Technical Information
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'system recover' = '"%ProgramFiles(x86)%\mIRC\Lokyshabazhy.exe"'
- '%WINDIR%\syswow64\taskkill.exe' /im "GcleanerEU.exe" /f
- '%WINDIR%\syswow64\taskkill.exe' /im "gcleaner.exe" /f
- '%WINDIR%\syswow64\taskkill.exe' /im AdvancedWindowsManager* /f
- <SYSTEM32>\svchost.exe
- %TEMP%\is-7hhos.tmp\<File name>.tmp
- %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\idownload.lnk
- C:\users\public\desktop\idownload.lnk
- %TEMP%\bd-3cf50-a47-e8c8e-da1e7f77da0a7\judedafaepy.exe.config
- %ProgramFiles(x86)%\idownload\unins000.dat
- %ProgramFiles(x86)%\mirc\lokyshabazhy.exe
- %ProgramFiles(x86)%\mirc\lokyshabazhy.exe.config
- %TEMP%\inxevnbd.0.cs
- %TEMP%\inxevnbd.cmdline
- %TEMP%\inxevnbd.out
- %TEMP%\res68c1.tmp
- %TEMP%\jocaiesm.bng\gcleaner.exe
- %TEMP%\inxevnbd.dll
- %ProgramFiles(x86)%\idownload\downloads.xml
- %TEMP%\qqwitsmt.u2e\gcleanereu.exe
- %TEMP%\srre1a4n.4cm\installer.exe
- %APPDATA%\aw manager\windows manager 1.0.0\install\decoder.dll
- %APPDATA%\aw manager\windows manager 1.0.0\install\97fdf62\windows manager - postback y.msi
- %TEMP%\hxp0urw1.kof\anyname.exe
- %TEMP%\sqlite.dat
- %TEMP%\sqlite.dll
- %TEMP%\bd-3cf50-a47-e8c8e-da1e7f77da0a7\judedafaepy.exe
- %TEMP%\csc68c0.tmp
- %ProgramFiles(x86)%\idownload\is-90ajf.tmp
- %TEMP%\bd-3cf50-a47-e8c8e-da1e7f77da0a7\kenessey.txt
- %TEMP%\is-auahq.tmp\_isetup\_setup64.tmp
- %TEMP%\is-auahq.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-auahq.tmp\idp.dll
- %TEMP%\is-auahq.tmp\mastazdom.exe
- %ProgramFiles%\cavse\alhlvgarvp\idownload.exe
- %ProgramFiles%\cavse\alhlvgarvp\idownload.exe.config
- %TEMP%\is-sfdu5.tmp\idownload.tmp
- %TEMP%\a2-a2e84-037-f4184-85d04728f0d6f\nomorotebe.exe
- %TEMP%\a2-a2e84-037-f4184-85d04728f0d6f\nomorotebe.exe.config
- %TEMP%\is-dgg2m.tmp\_isetup\_setup64.tmp
- %ProgramFiles(x86)%\idownload\is-ejq3l.tmp
- %TEMP%\is-dgg2m.tmp\_isetup\_shfoldr.dll
- %ProgramFiles(x86)%\idownload\is-4uumb.tmp
- %ProgramFiles(x86)%\idownload\is-8254t.tmp
- %ProgramFiles(x86)%\idownload\is-ad0at.tmp
- %ProgramFiles(x86)%\idownload\is-0emr7.tmp
- %ProgramFiles(x86)%\idownload\is-7ao7v.tmp
- %ProgramFiles(x86)%\idownload\is-4rrfv.tmp
- %ProgramFiles(x86)%\idownload\is-8q117.tmp
- %ProgramFiles(x86)%\idownload\is-0df5o.tmp
- %ProgramFiles(x86)%\idownload\is-dsdtd.tmp
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cookies.sqlite.tmp-shm
- %TEMP%\is-auahq.tmp\idp.dll
- %TEMP%\is-auahq.tmp\mastazdom.exe
- %TEMP%\is-auahq.tmp\_isetup\_setup64.tmp
- %TEMP%\is-auahq.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-7hhos.tmp\<File name>.tmp
- %TEMP%\res68c1.tmp
- %TEMP%\csc68c0.tmp
- %TEMP%\inxevnbd.out
- %TEMP%\inxevnbd.dll
- %TEMP%\inxevnbd.cmdline
- %TEMP%\inxevnbd.0.cs
- %TEMP%\sqlite.dat
- %TEMP%\qqwitsmt.u2e\gcleanereu.exe
- %TEMP%\jocaiesm.bng\gcleaner.exe
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cookies.sqlite.tmp-shm
- from %ProgramFiles(x86)%\idownload\is-4uumb.tmp to %ProgramFiles(x86)%\idownload\unins000.exe
- from %ProgramFiles(x86)%\idownload\is-8254t.tmp to %ProgramFiles(x86)%\idownload\idownload.app.exe
- from %ProgramFiles(x86)%\idownload\is-ad0at.tmp to %ProgramFiles(x86)%\idownload\downloads.xml
