kika.exe" "71267737"
- '%TEMP%\nss2.tmp\38824.exe'
- '%ProgramFiles%\Guffaw\kika.exe'
- '%TEMP%\nss2.tmp\129911.exe'
- '%TEMP%\nss2.tmp\NMspades.exe' "%ProgramFiles%\bayberry\impiety.exe" "7470180274701802"
- '%ProgramFiles%\Mcgrane\kika.exe'
- '%TEMP%\nss2.tmp\99309.exe'