Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<Full path to virus>' = '<Full path to virus>:*:Enabled:<Virus name>.exe (in)'
- %TEMP%\installer\gui\page_4001_attr_46.bmp
- %TEMP%\installer\gui\speedanalysis.ico
- %TEMP%\installer\gui\page_3885_attr_46.bmp
- %TEMP%\installer\gui\page_3633_attr_46.bmp
- %TEMP%\installer\gui\page_3737_attr_46.bmp
- %TEMP%\installer\gui\3123.html
- %TEMP%\installer\gui\3555.html
- %TEMP%\installer\gui\3122.html
- %TEMP%\installer\gui\3118.html
- %TEMP%\installer\gui\3119.html
- %TEMP%\installer\gui\page_3632_attr_46.bmp
- %TEMP%\installer\gui\page_3119_attr_46.bmp
- %TEMP%\installer\gui\page_3122_attr_46.bmp
- %TEMP%\installer\gui\page_3118_attr_46.bmp
- %TEMP%\installer\gui\page_4001_attr_3.png
- %TEMP%\installer\gui\template_40.png
- %TEMP%\installer\gui\page_3630_attr_46.bmp
- %TEMP%\installer\gui\page_3631_attr_46.bmp
- %TEMP%\installer\gui\page_3555_attr_46.bmp
- %TEMP%\installer\gui\page_3123_attr_46.bmp
- %TEMP%\installer\gui\page_3468_attr_46.bmp
- %TEMP%\installer\gui\js\utils.js
- %TEMP%\installer\wizard.xml
- %TEMP%\installer\gui\js\smart.js
- %TEMP%\installer\gui\js\jquery-1.7.min.js
- %TEMP%\installer\gui\js\jquery.noselect.min.js
- %TEMP%\ibtmpc810619\app_14398.part
- %TEMP%\ibtmpc810619\app_15971.part
- %TEMP%\ibtmpc810619\app_18002.part
- %TEMP%\ibtmpc810619\app_439.part
- %TEMP%\ibtmpc810619\app_9697.part
- %TEMP%\installer\gui\events\events.js
- %TEMP%\installer\gui\3633.html
- %TEMP%\installer\gui\3737.html
- %TEMP%\installer\gui\3632.html
- %TEMP%\installer\gui\3630.html
- %TEMP%\installer\gui\3631.html
- %TEMP%\installer\gui\conditions\conditions.js
- %TEMP%\installer\gui\js\config.js
- %TEMP%\installer\gui\ib\main.css
- %TEMP%\installer\gui\3885.html
- %TEMP%\installer\gui\4001.html
- %TEMP%\installer\gui\pb-bg-left.jpg
- %TEMP%\installer\gui\pb-bg-right.jpg
- %TEMP%\installer\gui\ib\mid.jpg
- %TEMP%\installer\gui\ib\center2.jpg
- %TEMP%\installer\gui\check.jpg
- %TEMP%\installer\gui\red-pb-act.jpg
- %TEMP%\installer\gui\ib\arrow.png
- %TEMP%\installer\gui\red-pb-act-right.jpg
- %TEMP%\installer\gui\pb-bg.jpg
- %TEMP%\installer\gui\red-pb-act-left.jpg
- %TEMP%\installer\gui\ib\trust.gif
- %TEMP%\installer\gui\ib\arrow.gif
- %TEMP%\installer\gui\ib\b-bg.gif
- %TEMP%\installer\gui\ajax-loader2.gif
- %TEMP%\installer\qrjatydimo
- %TEMP%\installer\gui\ajax-loader.gif
- %TEMP%\installer\gui\ib\lbg-top.gif
- %TEMP%\installer\gui\ib\lbg.gif
- %TEMP%\installer\gui\ib\lbg-bottom.gif
- %TEMP%\installer\gui\ib\b3.gif
- %TEMP%\installer\gui\ib\b4.gif
- %TEMP%\installer\gui\page_3630_attr_3.png
- %TEMP%\installer\gui\page_3630_feature_.png
- %TEMP%\installer\gui\page_3555_attr_3.png
- %TEMP%\installer\gui\page_3468_attr_3.png
- %TEMP%\installer\gui\page_3555_attr_15.png
- %TEMP%\installer\gui\page_3737_attr_3.png
- %TEMP%\installer\gui\page_3885_attr_3.png
- %TEMP%\installer\gui\page_3633_attr_3.png
- %TEMP%\installer\gui\page_3631_attr_3.png
- %TEMP%\installer\gui\page_3632_attr_3.png
- %TEMP%\installer\gui\page_3123_attr_3.png
- %TEMP%\installer\gui\ib\corn2.png
- %TEMP%\installer\gui\ib\corn3.png
- %TEMP%\installer\gui\ib\corn1.png
- %TEMP%\installer\gui\ib\btn.png
- %TEMP%\installer\gui\ib\btn2.png
- %TEMP%\installer\gui\page_3119_feature_835.png
- %TEMP%\installer\gui\page_3122_attr_3.png
- %TEMP%\installer\gui\page_3119_attr_3.png
- %TEMP%\installer\gui\ib\corn4.png
- %TEMP%\installer\gui\page_3118_attr_3.png
- from %TEMP%\ibtmpc810619\app_14398.part to %TEMP%\ibtmpc810619\app_14398
- from %TEMP%\ibtmpc810619\app_15971.part to %TEMP%\ibtmpc810619\app_15971
- from %TEMP%\ibtmpc810619\app_18002.part to %TEMP%\ibtmpc810619\app_18002
- from %TEMP%\ibtmpc810619\app_439.part to %TEMP%\ibtmpc810619\app_439
- from %TEMP%\ibtmpc810619\app_9697.part to %TEMP%\ibtmpc810619\app_9697
- 'www.na###mtech.com':80
- 'ap#.#bario.com':80
- 'in############571262.us-east-1.elb.amazonaws.com':80
- 'wp#d':80
- 'localhost':1037
- www.na###mtech.com/files/components/ZulaGamesSetup.exe
- www.na###mtech.com/files/components/MyBabylonTB3.cf
- www.na###mtech.com/files/components/SpeedanAlysisSetup.exe
- www.na###mtech.com/files/products/77zip920.exe
- www.na###mtech.com/files/components/Cloud_Backup_Setup_Adwards.exe
- in############571262.us-east-1.elb.amazonaws.com/service/country.php
- wp#d/wpad.dat
- www.na###mtech.com/service/country.php
- ap#.#bario.com/track/ib-show?ci##################
- ap#.#bario.com/track/ib-start?ci##
- DNS ASK www.na###mtech.com
- DNS ASK ap#.#bario.com
- DNS ASK wp#d
- DNS ASK in############571262.us-east-1.elb.amazonaws.com
- ClassName: 'MS_WebcheckMonitor' WindowName: '(null)'
- ClassName: 'MS_AutodialMonitor' WindowName: '(null)'
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'