- from %ProgramFiles(x86)%\idownload\is-0emr7.tmp to %ProgramFiles(x86)%\idownload\icsharpcode.sharpziplib.dll
- from %ProgramFiles(x86)%\idownload\is-7ao7v.tmp to %ProgramFiles(x86)%\idownload\idownload.app.exe.config
- from %ProgramFiles(x86)%\idownload\is-4rrfv.tmp to %ProgramFiles(x86)%\idownload\mydownloader.core.dll
- from %ProgramFiles(x86)%\idownload\is-8q117.tmp to %ProgramFiles(x86)%\idownload\mydownloader.core.dll.config
- from %ProgramFiles(x86)%\idownload\is-0df5o.tmp to %ProgramFiles(x86)%\idownload\mydownloader.extension.dll
- from %ProgramFiles(x86)%\idownload\is-ejq3l.tmp to %ProgramFiles(x86)%\idownload\mydownloader.extension.dll.config
- from %ProgramFiles(x86)%\idownload\is-dsdtd.tmp to %ProgramFiles(x86)%\idownload\mydownloader.spider.dll
- from %ProgramFiles(x86)%\idownload\is-90ajf.tmp to %ProgramFiles(x86)%\idownload\tabstrip.dll
- %APPDATA%\mozilla\firefox\profiles\gn7ryp3k.default\cookies.sqlite.tmp-shm
- 'sa###links.com':80
- 'co###ctini.net':443
- 'microsoft.com':80
- 're#####immersive.com':80
- 'google.com':80
- 'pr#######etrustednetwork.com':443
- '19#.#45.227.159':80
- 'so#####.boys4dayz.com':443
- 'aa.###tgamea.com':443
- 'bb.###tgameb.com':443
- 'ip###ger.org':443
- 'a.###tgame.co':443
- 'cl#####-partners.biz':80
- 'fs######ecloudservice.com':80
- 'r3.#.lencr.org':80
- 'x1.#.lencr.org':80
- http://sa###links.com/Installer_Provider/IDownload.exe
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- http://sa###links.com/Widgets/IDownload.exe
- http://sa###links.com/L3CKQSg3wbJyCsvFNeyUtJP4qUBxcV/cpm-provider/nfdbssmwan23dzjn.exe
- http://sa###links.com/L3CKQSg3wbJyCsvFNeyUtJP4qUBxcV/kenpachi/5d3cdh4z6b5ytg2t.exe
- http://sa###links.com/L3CKQSg3wbJyCsvFNeyUtJP4qUBxcV/post-install-provider/r2dcfcbx72q3cxze.exe
- http://www.google.com/
- http://19#.#45.227.159/pub.php?pu######
- http://cl#####-partners.biz/stats/1.php?pu############
- http://cl#####-partners.biz/check.php?pu########
- http://x1.#.lencr.org/
- http://r3.#.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgPbcS8XWMJIc%2Bfn9q8zgDQrhA%3D%3D
- http://fs######ecloudservice.com/campaign3/autosubplayer.exe
- http://re#####immersive.com/t7gu47xyp4mj4ekapans/zkau68gvw5aqjawnxpeg
- 'co###ctini.net':443
- 'pr#######etrustednetwork.com':443
- 'so#####.boys4dayz.com':443
- 'aa.###tgamea.com':443
- 'bb.###tgameb.com':443
- 'ip###ger.org':443
- 'a.###tgame.co':443
- DNS ASK sa###links.com
- DNS ASK x1.#.lencr.org
- DNS ASK fs######ecloudservice.com
- DNS ASK
- DNS ASK go####.vrthcobj.com
- DNS ASK a.###tgame.co
- DNS ASK cl#####-partners.biz
- DNS ASK ip###ger.org
- DNS ASK r3.#.lencr.org
- DNS ASK bb.###tgameb.com
- DNS ASK ht####ownload.pw
- DNS ASK so#####.boys4dayz.com
- DNS ASK pr#######etrustednetwork.com
- DNS ASK google.com
- DNS ASK re#####immersive.com
- DNS ASK microsoft.com
- DNS ASK co###ctini.net
- DNS ASK aa.###tgamea.com
- DNS ASK
- 'go####.vrthcobj.com':53
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: '' WindowName: ''
- '%TEMP%\is-7hhos.tmp\<File name>.tmp' /SL5="$C0226,506127,422400,<Full path to file>"
- '%TEMP%\bd-3cf50-a47-e8c8e-da1e7f77da0a7\judedafaepy.exe'
- '%TEMP%\srre1a4n.4cm\installer.exe' /qn CAMPAIGN="654"
