Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'attentivelyattentively' = '"%ProgramFiles%\Floorboards\ported.exe" WC5k'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'optionally' = '"%ProgramFiles%\Euler\ported.exe" WC5k'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'optionallyoptionally' = '"%ProgramFiles%\Floorboards\ported.exe" WC5k'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'dollops' = '"%ProgramFiles%\Euler\ported.exe" WC5k'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'mismo' = '"%ProgramFiles%\fluke\mismo.exe" WC5k'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'roederer' = '"%ProgramFiles%\Euler\ported.exe" WC5k'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'abd' = '"%ProgramFiles%\Euler\ported.exe" WC5k'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'abdabd' = '"%ProgramFiles%\Floorboards\ported.exe" WC5k'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'attentively' = '"%ProgramFiles%\Euler\ported.exe" WC5k'
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'roedererroederer' = '"%ProgramFiles%\Floorboards\ported.exe" WC5k'
- %HOMEPATH%\Start Menu\Programs\Startup\shindigs.lnk
- '<SYSTEM32>\taskkill.exe' /im chrome.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[35].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[36].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[34].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[32].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[33].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[40].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[41].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[39].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[37].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[38].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[31].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[24].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[25].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[23].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[21].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[22].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[29].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[30].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[28].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[26].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[27].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[56].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[57].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[55].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[53].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[54].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[61].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[62].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[60].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[58].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[59].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[52].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[45].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[46].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[44].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[42].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[43].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[50].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[51].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[49].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[47].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[48].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[20].htm
- %TEMP%\nsz5.tmp\SimpleFC.dll
- %TEMP%\nse7.tmp\AccessControl.dll
- %ProgramFiles%\skiwear\skiwear.exe
- <LS_APPDATA>\ported.exe
- %ProgramFiles%\Floorboards\ported.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\qwuwfr20mm18mm03gcq03qwuwfrmm[1].htm
- %TEMP%\nsqA.tmp\nsB.tmp
- %TEMP%\nsqA.tmp\nsExec.dll
- %ProgramFiles%\fluke\mismo.exe
- %WINDIR%\ported.exe
- %ProgramFiles%\Euler\ported.exe
- %TEMP%\nsk2.tmp\56247.exe
- %TEMP%\nsk2.tmp\75069.exe
- %TEMP%\nsk2.tmp\44440.exe
- %TEMP%\nsk2.tmp\AccessControl.dll
- %TEMP%\nsk2.tmp\20002.exe
- %TEMP%\nsk2.tmp\Microsoft.Win32.TaskScheduler.dll
- %TEMP%\nsk2.tmp\114352.exe
- %TEMP%\nsk2.tmp\NMbarbarities.exe
- %TEMP%\nsk2.tmp\104115.exe
- %TEMP%\nsk2.tmp\135912.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[13].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[14].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[12].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[10].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[11].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[18].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[19].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[17].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[15].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[16].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[9].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[2].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[3].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[1].htm
- %TEMP%\nskE.tmp\ShellLink.dll
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\U98D4X8H\qwuwfr20mm18mm03gcq03qwuwfrmm[1].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[7].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[8].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[6].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[4].htm
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\2VAZY7AN\qwuwfr20mm18mm03gcq03qwuwfrmm[5].htm
- %TEMP%\nskE.tmp\ShellLink.dll
- %TEMP%\nse7.tmp\AccessControl.dll
- %TEMP%\nsz5.tmp\SimpleFC.dll
- from %WINDIR%\ported.exe to %WINDIR%\costars.exe
- from %ProgramFiles%\Euler\ported.exe to %ProgramFiles%\Euler\ported.dll
- from %ProgramFiles%\Euler\ported.exe to %ProgramFiles%\Euler\Euler.exe
- %ProgramFiles%\Euler\ported.exe
- 'jo###alaam.pw':80
- 'localhost':1043
- 'localhost':1037
- 'localhost':1039
- http://www.jo###alaam.pw/qwuwfr20mm18mm03gcq03qwuwfrmm.htm?03################# via jo###alaam.pw
- DNS ASK www.jo###alaam.pw
- ClassName: 'Chrome_WidgetWin_0' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '%TEMP%\nsk2.tmp\56247.exe'
- '%ProgramFiles%\fluke\mismo.exe'
- '%TEMP%\nsk2.tmp\114352.exe'
- '%TEMP%\nsk2.tmp\104115.exe'
- '%TEMP%\nsqA.tmp\nsB.tmp' taskkill /im chrome.exe
- '%TEMP%\nsk2.tmp\75069.exe'
- '%TEMP%\nsk2.tmp\NMbarbarities.exe' "%ProgramFiles%\skiwear\skiwear.exe" "k25274321"
- '%TEMP%\nsk2.tmp\44440.exe'
- '%TEMP%\nsk2.tmp\135912.exe'
- '%TEMP%\nsk2.tmp\NMbarbarities.exe' "%ProgramFiles%\Euler\ported.exe" "55782875"
- '%TEMP%\nsk2.tmp\NMbarbarities.exe' "%ProgramFiles%\Floorboards\ported.exe" "25274321"
- '%ProgramFiles%\Floorboards\ported.exe' WC5k
- '%TEMP%\nsk2.tmp\NMbarbarities.exe' "<LS_APPDATA>\ported.exe" "4870318"