Technical Information
- [HKLM\System\CurrentControlSet\Services\Task Problem Spooler Control Plug Search] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Task Problem Spooler Control Plug Search] 'ImagePath' = 'C:\psjwgccd\qlycmibk.exe'
- 'Task Problem Spooler Control Plug Search' C:\psjwgccd\qlycmibk.exe
- %WINDIR%\psjwgccd\cvqyre
- C:\psjwgccd\cvqyre
- C:\psjwgccd\tbc7lvrqbio9eep.exe
- C:\psjwgccd\qlycmibk.exe
- C:\psjwgccd\krzkhnr.exe
- C:\psjwgccd\qlycmibk.exe
- C:\psjwgccd\krzkhnr.exe
- %WINDIR%\psjwgccd\cvqyre
- C:\psjwgccd\tbc7lvrqbio9eep.exe
- %WINDIR%\psjwgccd\cvqyre
- 'wi####supply.net':80
- DNS ASK mo#####ndistance.net
- DNS ASK po#####edistance.net
- DNS ASK mo####inoffice.net
- DNS ASK po####leoffice.net
- DNS ASK mo####inarrive.net
- DNS ASK po####learrive.net
- DNS ASK pe####ssupply.net
- DNS ASK wi####supply.net
- DNS ASK pe####sdistance.net
- DNS ASK wi####distance.net
- DNS ASK pe####soffice.net
- DNS ASK wi####office.net
- 'C:\psjwgccd\tbc7lvrqbio9eep.exe'
- 'C:\psjwgccd\qlycmibk.exe'
- 'C:\psjwgccd\krzkhnr.exe' "c:\psjwgccd\qlycmibk.exe"