Technical Information
- [HKLM\System\CurrentControlSet\Services\Bounced Email Handling 6.1] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Bounced Email Handling 6.1] 'ImagePath' = '%ALLUSERSPROFILE%\Bounced Email Handling 6.1\Bounced Email Handling 6.1.exe'
- 'Bounced Email Handling 6.1' %ALLUSERSPROFILE%\Bounced Email Handling 6.1\Bounced Email Handling 6.1.exe
- %TEMP%\is-jf9s2.tmp\<File name>.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-ra57h.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-ko0nd.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-ps0lt.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-b0oql.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-v0jfp.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-ddabh.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-hashk.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\lessmsi\is-vnuob.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-17m36.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-hfg7m.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-6am5e.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\plugins\internal\is-evpgj.tmp
- %LOCALAPPDATA%\weather widget\weatherwidget.exe
- %LOCALAPPDATA%\weather widget\bin\x86\plugins\internal\is-978lk.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-u8l23.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-8mu0l.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-ib9qm.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-1r832.tmp
- %LOCALAPPDATA%\weather widget\stuff\is-pbnca.tmp
- %LOCALAPPDATA%\weather widget\stuff\is-c93mo.tmp
- %LOCALAPPDATA%\weather widget\stuff\is-tn8o7.tmp
- %LOCALAPPDATA%\weather widget\stuff\is-rrf1p.tmp
- %LOCALAPPDATA%\weather widget\is-8dnss.tmp
- %LOCALAPPDATA%\weather widget\unins000.dat
- %LOCALAPPDATA%\weather widget\bin\x86\is-flflk.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-v6bue.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-96blg.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-le68r.tmp
- %TEMP%\is-0e9ve.tmp\_isetup\_regdll.tmp
- %TEMP%\is-0e9ve.tmp\_isetup\_setup64.tmp
- %TEMP%\is-0e9ve.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-0e9ve.tmp\_isetup\_isdecmp.dll
- %TEMP%\is-0e9ve.tmp\_isetup\_iscrypt.dll
- %LOCALAPPDATA%\weather widget\is-182sr.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-f2vn4.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-0qouo.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-9kcq6.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-4v4dk.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-ss824.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-5i1bl.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-6q8fo.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-q14vv.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-q6c4n.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-480oq.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-lq4ai.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-7rc5h.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-1d9nl.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-jklae.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-uue1m.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-k9bk5.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-j8h7l.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-gedtf.tmp
- %LOCALAPPDATA%\weather widget\bin\x86\is-had5g.tmp
- %ALLUSERSPROFILE%\bounced email handling 6.1\bounced email handling 6.1.exe
- %LOCALAPPDATA%\weather widget\stuff\date.txt
- %LOCALAPPDATA%\weather widget\stuff\tagsreplace.txt
- from %LOCALAPPDATA%\weather widget\is-182sr.tmp to %LOCALAPPDATA%\weather widget\unins000.exe
- from %LOCALAPPDATA%\weather widget\bin\x86\is-ps0lt.tmp to %LOCALAPPDATA%\weather widget\bin\x86\da.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-b0oql.tmp to %LOCALAPPDATA%\weather widget\bin\x86\daiso.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-v0jfp.tmp to %LOCALAPPDATA%\weather widget\bin\x86\dstt.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-ddabh.tmp to %LOCALAPPDATA%\weather widget\bin\x86\dsd2pcmt.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-hashk.tmp to %LOCALAPPDATA%\weather widget\bin\x86\pcm2dsd.exe
- from %LOCALAPPDATA%\weather widget\bin\x86\lessmsi\is-vnuob.tmp to %LOCALAPPDATA%\weather widget\bin\x86\lessmsi\lessmsi-v1.6.91.zip