- '%TEMP%\qqwitsmt.u2e\gcleanereu.exe' /eufive
- '%TEMP%\hxp0urw1.kof\anyname.exe'
- '%TEMP%\is-sfdu5.tmp\idownload.tmp' /SL5="$D021C,994212,425984,%ProgramFiles%\cavse\ALHLVGARVP\IDownload.exe" /VERYSILENT
- '%TEMP%\jocaiesm.bng\gcleaner.exe' /mixfive
- '%TEMP%\a2-a2e84-037-f4184-85d04728f0d6f\nomorotebe.exe'
- '%ProgramFiles%\cavse\alhlvgarvp\idownload.exe' /VERYSILENT
- '%TEMP%\is-auahq.tmp\mastazdom.exe' /S /UID=124
- '%ProgramFiles(x86)%\idownload\idownload.app.exe' -silent -desktopShortcut -programMenu
- '%TEMP%\hxp0urw1.kof\anyname.exe' -u
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /im "GcleanerEU.exe" /f & erase "%TEMP%\qqwitsmt.u2e\GcleanerEU.exe" & exit' (with hidden window)
- '<SYSTEM32>\cmd.exe' /k %TEMP%\hxp0urw1.kof\anyname.exe & exit' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /im "gcleaner.exe" /f & erase "%TEMP%\jocaiesm.bng\gcleaner.exe" & exit' (with hidden window)
- '<SYSTEM32>\cmd.exe' /k %TEMP%\jocaiesm.bng\gcleaner.exe /mixfive & exit' (with hidden window)
- '<SYSTEM32>\cmd.exe' /k %TEMP%\lmnjiz0l.5hg\installer.exe /qn CAMPAIGN=654 & exit' (with hidden window)
- '<SYSTEM32>\cmd.exe' /k %TEMP%\qqwitsmt.u2e\GcleanerEU.exe /eufive & exit' (with hidden window)
- '<SYSTEM32>\cmd.exe' /k %TEMP%\xrbsuqjl.2i4\app.exe /8-2222 & exit' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES68C1.tmp" "%TEMP%\CSC68C0.tmp"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\inxevnbd.cmdline"' (with hidden window)
- '%TEMP%\is-auahq.tmp\mastazdom.exe' /S /UID=124' (with hidden window)
- '<SYSTEM32>\cmd.exe' /k %TEMP%\srre1a4n.4cm\installer.exe /qn CAMPAIGN="654" & exit' (with hidden window)
- '<SYSTEM32>\cmd.exe' /k %TEMP%\03vco00e.jau\autosubplayer.exe /S & exit' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /im AdvancedWindowsManager* /f' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\inxevnbd.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES68C1.tmp" "%TEMP%\CSC68C0.tmp"
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' https://www.pr#######etrustednetwork.com/e2q8zu9hu?ke##################################
- '<SYSTEM32>\cmd.exe' /k %TEMP%\qqwitsmt.u2e\GcleanerEU.exe /eufive & exit
- '<SYSTEM32>\cmd.exe' /k %TEMP%\srre1a4n.4cm\installer.exe /qn CAMPAIGN="654" & exit
- '<SYSTEM32>\cmd.exe' /k %TEMP%\hxp0urw1.kof\anyname.exe & exit
- '<SYSTEM32>\rundll32.exe' "%TEMP%\sqlite.dll",global
- '<SYSTEM32>\svchost.exe' -k SystemNetworkService
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /im "GcleanerEU.exe" /f & erase "%TEMP%\qqwitsmt.u2e\GcleanerEU.exe" & exit
- '<SYSTEM32>\cmd.exe' /k %TEMP%\jocaiesm.bng\gcleaner.exe /mixfive & exit
- '<SYSTEM32>\cmd.exe' /k %TEMP%\03vco00e.jau\autosubplayer.exe /S & exit
- '<SYSTEM32>\cmd.exe' /k %TEMP%\lmnjiz0l.5hg\installer.exe /qn CAMPAIGN=654 & exit
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /im "gcleaner.exe" /f & erase "%TEMP%\jocaiesm.bng\gcleaner.exe" & exit
- '<SYSTEM32>\cmd.exe' /k %TEMP%\xrbsuqjl.2i4\app.exe /8-2222 & exit
- '%WINDIR%\syswow64\msiexec.exe' /i "%APPDATA%\AW Manager\Windows Manager 1.0.0\install\97FDF62\Windows Manager - Postback Y.msi" /qn CAMPAIGN=654 AI_SETUPEXEPATH=%TEMP%\srre1a4n.4cm\installer.exe SETUPEXEDIR=%TEMP%\srre1a4n.4...