- from %LOCALAPPDATA%\weather widget\bin\x86\is-17m36.tmp to %LOCALAPPDATA%\weather widget\bin\x86\d_writer.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-ra57h.tmp to %LOCALAPPDATA%\weather widget\bin\x86\dsd2.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-ko0nd.tmp to %LOCALAPPDATA%\weather widget\bin\x86\lame_enc.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-hfg7m.tmp to %LOCALAPPDATA%\weather widget\bin\x86\libwebp.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\plugins\internal\is-evpgj.tmp to %LOCALAPPDATA%\weather widget\bin\x86\plugins\internal\peak_scanner_plugin_c.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\plugins\internal\is-978lk.tmp to %LOCALAPPDATA%\weather widget\bin\x86\plugins\internal\raw_decode_plugin_c.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-u8l23.tmp to %LOCALAPPDATA%\weather widget\bin\x86\copying
- from %LOCALAPPDATA%\weather widget\bin\x86\is-8mu0l.tmp to %LOCALAPPDATA%\weather widget\bin\x86\7z.exe
- from %LOCALAPPDATA%\weather widget\bin\x86\is-ib9qm.tmp to %LOCALAPPDATA%\weather widget\bin\x86\takdec.exe
- from %LOCALAPPDATA%\weather widget\bin\x86\is-1r832.tmp to %LOCALAPPDATA%\weather widget\bin\x86\tak_deco_lib.dll
- from %LOCALAPPDATA%\weather widget\stuff\is-pbnca.tmp to %LOCALAPPDATA%\weather widget\stuff\date.txt
- from %LOCALAPPDATA%\weather widget\bin\x86\is-6am5e.tmp to %LOCALAPPDATA%\weather widget\bin\x86\libwinpthread-1.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-v6bue.tmp to %LOCALAPPDATA%\weather widget\bin\x86\sd.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-flflk.tmp to %LOCALAPPDATA%\weather widget\bin\x86\libdtsdec.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-96blg.tmp to %LOCALAPPDATA%\weather widget\bin\x86\utils.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-had5g.tmp to %LOCALAPPDATA%\weather widget\bin\x86\uchardet.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-0qouo.tmp to %LOCALAPPDATA%\weather widget\bin\x86\bassflac.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-9kcq6.tmp to %LOCALAPPDATA%\weather widget\bin\x86\bassmix.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-4v4dk.tmp to %LOCALAPPDATA%\weather widget\bin\x86\bassopus.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-ss824.tmp to %LOCALAPPDATA%\weather widget\bin\x86\basswma.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-le68r.tmp to %LOCALAPPDATA%\weather widget\bin\x86\basswv.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-5i1bl.tmp to %LOCALAPPDATA%\weather widget\bin\x86\bass_fx.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-q14vv.tmp to %LOCALAPPDATA%\weather widget\bin\x86\bassmidi.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-q6c4n.tmp to %LOCALAPPDATA%\weather widget\bin\x86\bass_tta.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-f2vn4.tmp to %LOCALAPPDATA%\weather widget\bin\x86\basscd.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-480oq.tmp to %LOCALAPPDATA%\weather widget\bin\x86\copying.lgplv2.1
- from %LOCALAPPDATA%\weather widget\bin\x86\is-7rc5h.tmp to %LOCALAPPDATA%\weather widget\bin\x86\gain_analysis.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-1d9nl.tmp to %LOCALAPPDATA%\weather widget\bin\x86\libflac_dynamic.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-jklae.tmp to %LOCALAPPDATA%\weather widget\bin\x86\bass_ofr.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-uue1m.tmp to %LOCALAPPDATA%\weather widget\bin\x86\optimfrog.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-k9bk5.tmp to %LOCALAPPDATA%\weather widget\bin\x86\mp3gain.exe
- from %LOCALAPPDATA%\weather widget\bin\x86\is-j8h7l.tmp to %LOCALAPPDATA%\weather widget\bin\x86\rg_ebur128.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-gedtf.tmp to %LOCALAPPDATA%\weather widget\bin\x86\wavpackdll.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-6q8fo.tmp to %LOCALAPPDATA%\weather widget\bin\x86\libsoxr.dll
- from %LOCALAPPDATA%\weather widget\bin\x86\is-lq4ai.tmp to %LOCALAPPDATA%\weather widget\bin\x86\ff_helper.dll
- from %LOCALAPPDATA%\weather widget\stuff\is-c93mo.tmp to %LOCALAPPDATA%\weather widget\stuff\tagsreplace.txt
- from %LOCALAPPDATA%\weather widget\is-8dnss.tmp to %LOCALAPPDATA%\weather widget\weatherwidget.exe
- %LOCALAPPDATA%\weather widget\stuff\date.txt
- %LOCALAPPDATA%\weather widget\stuff\tagsreplace.txt
- ClassName: '' WindowName: 'b20341_WW1133FlashFixClass_b20341'
- '%TEMP%\is-jf9s2.tmp\<File name>.tmp' /SL5="$E016C,4596989,54272,<Full path to file>"
- '%LOCALAPPDATA%\weather widget\weatherwidget.exe' -i
- '%LOCALAPPDATA%\weather widget\weatherwidget.exe' -s
- '%WINDIR%\syswow64\net.exe' helpmsg 1132
- '%WINDIR%\syswow64\net1.exe' helpmsg 1132